It required that I looked an extra time but in the end I banned this reporter as well: hackerone.com/reports/3346118
curl disclosed on HackerOne: Timing Attack Vulnerability in curl...
## Summary: A timing attack vulnerability exists in curl's Digest Authentication implementation due to the use of non-constant-time string comparison (strcmp()) when comparing authentication...HackerOne
Robert Dresden
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Robert Dresden • • •D*
in reply to daniel:// stenberg:// • • •These people need to be publicly shamed for wasting so much time and energy (and to what ends, one may wonder?), and for the test of us to know how much sh*t you have to deal with on a daily basis.
Numerfolt
in reply to daniel:// stenberg:// • • •revsuine 🇵🇸
in reply to daniel:// stenberg:// • • •