Page 1 of 1

Reporting Security-sensitive NoScript bugs.

Posted: Wed Oct 22, 2014 9:21 pm
by Giorgio Maone
If you discover an issue which may be exploited to weaken any of the security guarantees NoScript users rely upon (e.g. a XSS or ABE bypass, or a way to execute active content on a forbidden page) please report it privately, either by private messaging on this forum or (preferred) by sending a PGP-encrypted email to Giorgio Maone.

A fix will be released within 24 hours in the beta channel, and if validated will be pushed to the stable channel. Please keep your finding embargoed at least one week, until the vast majority of NoScript users are reached by the automatic update.

Thank you!

Re: Reporting Security-sensitive NoScript bugs.

Posted: Wed Apr 15, 2015 11:33 pm
by barbaz
Locking because this isn't intended for discussion and the spammers have discovered this.