3 ms·
To be fair though, as per the report all of these "Critical" vulnerabilities were fixed by mid-2017. So they're listening, at least.
by mxstbr 9y ago
To be fair though, as per the report all of these "Critical" vulnerabilities were fixed by mid-2017. So they're listening, at least.
- deleted 9y ago[deleted]
- ktta 9y agoAnd I bet the critical sub-domain vulnerability was fixed too. The problem is that they are going to keep adding code, but won't get a security audit with every update. So all it takes is a slight mistake for it to be vulnerable again. What you need is a strong in-house pentesting team to be sure about there not being any new vulnerabilities with each release. Or atleast a bug bounty starting with beta releases, and let them bake before releasing them publicly. The fact that such serious vulnerabilities come up at the time of an audit shows that they don't have one.