Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Very nice write-up! Especially since RSnake stopped writing ha.ckers.org, great and educational reports have been rather scattered (unless anyone knows some good blogs on that subject? hm, makes me wonder if the sla.ckers forum is still up ...).

You conclude that these bugs are "subtle", but I don't quite agree. In some sense, ClickJacking is always "subtle"(vuln 2 and 3), and you can argue the same for any kind of side channel information leakage (vuln 1 and 2).

Except that clickjacking is known for years now and should be considered serious like XSS.

And the information leakage, well, it's IMO just not allowed to happen if you're a huge corporation implementing a worldwide single-sign-on identity service and many different types of web applications, while claiming to care about your user's privacy. It should be their number one priority and failing this means they're rolling out new features in a tempo that simply means they cannot hold true to claims about privacy.

Somebody else mentioned the tone of this article. While I'm not a big fan of the "jerk" attitude either when it comes to security testing (mostly because usually the bigger the mouth, the less interesting their feats), a security vulnerability is still a coding mistake that always ends up inconveniencing or endangering the privacy of the userbase. And I think that should be said. Which the author did. But he also downplayed the bugs by calling them "subtle" and then immediately praising Google for how lucky we are that they fixed them so quickly ... maybe I just do prefer the jerks, after all.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: