How to (not) fix a security flaw
How to (not) fix a security flaw
Posted Apr 4, 2019 9:35 UTC (Thu) by sorokin (guest, #88478)Parent article: How to (not) fix a security flaw
I wonder what the thought process was of the person who decided that checking user agent would be sufficient for the fix. It looks so wrong on so many levels.
One can only guess what other remarkable design decisions are taken by the engineer (or the team) who released the fix.