Live data from Hacker News

Google Chrome Hacked?

vupen.com

21–30 of 223 posts

Re: Google Chrome Hacked?

#21

Whether or not this exploit is impressive, using the term "pwnd" comes across as incredibly unprofessional and predisposes me to perceiving this whole article in a negative light.

like it or not, it's been vernacular for quite some time. how do you feel about pwn2own? the pwnies?

"Whore" is vernacular, but that doesn't mean the FBI uses the word when they announce they've cracked a prostitution ring.

Re: Google Chrome Hacked?

#22
Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers.

I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for money. While I can understand that they have to make a living too, it just feels wrong to not protect everyone in the world when possible.

Re: Google Chrome Hacked?

#23
vupen: "Hey Google, your browser has a very nasty bug that allows for potentially horrible things to happen. We thought we'd share that with the world. If you'd like to know where it is though, you'd better give us money."

Re: Google Chrome Hacked?

#24
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

The reality is that there is probably no chance that they would ever find these bugs if they weren't funded to do it and the only way to be funded is to have customers.

The net result is probably safer software for all.

Re: Google Chrome Hacked?

#25
post #11

Not saying this isn't true, as I'm sure VUPEN is quite legit, but what stops me from creating a keyboard shortcut to calculator.exe, opening a random website which loads for a few seconds, and then pressing ctrl+alt+f6 or something to open calculator?

Nothing keeps you from doing it, their reputation keeps them from doing it.

Re: Google Chrome Hacked?

#26
post #16

seems odd to me that they don't publicly disclose the vulnerabilities, but they do publicly disclose the software versions affected by their "weaponized exploits", thereby giving the heads up to whomever might be targeted to avoid using that newly compromised software.

If you're selling a product you have to get the word out somehow.

Re: Google Chrome Hacked?

#27

Whether or not this exploit is impressive, using the term "pwnd" comes across as incredibly unprofessional and predisposes me to perceiving this whole article in a negative light.

It's not like "hacked" is a much better to the professional technical community.

Re: Google Chrome Hacked?

#28
post #23

vupen: "Hey Google, your browser has a very nasty bug that allows for potentially horrible things to happen. We thought we'd share that with the world. If you'd like to know where it is though, you'd better give us money."

Why not? This is highly specialized research that not even well-paid Google employees were able to do.

This is actually quite common in recent years for bug hunters and exploit developers. I can think of a dozen or so companies that do the same thing. Immunity is another example.

Trying to use a moral argument to get out of compensating someone when you have the resources to do so is shameful. Sorry, but this stuff is worth far more than the (up to) $3133 they are offering.

No More Free Bugs, as they say.

They can either pay a nominal fee for doing their security work for them, or they can hire some equally talented people and fund this type of research on their own internally. Fair is fair. There is no reason this isn't worth compensating but something like pagerank optimizations is.

Re: Google Chrome Hacked?

#29
post #16

seems odd to me that they don't publicly disclose the vulnerabilities, but they do publicly disclose the software versions affected by their "weaponized exploits", thereby giving the heads up to whomever might be targeted to avoid using that newly compromised software.

I think the version disclosure here was less of a "This version has a bug" and more of a "The latest version has a bug." It's a lot safer to tell people which haystack the needle is in than to give away the needle anyway.

Re: Google Chrome Hacked?

#30
post #27

Whether or not this exploit is impressive, using the term "pwnd" comes across as incredibly unprofessional and predisposes me to perceiving this whole article in a negative light.

It's not like "hacked" is a much better to the professional technical community.

Also pwned means something more specific than hacked. "owned" might be more "professional", but potentially more confusing, since Google didn't sell them the Chrome browser.
Post reply on HN