Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> A year ago I reported a security issue in Mozilla Basket (not publicly accessible). The essence is that subscribing anybody to Mozilla’s newsletters is trivial

I don’t see how signing someone up to a newsletter is a security vulnerability.



In some countries, it's not allowed without verification. This could get Mozilla in hot waters so I would fix it. How hard can it be?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: