I had the same idea the last days, but did not find the time to create it. AWESOME u did it. Thanks and i wish u success with it. i am definatly going to use it.
Obvious mistake made in the calculation. From "We also know that they had 3.4 million unique payers in the September quarter, which is up from 3 million at the end of December 2010." lead them to "In other words, they added 400,000 additional payers and they spent $120 million to acquire them.”
This is an obvius mistake, as not all of the 3 Million from Dec 2010 continued to be a customer in Sept 2011. I roughly assume they lost 800.000 customers in that span (i think its more), then the newly aquired customers triple to 1.2 Million. Thus Zynga makes 50$ profit per customer.
Parse is very unsecure because you essentially give the user full read/write/delete access to all of its data as no logic is run server side but clientside. That means any scriptkiddy can change all data as it likes.
That has nothing to do with MongoDB, but with the cirtical design flaw of Parse to trust the client not to send fake data.
So then they can only fake the traffic in their country what they can do anyway with non SSL traffic. I sounds more like this could be a global attack.
Just by having a forged SSL Certificate for ssl.google-analytics.com how can they supply their javscript ? The request still goes to the google servers and not to any evil-democracy-suppressors.gov.ir
So sure if they could reroute the request to their servers evil things could be done. But they can NOT. Or am i missing something ?