This android wallet has an internal browser and it incorrectly strips www. from hosts. This also affects their permission system, meaning this is the perfect bug to phish users.
They didn't answer multiple mails in 30 days, so it's being disclosed.
HN user
This android wallet has an internal browser and it incorrectly strips www. from hosts. This also affects their permission system, meaning this is the perfect bug to phish users.
They didn't answer multiple mails in 30 days, so it's being disclosed.
Don't get me wrong, I do use kagi. but it's not nearly what I wish it'd be.
Maybe MetaGer if you can live with their quality
Oh yes because of the CSP. The CSP that allows forms that can change your settings... you could easily use the above bug to get some impact with an additional click on a form's submit button.
Admittedly, no full XSS anymore, but still dangerous and shows their lack of understanding and caring about security.
It's not the only place you can inject HTML and not every page has a CSP...
Go look at MetaGer, they solved that issue
Ha, exactly! They rarely fix bugs.
E.g., XSS / HTML injection in summarizer or discuss document. Or their broken CSP which allows injecting forms to e.g., change settings.
They haven't fixed many reported issues in a while, and just to prove I'm not lying: https://kagi.com/discussdoc?url=https%3A%2F%2Fkagi.com%2Fcha...
They do not take security and privacy seriously
I don't want that?
Well if you attack his friends, it's not okay, but if you go which death upon 'the leftists' he wouldn't say a thing, I bet
Dude can move so many millions around I'd shit my pants if he tells me to die slow.
oh man I didn't know I'd hate this guy :D
There's another tool like this called horcrux, which I find to be a better name personally.
=cmd|' /C calc'!A0
C is unsafe
Don't you ever care about upsetting people who live in countries with unreasonable gun laws. Especially third world countries like the US.
a query for red shoes is mostly red shoes
well I get mostly black shoes lol
Edit: ah no, they just use half a page for shoe shops first with black shoes as logo??
Sending network packets. Like, I send you a big array of bytes and you write it to a small buffer and therefore I overwrite unintended data.
Right, there haven't been crazy Java exploits going around the past few months, only Rust and Go!
Switch to security :)
Especially because people didn't know ALL the effects. This is not just about static, but also how it impacts shots.
Lance made a video too, but in more detail: https://www.youtube.com/watch?v=GuqVUsMPs-U
You can use a wet spoon handle
Just chiming in to mention that xylitol seems to have a beneficial effect, similar to what this sounds like, though very different mechanism.
Do you still use other search engines?
You should start to do your everyday searches on both and compare the results. For me, this showed that kagi can save me time, I'm rarely scrolling to find good results where on DDG or Google I'd rephrase and search again often.
I don't like Kagi for other things, but that's not the topic here.
I do not think it is hard for any of them to get a new job and they would be flooooooded with offers if the opened their linkedin
DDoS is also a good distraction from actual attacks tho
But not my browser
Change your user agent so it looks like chrome, life is better then.
They are still one of the very best