Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Depends on the data. If you use a primary key in data about a person that shouldn't include their age (e.g. to remove age-based discrimination) then you are leaking an imperfect proxy to their age.




So the UUID could be used as an imperfect indicator of a records created time?

UUIDv7 but not UUIDv4.

I suppose timing attacks become an issue too.

UUIDv7 still have a lot of random bits. Most attacks around creating lots of ids are foiled by that



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: