iTunes Music Store Hole Discovered, Patched
prockcore writes "A vulnerability has been found in Apple's iTunes Music Store. The flaw enabled hackers to hijack other people's accounts by knowing only their email address, and download music with it. Apple has patched the hole."
How does something as simple as not passing authentication objects/info to the browser get past Apple's QA? Session Objects, Cookies and Hidden form fields are never secure from the user. Amazing this still happens.
Ah, it feels like 1996 again.
risk area, where if you and QA don't catch something like this, you're fired.
It makes you code better knowing screwing up could cost you your job. Although in situations like that you usually get more realistic development schedules compared to the corporate schedule of get it done now. (Or at least that's what I've experienced.)