>Why don't you include a POC? I have one that demonstrates this attack, but I don't want to show script kiddies how.
That leads me to this question: Did the author reach out to CircleCI to report this issue, before publishing their blog post?
>Why don't you include a POC? I have one that demonstrates this attack, but I don't want to show script kiddies how.
That leads me to this question: Did the author reach out to CircleCI to report this issue, before publishing their blog post?
What you as a commenter, or a company (usually prefers to quietly fix this), or the wider user base (usually prefers a 'heads up' immediately), all have different opinions about what they see as responsible.
Also, it doesn't seem fair to dismiss this disclosure as a 'hit piece' unless it is factually incorrect.
Write. I have written at least ten posts that made the front page of Hacker News / Programming Reddit (nb - Those aren't the best proxies for quality or popularity, but they are well known proxies). I can help kickstart your company's engineering blog, or work with your team on story/content ideas.
Now I'm not sure how much making the front page motivates your writing process. It is an interesting topic but I feel it would be a stronger case to demonstrate the issue across products from multiple vendors, though less incendiary/front-page-y.
PS. Props for not being the one to submit this particular article!
I used to be in ad tech, it always baffled me that we had first party js on every single customer page. Conceivable if we were breached, someone could inject code to read every login token or cc# or anything and send it to their servers.