Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah, glancing at the specs it looks like you're almost surely correct, that it's just checking a version string thats returned.

I got a little carried away, but really my point wasn't that it's impossible to avoid the risks, just that undoubtedly 99%+ of their customer base could be subjected to this and im sure most don't realize it. I thought my concerns with it were pretty tin foil hat until reading this story about the exact company doing something very, very similar.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: