5 ms·
>> Yahoo takes external security reports seriously Few weeks ago, I reported to your team that some of the yahoo servers' SSL cert were expired, acknowledged b
by tszming 12y ago
>> Yahoo takes external security reports seriously
Few weeks ago, I reported to your team that some of the yahoo servers' SSL cert were expired, acknowledged but no one want to fix it (until I post it here and finally get them updated...your site was showing security warning to your users for 2 weeks)
One of your awesome engineers replied the issue with expired SSL cert: "there do not appear to be any security implications as a direct result of this behavior"
- tacotime 12y agoif that's true then... wow and hopefully there's a new engineering position opening up at Yahoo right now
- aswanson 12y agoResponses like this remind me why I fell in love with this site.
- cpncrunch 12y agoAdmob.com also had an expired ssl cert for a few days recently.
- tszming 12y agoPeople make mistake, we all understand. (actually quite surprising as Yahoo does not have a mechanism to scan/monitor expired SSL certs). This is not the real issue here, the thing is their engineers think expired SSL cert is okay and no action being done. I told them you are now training your users to `feel` comfortable with browser warnings when they edit their Yahoo profile and risk your users in future's phishing attacks. I asked them why you are not using a self-signed cert if you think expired SSL cert is okay (of coz they didn't reply) Util I raise this up in another hackernews' thread on their product's announcement and maybe this time it really made them feel embarrassing and finally they fixed it with a day. The real problem here is actually not on the expired SSL cert, it is their mindset - you should treat every little reports seriously and it is your responsibility, because you are running one of the world's largest web sites.
- secalex 12y agoI appreciate you reporting expired certs, which unfortunately happen from time to time. That canned reply for is not appropriate and not a reflection of how we approach TLS and I will get it changed.
- madaxe_again 12y agowhich unfortunately happen from time to time How on earth do you manage that? Surely you have a process for monitoring and maintaining them?
- gr3yh47 12y agoAny real third party certification authority will let you generate emails to an address of your choice 90, 30, 14, and 3 days before your cert expires (or some similar schedule) Why wouldn't Yahoo set this up to email the group responsible or a ticketing email?
- jonknee 12y agoOr you know, create a reminder in Yahoo! Calendar...
- el_duderino 12y agoPeople use that??
- psykovsky 12y agoDoes your "successful" bug bounty program still only pays $12,50 in store credit per bug? That could explain the lack of interest in contacting you about any bug at all.
- djeikyb 12y agoI was curious. So I went to the link secalex posted. Bountys start at $50; max is $15k.