4 ms·
I can't help but think that he's right though. Not explicitly but implicitly. By keeping the vulnerability from the dev team they're allowing it to stay out in
by nchelluri 10y ago
I can't help but think that he's right though. Not explicitly but implicitly. By keeping the vulnerability from the dev team they're allowing it to stay out in the wild. No?
Edit: It may be that this is only an issue inside of Firefox extensions (addons). In which case, maybe the point is moot. See: https://github.com/mozilla/addons-linter/blob/master/docs/third-party-libraries.md#angularjs-1x https://github.com/mozilla/addons-linter/blob/master/docs/th...
- vosper 10y agoThere's a world of difference between an exploit being known to someone and that exploit being put up for sale on the black market. In either case, if the researcher who found the exploit sold it, that hardly makes Mozilla complicit in his actions.
- nchelluri 10y agoI am not sure that I agree. It's hard for me to say where the responsibility for disclosure lies, but if I was Mozilla I'd need to find a good reason not to disclose such a vulnerability to the project owner/development team. I am not sure that being asked not to disclose is a good enough reason without further justification; in fact it seems like a poor reason to me. Mozilla is in my view kind of a shepherd for internet users and I'd hope they'd fall more on the side of "let's not let our users get owned unnecessarily" than that of "let's sit on this vulnerability just because the disclosing party asked us to."
- rifung 10y agoWell, first of all if they disclosed it they would likely be sued for violating an NDA. Secondly, this would set a bad precedent because now who would ever trust Mozilla with a vulnerability that's behind an NDA?
- deleted 10y ago[deleted]
- icebraining 10y agoIsn't it a little soon to be judging them at all? We don't even know if this affects regular use of Angular (on websites) rather than just on rare use cases like browser extensions.