Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Arbitrary content injection into signed emails from Google, and it's not a security risk??? Incredibly poor response from them. Props to the author for being patient and trying multiple times to convince them to actually fix it.


It's too bad that Google decided that he didn't deserve compensation for reporting this security vulnerability.


start a crowd-funded reward like reported at http://www.theinquirer.net/inquirer/news/2290380/crowdfunded...


I'd rather pressure Google into delivering on their promise. But then again, I don't use Gmail.


What does Gmail have to do with it? It was the way Google Scholar was building emails that was at fault, right?


Right. And Google Scholar is part of Google.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: