Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

I mean in the end they could have got all this info from IP + headers + API key right? So what is the issue?


Maybe you missed it in the post, they look for the value of an environment variable and send the obfuscated result. I'm guessing this particular variable isn't sensitive for most users, but the reality that they find it acceptable to snoop your environment and hide their tracks is a big red flag.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: