Live data from Hacker News

Google Chrome Hacked?

vupen.com

31–40 of 223 posts

Re: Google Chrome Hacked?

#31
post #24
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

The reality is that there is probably no chance that they would ever find these bugs if they weren't funded to do it and the only way to be funded is to have customers. The net result is probably safer software for all.

The net result in this case is the government owning a zero-day root exploit for every Chrome/Win citizen’s computer. It’s worse than zero-day because we have no reason to expect a patch, so the window of attack will stay open.

Re: Google Chrome Hacked?

#32
post #8

I can understand their joy but the last sentence in the post and the Twitter update: "Sorry Google...we have officially pwned Google Chrome and its sandbox with a 0-Day." [1] seem rather unprofessional for the "world leader in vulnerability research for defensive and offensive security" [2], a company with "Government customers". [1] https://twitter.com/VUPEN [2] http://www.vupen.com/english/company.php

Who cares if they sound unprofessional to you? Very obviously they produce.

Re: Google Chrome Hacked?

#33
post #23

vupen: "Hey Google, your browser has a very nasty bug that allows for potentially horrible things to happen. We thought we'd share that with the world. If you'd like to know where it is though, you'd better give us money."

The "no more free bugs" campaign has gained a fair amount of support:

http://trailofbits.com/2009/03/22/no-more-free-bugs/

Re: Google Chrome Hacked?

#34
post #23

vupen: "Hey Google, your browser has a very nasty bug that allows for potentially horrible things to happen. We thought we'd share that with the world. If you'd like to know where it is though, you'd better give us money."

Why not? This is highly specialized research that not even well-paid Google employees were able to do. This is actually quite common in recent years for bug hunters and exploit developers. I can think of a dozen or so companies that do the same thing. Immunity is another example. Trying to use a moral argument to get out of compensating someone when you have the resources to do so is shameful. Sorry, but this stuff i…

"They can either pay a nominal fee for doing their security work for them, or they can hire some equally talented people and fund this type of research on their own internally."

What makes you think they don't already? You make it sound like Google doesn't give a shit about security. That clearly isn't the case.

Re: Google Chrome Hacked?

#35
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

Do policemen work for free? It's a dirty job, I 'd want to be paid

Re: Google Chrome Hacked?

#37
post #36

[deleted]

"Dear Google Employees reading HN: This exploit, along with VUPEN's affiliation to goverment agencies, scared the crap out of me. Having used Chrome since it's earliest days, I'm now forced to switch my main browser to FF4; it remains so until confirmation from either parties of the bug's "fixed" status."

I think it's time for you to take your computer out back and set it on fire. Best way to be safe until Google fixes this. Whatever it is.

If you think there isn't an active 0-day against Firefox or IE or Safari or... oh boy. This is news because such things are rare against Chrome. Welcome to software.

Re: Google Chrome Hacked?

#39
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

Looking at VUPEN services it sounds like HBGary twin :

http://www.vupen.com/english/services/

"offensive security", yep. The guys are dirty like the Gary. Why a racket and government always means a happy marriage?

Re: Google Chrome Hacked?

#40
post #8

I can understand their joy but the last sentence in the post and the Twitter update: "Sorry Google...we have officially pwned Google Chrome and its sandbox with a 0-Day." [1] seem rather unprofessional for the "world leader in vulnerability research for defensive and offensive security" [2], a company with "Government customers". [1] https://twitter.com/VUPEN [2] http://www.vupen.com/english/company.php

Who cares if they sound unprofessional to you? Very obviously they produce.

"Who cares if they sound unprofessional to you? Very obviously they produce."

Sadly we can't verify that in this case. Because you know, we're not the CIA.

Post reply on HN