Hacker News new | past | comments | ask | show | jobs | submit login

I guess the most backdoor-looking bug I've ever seen (referring of course to Signal Desktop's usage of React's __dangerouslySetInnerHTML to render user-supplied messages in a Node.js privileged context) is below the technical authors paygrade. (https://thehackerblog.com/i-too-like-to-live-dangerously-acc...) - CVE-2018-11101



Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: