@infoseccrow @WiteWulf @SwiftOnSecurity Hey, they're not… *that* bad. I've seen worse.
I appreciate how you can tell what's going on in the back-end, because part of the server-side logic relies on the client making a specific sequence of GET requests. Also, I like how they usually comply with privacy law.
(I'm not really selling this, am I?)
@wizzwizz4 @WiteWulf @SwiftOnSecurity I mean, it's a step up from DVLA, who's test registration system has a misconfigured autoscaler that only exposes itself when under load...