https://textplain.wordpress.com/2016/03/06/using-https-properly/
"This post isn’t really about Pandora, per-se, but about common
anti-patterns in the industry."
This is very important:
"ProTip: Unless you want your frontline user-support team triaging
security vulnerability reports, get a HackerOne account and hook up a
security@ alias."
Via Erik de Castro Lopo, who wrote:
"Really interesting blog post showing how even big companies can get
security wrong."
Also via Lana Brindley.
Cheers,
*** Xanni ***
--
mailto:xanni@xanadu.net Andrew Pam
http://www.xanadu.com.au/ Chief Scientist, Xanadu
http://www.glasswings.com.au/ Partner, Glass Wings
http://www.sericyb.com.au/ Manager, Serious Cybernetics