I got into YC by hacking it

A developer describes how they discovered a security vulnerability in a Y Combinator-affiliated tool called Paxel. By exploiting an unvalidated HMAC, they were able to manipulate ranking scores, eventually leading to an invitation to YC's Startup School.
Why it matters
It highlights the risks of integrating third-party evaluation tools into application processes and the importance of responsible disclosure.
tldr: I uncovered Y Combinator was scoring 100k+ founders around the world through Paxel, I broke it (possible easter egg) + found a vulnerability that let anyone forge and push any score to their ranking database, courtesy of an unvalidated hmac
Latest update: YC admirably, didn’t mind. In just a couple hours after first-public-disclosure Jared Friedman himself replied, announced the patch, and invited me to attend the Startup School in SF this summer! I’d also disclosed it in private through email 12 days earlier to no response. But publicly at least the process works.
this is a re-write of an earlier draft where I first made the disclosure public. it was badly written, sleep-deprived and I didn’t feel good enough about it to publicize
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in