LiveOverflow asks why UUID-as-API-key is standard practice but UUID-as-ID is IDOR

rez0__ · x · 2026-10-10

Security researcher LiveOverflow poses an interesting discussion: using a UUID as a user ID is an insecure IDOR vulnerability, while using a UUID as a static API key is perfectly acceptable industry standard. Same UUID, opposite security verdicts depending on its role—he uses this to explore the underlying security reasoning.

Original post →

More from Safety

Safety channel →