I'm not a security expert but I think this could also open the door to a
MITM phishing attack. A user could click a link (sent from a server
pretending to be productsearch.ubuntu.com) thinking they are buying from
amazon.com but instead the login information is being read by a
malicious third party before being somewhat transparently passed on to
amazon for order completion.

** This bug has been flagged as a security vulnerability

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1054677

Title:
  Communicates with server in plaintext

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/unity-lens-shopping/+bug/1054677/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to