Stealing OAuth tokens of Microsoft accounts via open redirect in Harvest App
111–114 of 114 posts
Re: Stealing OAuth tokens of Microsoft accounts via open redirect in Harvest App
#112Re: Stealing OAuth tokens of Microsoft accounts via open redirect in Harvest App
#113Earlier quoted context omitted.
I'm wondering how your two quotes "security of our customers is of the utmost importance to us" and "we believed there was something" fit together given that the issue stayed open for three years? So for three years you believed there was something, yet you didn't invest sufficient resources to reproduce and/or understand the issue, while at the same time, all these three years security was of utmost importance?
Hey, I got into more details in my internal discussion with the researcher and previous post, but around the time we determined we couldn't replicate it, we got a similar report leading me to believe this was already closed. I didn't believe there was something the whole time. It was a mix-up on my side, and I'm sorry about it.
Re: Stealing OAuth tokens of Microsoft accounts via open redirect in Harvest App
#114Earlier quoted context omitted.
I'm wondering how your two quotes "security of our customers is of the utmost importance to us" and "we believed there was something" fit together given that the issue stayed open for three years? So for three years you believed there was something, yet you didn't invest sufficient resources to reproduce and/or understand the issue, while at the same time, all these three years security was of utmost importance?
Hey, I got into more details in my internal discussion with the researcher and previous post, but around the time we determined we couldn't replicate it, we got a similar report leading me to believe this was already closed. I didn't believe there was something the whole time. It was a mix-up on my side, and I'm sorry about it.
It's still unclear what prevented the follow up communications from making its way to you.