Sometimes times the best hack is no hack at all — $2900 Shopify Bug Bounty

Access control is key.

Roberto
InfoSec Write-ups
Published in
3 min readAug 26, 2022

--

Photo by Ashin K Suresh on Unsplash

Broken Access Control was listed by the Open Web Application Security Project (OWASP) as the number one web app security risk in 2021. When applications get increasingly complex with more API endpoints and features, it can become more difficult to develop and adhere to policies to maintain proper…

--

--

Stanford alum, Software Engineer with a passion for CyberSec, Biotech, and Sustainability. Work with me at https://www.tidallabs.io/.