Posted May 4, 2012 17:59 UTC (Fri) by drag (subscriber, #31333)
[Link]
What's more is that they actually had code in place to properly protect against this sort of attack in 2004, but removed it.
A developer realized that the protection against this sort of attack was interfering with some of the regression tests so he deleted it. Nobody replied to his email explaining why the code check was needed.