I'm not surprised in the least, they have a Bugcrowd program and I've submitted atleast one P2 that took months to fix, and best of all - they don't pay bounties! what a joke if you ask me.
Doh.. this guy recently came to me and swooped an up .io I owned. I gave it to him for what I paid for it thinking it was just an individual, should of asked for more lol.
Migrated a complex Jenkins setup to Deploybot in 2015, saves our company a ton of time managing deploys. I'd highly recommend deploybot to anyone.
If I could critique even just one thing it would probably be its pricing structure for personal use, I can't justify $15/m just for deployments. I'd love if they had some kind of personal "developer" tier with support for more repos. On the business side, $15/m is ridiculously cheap for what service we're getting.
I think more cloud providers should do something like what Google Compute Cloud does, they have SSHGuard on their images by default so IPs get blocked after too many failed attempts.
Its funny the author mentions all the Google Play stuff about installing apps to users phones without them ever even knowing.. I actually found a company exploiting this in the wild using browser extensions, I wrote about it on this blog:
Oddly enough I submitted a bug report to google telling them they should set a content-security-policy on play.google.com, and was basically told "wont-fix" so the vulnerability to play store still exists.
I've had a few emails about our Enterprise offering but I have not had to the time to really land the sales. I know there are alot of people on HN looking to acquire projects, if someone is interested in the project, you can contact me at [email protected]
Would it be possible to constantly scan the DOM for new iframes and add the attribute with JS? Seems like there might be a small window of opportunity though for bad things to happen, if it would even work.
Chrome extensions can do some really nasty things.. Just last year while doing adware research for extensions, I actually came across an extension monetization company who was silently installing google android apps to the users phone with no human interaction what so ever, I wrote a break down of this on my blog:
I've been in contact with someone from Google Security and this was their answer:
"I spoke to the team that maintains that list and they don't have plans to make it public, if you would be willing to share some ideas on how to better protect people from this unwanted software I would be happy to pass it on but due to the nature of the work (trying to stay one step ahead of bad guys) we probably won't be able to share anything back."
I'm the author of this anti-adware addon called "Extension Defender" and it would greatly help my users if I could use their list, because while they extensions were removed from the Webstore, does that mean it was forcibly removed from their PC? Probably not.
I actually got really confused on the examples page, it took me a moment to realize there was a dropdown box with all the features.. I think displaying them all in a column on the left/right like bootstrap docs do, would make it easier to know whats going on.
I'm completely guessing here, but I'm wondering if this was spawned from looking at their own internal data on Adwords? I'm sure there are advertisers spending ungodly amounts of money toward auto insurance.. and Google probably thinks "oh we can do that easy and better, and take premium space on search". I think I remember reading an article somewhere that it was one of the most expensive keywords possible (Although this article is dated):
Counter Strike: Global offensive competitive play is a 5vs5 game, which is a pretty popular game in the esports community, perhaps something built for that community?
I really hope this comes to full light. I am an honest Adsense publisher since 2010 and got completely ripped off for $18,000. They waited until last day before payout as well, so all the traffic up until then for almost 2 full months was just gone. No answers from Google at all, just corporate firewall. They shouldn't be allowed to do this to so many people.