7 ms·
corylouie is on Dropbox's security team. (I work for Dropbox but don't speak for it in this capacity)
by frew 13y ago
corylouie is on Dropbox's security team.
(I work for Dropbox but don't speak for it in this capacity)
- daeken 13y agoDisclosing a fairly significant (albeit very niche) vulnerability like this via a comment on HN 3 weeks later isn't really best practice. Was there a disclosure prior to this post going up?
- rpearl 13y agoThis HN post is a link to a disclosure from the security researchers who worked with Dropbox (note: I work for Dropbox). It is not generally the case that companies disclose quickly-patched vulnerabilities that were reported by white-hat security researchers. Example of a similar vulnerability with a similar response time by another company: https://blog.duosecurity.com/2013/02/bypassing-googles-two-factor-authentication/ https://blog.duosecurity.com/2013/02/bypassing-googles-two-f... Researchers disclose a while after the vulnerability is patched. This is standard practice.