Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Just to be clear, by "script" here do we mean "Dude, check this out, you can just change /accounts?id=12345 to /accounts?id=12346"?


By "script", we mean a program written in PHP* which would generate plausible iPad ICC-IDs, run them by AT&T's web site, and save any ICC-IDs and email addresses it ended up with.

*: per the Gawker article, http://gawker.com/5559346/apples-worst-security-breach-11400...


Good point. The question I would ask is - Should he be doing even that given the fact he is in complete knowledge of the situation?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: