DEV Community

Discussion on: Exposing sequential IDs is bad! Here is how to avoid it.

Collapse
 
darkain profile image
Vincent Milum Jr

I'd highly suggest reading this article, along with several of the linked items within it. Essentially, security through obscurity isn't really security at all. en.wikipedia.org/wiki/Security_thr...

Collapse
 
pazvanti profile image
pazvanti

Yes, security just by making things harder to guess is not truly security. Still, time and time again we have data leaks simply because the IDs are easily guessable, either due to a lack of security on the app, or to use-error (making things public instead of private, se the Parler data dump). I am not saying that it is enough to have he PK hidden, I am just saying that it definitely helps.