miscoded

the web is a hack

they've made you safer

One night I checked work E-mail quickly on my mobile, and one of the numerous E-mails from the bug tracker caught my attention. It had a very specific and detailed - though brief - summary and claimed the bug was about a samedomain security policy violation. With mixed feelings of security concerns and curiosity I didn't go to bed but un-packed the laptop to have a look at the bug...

Now 9.24 arrived a couple of days ago. This is a recommended security upgrade which fixes two security issues, reported by Opera users. Both of them hang out on My Opera, so cheers to dbloom and burnout426 for having made us all safer! The results of their work and testing reach beyond those two simple fixes since a single security issue found makes us all investigate how it happened - QA wonders why things weren't tested from that angle - and thus a number of new test cases are written to try to ensure not only that those issues won't re-occur but also that related similar issues won't arise, and will be caught when they do.

So many thanks, guys! Good catch and your work is greatly appreciated. cool

Y!Mail: getting somewhereA malicious thought: how to imagine a security issue

Comments

David Bloomdbloom Friday, October 19, 2007 2:39:01 PM

No problem. Your work is appreciated too :-)

Opera has, by far, been the fastest and most responsive browser maker when it comes to vulnerability reports (and I've reported confirmed vunerabilities in 3 of the "big 4" browsers). After seeing the hard (fast) work of Hallvord and Opera's script team, I feel more secure using Opera after reporting this security problem than before!

Dan Alexandrudantesoft Friday, October 19, 2007 2:43:47 PM

Thanks, guys! Scary issues, indeed.

I noticed from the changelog that the reporters didn't seem to be from a researcher tank smile

FataL Friday, October 19, 2007 4:15:57 PM

Great work, guys! up
Thank you!

Daniel Goldmandanigoldman Friday, October 19, 2007 7:22:26 PM

Thanks guys!!

Michael A. Puls IIburnout426 Saturday, October 20, 2007 5:10:24 AM

smile

Connytars1 Saturday, October 27, 2007 12:42:01 PM

Do you own the Lounge?

Hallvord R. M. Steenhallvors Wednesday, October 31, 2007 2:03:58 PM

No, I can make no claims to owning the lounge - in fact I'm perhaps its least frequent visitor wink

Write a comment

You must be logged in to write a comment. If you're not a registered member, please sign up.