TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Mega.co.nz: 1st week report of vulnerability reward program

5 pointsby Mithrandirover 12 years ago

2 comments

taprootover 12 years ago
The smugness of this post reaks. Rather unwarranted considering the number of XSS vulns found, I also question their classification of these, XSS in this system entirely breaks their "encryption as a mass product" philosophy. (provided you give them the benefit of the doubt and assume its for the users and not their protection)<p>Taking they want to tout this system as security focused I'm quite amazed they seem to not have scrubbed a single output. I highly doubt they fixed it properly either.
lemcoe9over 12 years ago
This definitely seems like the best way they could handle the recent coverage of their security.