Hacker News new | past | comments | ask | show | jobs | submit login

You didn't need the target's access token. Your own worked just fine.



Exactly, that in itself is the whole point of this being a security bug.


Woah, didn't catch that when I first skimmed through the article. $12,500 wasn't enough then.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: