Comment by fc417fc802

Comment by fc417fc802 4 days ago

2 replies

> an API that should probably be better secured.

I think the API is secured? The entire premise is that a volunteer creates an account and uploads ADS-B telemetry. Detecting falsified data is a separate matter.

darthwalsh 4 days ago

Sounds like authentication is working great, but their authorization design may be flawed.