Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> For all we know Mozilla is complicit in the black market sale of this vuln by the mystery security researcher.

That's a ridiculous claim



I can't help but think that he's right though. Not explicitly but implicitly. By keeping the vulnerability from the dev team they're allowing it to stay out in the wild. No?

Edit: It may be that this is only an issue inside of Firefox extensions (addons). In which case, maybe the point is moot. See: https://github.com/mozilla/addons-linter/blob/master/docs/th...


There's a world of difference between an exploit being known to someone and that exploit being put up for sale on the black market. In either case, if the researcher who found the exploit sold it, that hardly makes Mozilla complicit in his actions.


I am not sure that I agree. It's hard for me to say where the responsibility for disclosure lies, but if I was Mozilla I'd need to find a good reason not to disclose such a vulnerability to the project owner/development team.

I am not sure that being asked not to disclose is a good enough reason without further justification; in fact it seems like a poor reason to me. Mozilla is in my view kind of a shepherd for internet users and I'd hope they'd fall more on the side of "let's not let our users get owned unnecessarily" than that of "let's sit on this vulnerability just because the disclosing party asked us to."


Well, first of all if they disclosed it they would likely be sued for violating an NDA. Secondly, this would set a bad precedent because now who would ever trust Mozilla with a vulnerability that's behind an NDA?


Isn't it a little soon to be judging them at all? We don't even know if this affects regular use of Angular (on websites) rather than just on rare use cases like browser extensions.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: