Live data from Hacker News

Google Chrome Hacked?

vupen.com

41–50 of 223 posts

Re: Google Chrome Hacked?

#41
I wonder if this is a sandboxing issue with NaCL, which is I noticed was added (default disabled) in Chrome 11.

Considering how non specific VUPEN are, I wouldn't be surprised if they're hiding this.

Re: Google Chrome Hacked?

#42
post #8

I can understand their joy but the last sentence in the post and the Twitter update: "Sorry Google...we have officially pwned Google Chrome and its sandbox with a 0-Day." [1] seem rather unprofessional for the "world leader in vulnerability research for defensive and offensive security" [2], a company with "Government customers". [1] https://twitter.com/VUPEN [2] http://www.vupen.com/english/company.php

Who cares if they sound unprofessional to you? Very obviously they produce.

I am still waiting for that obvious evidence. That includes more details and also tests on the latest dev version of Chrome (Chromium). I am not defending Google in any way, but some claim with no real evidence shouldn't convince anybody.

Re: Google Chrome Hacked?

#43
post #23

vupen: "Hey Google, your browser has a very nasty bug that allows for potentially horrible things to happen. We thought we'd share that with the world. If you'd like to know where it is though, you'd better give us money."

Why not? This is highly specialized research that not even well-paid Google employees were able to do. This is actually quite common in recent years for bug hunters and exploit developers. I can think of a dozen or so companies that do the same thing. Immunity is another example. Trying to use a moral argument to get out of compensating someone when you have the resources to do so is shameful. Sorry, but this stuff i…

"Why not? This is highly specialized research that not even well-paid Google employees were able to do."

Correction: not even well-paid Google employees did. They may yet be able, and an existence proof may be all the help they need to find and fix it. Don't give up hope yet.

Re: Google Chrome Hacked?

#44
post #31
post #24

Earlier quoted context omitted.

The reality is that there is probably no chance that they would ever find these bugs if they weren't funded to do it and the only way to be funded is to have customers. The net result is probably safer software for all.

The net result in this case is the government owning a zero-day root exploit for every Chrome/Win citizen’s computer. It’s worse than zero-day because we have no reason to expect a patch, so the window of attack will stay open.

Out of speculation, would this tie in at all to an article I saw on HN a while back about the Government hiring 3rd parties to hack Google for some reason?

Re: Google Chrome Hacked?

#45
post #23

vupen: "Hey Google, your browser has a very nasty bug that allows for potentially horrible things to happen. We thought we'd share that with the world. If you'd like to know where it is though, you'd better give us money."

Why not? This is highly specialized research that not even well-paid Google employees were able to do. This is actually quite common in recent years for bug hunters and exploit developers. I can think of a dozen or so companies that do the same thing. Immunity is another example. Trying to use a moral argument to get out of compensating someone when you have the resources to do so is shameful. Sorry, but this stuff i…

I doubt Google will hire them. They seem to be a very unprofessional company, even with their skilled people. They may pay to know about this security breach, though.

Re: Google Chrome Hacked?

#46
post #24
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

The reality is that there is probably no chance that they would ever find these bugs if they weren't funded to do it and the only way to be funded is to have customers. The net result is probably safer software for all.

OTOH, if they weren't paid then maybe the bugs would never be found and people wouldn't get owned.

Re: Google Chrome Hacked?

#48
post #46
post #24

Earlier quoted context omitted.

The reality is that there is probably no chance that they would ever find these bugs if they weren't funded to do it and the only way to be funded is to have customers. The net result is probably safer software for all.

OTOH, if they weren't paid then maybe the bugs would never be found and people wouldn't get owned.

So your theory is that they, unlike organized criminals with 6-7 figure budgets, are atomic supermen?

Re: Google Chrome Hacked?

#49
post #24
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

The reality is that there is probably no chance that they would ever find these bugs if they weren't funded to do it and the only way to be funded is to have customers. The net result is probably safer software for all.

I'm confused. Why would the government want to break Chrome? Also, if they are not going to release the exploit soon (especially to Google), why are you saying 'safer software for all'?

Re: Google Chrome Hacked?

#50
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

[deleted]
Post reply on HN