@securedbycasco: Can someone steal your users' data just by pasting a URL? If your app doesn't check who's asking for that data, then yes. In this one I break down one of the most common vulnerabilities we find at Casco: Insecure Direct Object Reference, or IDOR. Change a single ID in a URL, and a broken app will hand over someone else's private data. If you're vibe coding an app right now, watch this before you ship it. #cybersecurity #vibecoding #softwareengineering #startup
ChatGPT, create comprehensive security plan, make no mistakes
2026-07-01 02:53:20
1027
chriscmcclurg :
lol. Claude code automatically builds against this. It and other basic tools can and do own test as a predictors function of building code. You would literally have to instruct it to allow this.
2026-07-05 09:16:37
20
Bungflavor :
no because why would I role my own auth
2026-07-01 11:11:31
19
Milupa55 :
any decent security audit skill will pick up on these, it's just a simple due diligence and best practice to do this
2026-07-01 04:48:09
82
dougdougdoug :
Implement JWTs with refresh and accesss tokens, make your websites api endpoints require the token to view the data and if no token then throw error message that they arent signed in
2026-07-01 02:35:16
80
justin :
ChatGPT setup middleware and authentication and rate limiting, any security you could think of
2026-07-01 13:20:30
6
Odeyemi Daniel :
why not use a provider for authorization and authentication on the website
2026-07-02 17:21:28
0
Jamesssss :
Middleware & authentication
2026-07-01 13:01:20
6
A Darker World :
lol not just vibe coders... so many companies before AI had flaws like this or worse
2026-07-01 18:59:21
4
🙄😀😒 :
while you're developing, in other chat or window, ask them to audit the project and tell them to plan all the security checks step by step like api limiters, user api access checks, tokens with refresh. you don't even have to specify individually, they would recommend you in the plan.. as a backend enginner, I had plans to do that but them recommending all those is exceptional.. you would still need a software enginner to review the code
2026-08-04 14:53:02
1
Waleed :
Claude Security handle more sophisticated security issues than this bs
2026-07-31 12:01:37
1
Navi :
Dont you just add a auth check in the middleware/routing? Isnt this like a super simple thing to prevent?
2026-08-07 03:20:08
4
rainy :
that page identifier is called a slug
2026-07-04 07:22:33
0
Cheesemo :
If you're running an incapable model and has no prior dev experience, then yes - this is really a thing that happens.
2026-07-06 15:52:21
5
HolyCrab85 :
super easy to prevent
2026-08-05 09:23:23
1
madarauchiha8927 :
Please stop. It middleware are know from AI models.
2026-07-02 18:41:50
1
Hokageofyadd :
IDOR
2026-07-02 00:42:13
1
Alexgmt93 :
basic auth security that AI covers...
2026-07-03 09:57:56
14
Jose Zuñiga :
Authentication ≠ Authorization
2026-07-15 21:55:22
1
Jens Humke :
Ever heard about DBSC
2026-07-01 17:10:06
1
cybergng :
all of this just to hardcode passwords
2026-08-27 02:44:30
0
oa :
dirb
2026-08-25 23:50:54
0
an083w :
Or just NEON OAuth
2026-09-25 20:21:43
0
To see more videos from user @securedbycasco, please go to the Tikwm
homepage.