Hacker News new | ask | show | jobs
by jevinskie 4632 days ago
I'm curious as to why FireEye chose not to disclose the library. What would you call this kind of disclosure?
3 comments

"I'm curious as to why FireEye chose not to disclose the library."

For the same reason that most responsible security researchers don't disclose zero-day threats: to prevent people from exploiting them before they can be fixed. In this case, they did notify Google, which can pull the compromised apps out of their app store and notify the developers who've used this library that they need to rewrite their apps.

Covering their own asses so the framework dev doesn't come after them is the only reason I could see.

The pixelization just reminds me of 'dodgy plumbers' on 'current affairs' shows or somesuch. I'm sure someone will recognize the pictured app eventually.

your point is moot.

The ad library, who runs the code and expose the JS apis so that html ads can call it, proably advertise to its clients that they can do that.

So which actor exactly is being left out if they do not disclose? only the victims.