Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That fact that they fixed the problem seems to be counter to the CEO's statement that it wasn't actually a problem.

They clearly weren't validating all of the form inputs on the server side. Hopefully this was a learning experience for the engineering team.



You have a 24 hour window for a deal like this and you know it costs you $10 for everyone who games the system. So you let the hackers think they've won then after the 24 hours is up, reveal that they've lost. Instead of finding creative and more difficult ways to game the system, the hackers wasted their 24 hours partying and getting drunk and so LivingSocial wins.

Probably not exactly how it went down, but it's a good story.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: