3 ms·
Great talk (it's about pen testing Angular 1 apps, not Angular 2). I have mixed feelings about the "whitehat" security person intentionally submitting a flawed
by dude01 10y ago
Great talk (it's about pen testing Angular 1 apps, not Angular 2).
I have mixed feelings about the "whitehat" security person intentionally submitting a flawed bug fix (into the real Angular code base) so that they could introduce a security vulnerability in an open source project. At least they made sure their vulnerability didn't appear in an actual release, and they had given a warning to the Google security team, but not the Angular team, about what they intended.
Perhaps the only thing I really learned is that if a "whitehat" security person thinks it's a legit concern to make a malicious patch to an open source project, you can be darn sure there are lots of blackhats doing the same thing on other projects right now.