Website enumeration insanity: how our personal data is leaked
I've just wrapped up a couple of Hack Yourself First workshops [https://www.troyhunt.com/workshops/] down closer to home in Australia and true to usual form, attendees found some absolute zinger security implementations. Previous workshops have found various vulnerabilities ranging from realestate.com.au's lack of HTTPS in their Android app [https://www.troyhunt.com/are-your-apps-giving-one-device/] (pro tip: don't 301 HTTP requests to APIs!) to the one that really made headlines earlier this ye...