Hacker News new | past | comments | ask | show | jobs | submit login

> it requires a specific (common, but not universal) set of circumstances to escalate it to code execution.

Man in the middle attack does not require code execution because the data is already available.

In a sense, this bug is like having part of a keyboard sniffer already installed for you.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: