this post was submitted on 26 Jul 2025
        
      
      890 points (99.0% liked)
      Programmer Humor
    27117 readers
  
      
      1725 users here now
      Welcome to Programmer Humor!
This is a place where you can post jokes, memes, humor, etc. related to programming!
For sharing awful code theres also Programming Horror.
Rules
- Keep content in english
- No advertisements
- Posts must be related to programming or programmer topics
        founded 2 years ago
      
      MODERATORS
      
    you are viewing a single comment's thread
view the rest of the comments
    view the rest of the comments
 
          
          
@01189998819991197253 @ConstantPain
Security isn't binary, it's a spectrum. You apply the level of security that is appropriate for each situation.
Of course it's *possible* to brute force it, but by the same logic you could brute force jwt tokens, or api keys, or even ssl certs.
It's literally *impossible* to apply "max security" to everything, so you have to prioritize.
What happened was unconscionable, but insisting uuid are mathematically breakable isn't helpful, and can make it worse.