| > I'd sooner believe that something's wrong with the closing of the bug report than something's wrong with my understanding of how this is still a bug. Your credentials and ability in the field have not been established despite enquiries by many folks in this sub-thread. At the moment, I'm far more likely to believe that Mr. Ormandy has a far better understanding of the security issues with the AVG Chrome extension and their implications than you do. > Perhaps if he'd said "this XSS is not an issue" without explanation, I'd be happy... He marked the bug as Resolved-Fixed and removed the disclosure embargo. I don't know what more you want. > Note that nobody yet has given me any explanation of how it might not be a bug... tptacek and many others gave you a couple of really coherent replies in the subthread attached to your initial comment. None of them provide you with the answer you're looking for, but -frankly- you haven't demonstrated that you understand why it's reasonable the embargo on a security bug for a Chrome extension that AVG has made publicly available in the Chrome Webstore and that its security researcher (and -I suppose- AVG) feels fixes his reported problem was removed. :) Maybe it'd help to know that the extension is currently not available pending an investigation into whether or not it violates any Webstore policies. |