Live data from Hacker News

Angular 1.x Banned from Firefox Addons

github.com

21–30 of 222 posts

Re: Angular 1.x Banned from Firefox Addons

#21
post #11

Bitwarden is a password manager? And their engineer is asking, after being told a hint of serious security issues in their framework, to just forget about it and let them publish? That's an interesting approach.

It is strange. On the other hand there's something suspicious here. Some things clearly aren't being communicated properly.

Yeah, definitely odd.

"We banned any package containing Angular 1.x. We received a security report. One that we were asked not to share with you, one that we didn't even mention, we just went ahead and implemented the ban, didn't tell anybody."

Re: Angular 1.x Banned from Firefox Addons

#22
post #15

For all we know Mozilla is complicit in the black market sale of this vuln by the mystery security researcher. Given Angular 1's popularity, Mozilla has a moral obligation to responsibly disclose this bug to the Angular team and let them determine if its unsolvable or not. Hinting at its existence is one of the worst things they could have done since it will simply give other blackhats motivation to find this vuln wh…

> For all we know Mozilla is complicit in the black market sale of this vuln by the mystery security researcher.

That's a ridiculous claim

Re: Angular 1.x Banned from Firefox Addons

#25
post #15

For all we know Mozilla is complicit in the black market sale of this vuln by the mystery security researcher. Given Angular 1's popularity, Mozilla has a moral obligation to responsibly disclose this bug to the Angular team and let them determine if its unsolvable or not. Hinting at its existence is one of the worst things they could have done since it will simply give other blackhats motivation to find this vuln wh…

This is a bad comment. You're fear mongering and conjecturing conspiracy theories that don't exist.

Re: Angular 1.x Banned from Firefox Addons

#26
That doesn't make much sense. If there's a vulnerability in Angular, doesn't it mean that there's a vulnerability in the JS engine that runs the Firefox addons? And in that case, can't an attacker replicates whatever Angular is doing to make an exploit? Basically it sounds like it's something for Mozilla to fix, not the Angular team.

Re: Angular 1.x Banned from Firefox Addons

#27

Bitwarden is a password manager? And their engineer is asking, after being told a hint of serious security issues in their framework, to just forget about it and let them publish? That's an interesting approach.

No, the engineer is asking for more information so that he can determine if the application is truly affected by some unpublished Angular vulnerability or if Mozilla is just being too aggressive with their ban hammer because someone said "Angular 1.x was no longer being officially supported", which is false.

I think encoderer was referring to https://github.com/mozilla/addons-linter/issues/1000#issueco..., where the engineer asks, "Is there any possible way for us to get around this ban?"

Re: Angular 1.x Banned from Firefox Addons

#28
post #22
post #15

For all we know Mozilla is complicit in the black market sale of this vuln by the mystery security researcher. Given Angular 1's popularity, Mozilla has a moral obligation to responsibly disclose this bug to the Angular team and let them determine if its unsolvable or not. Hinting at its existence is one of the worst things they could have done since it will simply give other blackhats motivation to find this vuln wh…

> For all we know Mozilla is complicit in the black market sale of this vuln by the mystery security researcher. That's a ridiculous claim

[deleted]

Re: Angular 1.x Banned from Firefox Addons

#29
post #22
post #15

For all we know Mozilla is complicit in the black market sale of this vuln by the mystery security researcher. Given Angular 1's popularity, Mozilla has a moral obligation to responsibly disclose this bug to the Angular team and let them determine if its unsolvable or not. Hinting at its existence is one of the worst things they could have done since it will simply give other blackhats motivation to find this vuln wh…

> For all we know Mozilla is complicit in the black market sale of this vuln by the mystery security researcher. That's a ridiculous claim

I can't help but think that he's right though. Not explicitly but implicitly. By keeping the vulnerability from the dev team they're allowing it to stay out in the wild. No?

Edit: It may be that this is only an issue inside of Firefox extensions (addons). In which case, maybe the point is moot. See: https://github.com/mozilla/addons-linter/blob/master/docs/th...

Re: Angular 1.x Banned from Firefox Addons

#30
post #15

For all we know Mozilla is complicit in the black market sale of this vuln by the mystery security researcher. Given Angular 1's popularity, Mozilla has a moral obligation to responsibly disclose this bug to the Angular team and let them determine if its unsolvable or not. Hinting at its existence is one of the worst things they could have done since it will simply give other blackhats motivation to find this vuln wh…

This is a bad comment. You're fear mongering and conjecturing conspiracy theories that don't exist.

That was the way I read it initially to. I think the intended meaning was that we don't know anything about it, up to and including this ridiculous claim. It's more to highlight the lack of transparency than actually put forth a viable theory.
Post reply on HN