Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why did it take months for Amazon to fix it?


I have no idea. Adding a single HTTP header seems simple to me, but I have no idea what their architecture looks like. It took them an entire month to send me a "thanks, we're working on it" email and that was only after I followed up with them.


They probably spent most of the time investigating to make sure that adding the header wasn't going to break anything.


Yep, they may have had widgets or legitimate framing that they needed to handle.


Probably because you can't do much by exploiting this security hole besides annoying people, so there's little incentive to do so. If you can get me to click on an item and buy it, the item will be shipped to my physical address, not yours. Even if was a product you were selling, I could return it for a refund and your account would be charged back. It doesn't seem like a very profitable scheme.


Sounds about the right amount of time for a dev cycle in a large corporation.

Yes, I may be a bit bitter...


Yeah for a normal dev cycle. Security fixes do not need to follow a normal dev cycle.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: