On Mon, 11 Jun 2012 13:45:26 -0700
Sid Stamm wrote:

> Can you elaborate here?  I'm interested to hear your thoughts.

Leaving aside server/device security which may affect user security and
also completely anonymised data matching to connection details or
substitued user ids. An example being homesafe violating the long
standing and well serving principle of simple safe routing technologies
employing Hauwei hardware. Note: Symantec couldn't keep their own
source code secure. 


Is there any chance of chaining together anonymised downloads in your
design perhaps via some url scheme or proxying a user is using or any
other kept information potentailly giving crude information on likely
researched parts employed in an unknown companies product for example.
There may even be a unique download url you can identify someone to and
if you can chain then get a wealth of information such as a medical
condition.
_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security

Reply via email to