Wednesday, 13 February, 2019 UTC


Earlier this year, the popular Bower package manager was found vulnerable to archive extraction, allowing attackers to write arbitrary files on a user's disk. As it turns out, the vector attacks used by this exploit have been known since the early days of BBS. InfoQ has taken the chance to speak with Tal to learn more about software security and NodeJS security in particular.
By Sergio De Simone