Elektrine lite

← Feed

@lmk@infosec.exchange

Post #3913811

2026-07-18 01:54 UTC

@adamshostack@infosec.exchange If only they had a threat model and we could see how they updated it. :-/

Replies (1)

  • @lmk@infosec.exchange There's an interesting discussion here https://bugzilla.mozilla.org/show_bug.cgi?id=1139656 (Thanks @jann@infosec.exchange !) I think one of my takeaways is .. you're right. Having a clear security goal would have helped this discussion. My other takeaway is it's not easy to determine if they fully considered the case that had led to the earlier security decision. I think that comment 6 implies they did, and 8 implies that they're moving to trusting anyone with signed code, and I might be mis-reading this. But to my original question, no one seems to have explicitly hearkened back to the original flaw.

    Open ##3913810