1/
got a dm. "can you test our platform?"
sure. that's my hobby.
it was a govt voting platform. link dropped. frontend was gorgeous, whoever built it deserves a raise.
then the engineer in me woke up.
3/
asked myself, no login, so how do they know i already voted?
tried again, got blocked.
cookies. cleared them. reloaded.
voted again.
second round secured. i laughed for this one.
4/
opened dev tools. fired a request. watched the response.
PHP. not bad, i said.
then i saw it, the response was leaking candidate IDs it had no business sending back.
that's the door right there.
7/
moral: your frontend can wear armor, jet fighters, whatever
attacker doesn't care how pretty your UI is. give them a terminal and your endpoints, and your "secure" system is wide open
rate limit your backend. validate what you send back. build like someone's already testing it