Hacker News new | ask | show | jobs
by albinowax_ 2510 days ago
You can now see the PayPal timelines here: https://hackerone.com/reports/488147 https://hackerone.com/reports/510152

Trello patched it in roughly 10 days. In general I found companies took longer to patch this issue than other similar-severity vulnerabilities, probably because it's conceptually unfamiliar so I frequently had to spend quite a while explaining it, and the patch itself appears to be challenging sometimes too.