3 ms·
https://security.googleblog.com/2013/05/disclosure-timeline-for-vulnerabilities.html https://security.googleblog.com/2013/05/disclosure-timeline-...
by DrewHintz 10y ago
https://security.googleblog.com/2013/05/disclosure-timeline-for-vulnerabilities.html https://security.googleblog.com/2013/05/disclosure-timeline-...
- acqq 10y agoI know about that post from 2013 and I still don't agree. Just like I don't agree with how Google implemented AMP, making google.com a link redirector that didn't exist before and was actually used in the fishing campaign, specifically: http://seclists.org/bugtraq/2016/Apr/70 http://seclists.org/bugtraq/2016/Apr/70 That is what was actively used to fish the logins from Podesta et al. Google's response: https://sites.google.com/site/bughunteruniversity/nonvuln/open-redirect https://sites.google.com/site/bughunteruniversity/nonvuln/op... "tooltips are not a reliable security indicator" Translation: "we don't look at that sh.t" "poses very little practical risk." See how Podesta et al. were tricked. "offers fairly clear benefits" Translation: "For us. Muahhaha."