Skip to content

Comment on Our Responsibility As Developersparent

Comments

Due to a bug in our third-party network library the certificates were not being verified so a self signed certificate could decrypt the data.

Finally, now the TC article makes sense. Someone told me the guy that found the exploit works for one of your competitors. ;).

You mean, the author of the article who disclosed that from the beginning?

Ah I didn't notice the disclosure so much as I skimmed the start looking for the technical details. Still strikes me as somewhat cynical though.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.