Discovering and Disclosing httpoxy

Over the past two weeks, I’ve been coordinating the disclosure of a pretty big and very old security vulnerability. If you’re looking for the technical details, you can head to, and if you’re looking for a non-technical explanation, you might prefer to read my other Medium story about the issue.

Instead, this is the story of how we discovered it, and my experience with the disclosure process.


An explanation for non-technical audiences

