Live data from Hacker News

Google Chrome Hacked?

vupen.com

91–100 of 223 posts

Re: Google Chrome Hacked?

#91
I'd like to mention something to everyone running around crying about the falling sky because THE GUBBMINT has paid a security company to audit Chrome. Oak Ridge National Labs just recently had to shut down COMPLETELY because an Internet Explorer exploit "pwned" them. Do you maybe see how THE GUBBMINT might be interested in knowing if other browsers, such as Chrome, are as vulnerable?

But by all means, put on your tinfoil hats if that's more fun.

Re: Google Chrome Hacked?

#92
post #49

Earlier quoted context omitted.

I'm confused. Why would the government want to break Chrome? Also, if they are not going to release the exploit soon (especially to Google), why are you saying 'safer software for all'?

you know that there is more than one government on earth... and all of them arent pro free-speech :) Safer software for all, because it's a better thing that VUPEN discover the bug than if it's discovered by some criminals who keep it secret and scam/hack

> Safer software for all, because it's a better thing that VUPEN discover the bug than if it's discovered by some criminals who keep it secret and scam/hack

I suppose it depends on the point of view, but having it exclusively in the hands of governments can easily mean it's limited to criminals who keep it secret and hack.

Re: Google Chrome Hacked?

#93
post #79
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

why do they announce it at all then?

Advertising?

Re: Google Chrome Hacked?

#94
post #23

vupen: "Hey Google, your browser has a very nasty bug that allows for potentially horrible things to happen. We thought we'd share that with the world. If you'd like to know where it is though, you'd better give us money."

I'm tired of doing volunteer work for corporations, personally.

Re: Google Chrome Hacked?

#95
post #49

Earlier quoted context omitted.

I'm confused. Why would the government want to break Chrome? Also, if they are not going to release the exploit soon (especially to Google), why are you saying 'safer software for all'?

you know that there is more than one government on earth... and all of them arent pro free-speech :) Safer software for all, because it's a better thing that VUPEN discover the bug than if it's discovered by some criminals who keep it secret and scam/hack

Thanks for your response, but my question remains.

Why would a entity as big as "the government" would invest in breaking one browser used by a minority (~10%) of users in the web? Wouldn't it be much easier to just compromise their Internet connections?

Re: Google Chrome Hacked?

#96
post #55
post #42

Earlier quoted context omitted.

I am still waiting for that obvious evidence. That includes more details and also tests on the latest dev version of Chrome (Chromium). I am not defending Google in any way, but some claim with no real evidence shouldn't convince anybody.

I saw a similar mentality on the Skype for Mac thread, as if there is a huge incentive to just make up vulnerabilities. More or less, when HN threads don't want something to be true ("terrible Chrome vulnerability with no public info and no pending patch!"), they make up controversies to keep them from having to accept that it's true. It's a bad habit.

I have over the years participated on a number of communities "for smart people", and this is the case in all of them. People have their particular points of view, and when there is some evidence against what the group considers to be good they use all kinds of ad-hominem attacks. I know it is just human nature, but it is sad that people don't see these patterns occurring.

Re: Google Chrome Hacked?

#97
Looking at the video and time it took to launch the calc.exe, it could be pdf/flash exploit that they are using.

Process count in process explorer started with 5 and at the end of the demo, it looked like they have 8. That tells there are 2 extra processes that are created (discounting 1 for calc.exe).

I tried to see if pdf/flash creates new processes but I couldn't verify. Perhaps a chrome developer could get a clue about what is happening looking at the video.

Re: Google Chrome Hacked?

#98
post #95

Earlier quoted context omitted.

you know that there is more than one government on earth... and all of them arent pro free-speech :) Safer software for all, because it's a better thing that VUPEN discover the bug than if it's discovered by some criminals who keep it secret and scam/hack

Thanks for your response, but my question remains. Why would a entity as big as "the government" would invest in breaking one browser used by a minority (~10%) of users in the web? Wouldn't it be much easier to just compromise their Internet connections?

[deleted]

Re: Google Chrome Hacked?

#99
post #57

Earlier quoted context omitted.

One difference is that it appears that these VUPEN folks are not entirely incompetent.

people were telling the same about HBGary before they started to tell the opposite. Though my post isn't about technical brilliance. Being in bed with Power and relaxing one's moral standards to better serve it always leads the same way....

> it always leads the same way....

To profit? I believe most people would get into bed with the government if offered the correct incentives. I probably would, too. It's unfortunate, but that's how things work. Is it immoral not to relax your morals to, e.g., secure a better life for yourself and your family?

(Apologies for being meta, but I've recently begun studying morality/ethics so I'm exploring ideas for which I currently do not have answers. Suggestions/directions are appreciated.)

Re: Google Chrome Hacked?

#100
A video of calculator showing up after clicking a link hardly constitutes proof of an exploit.

Considering the fact that they aren't going to publish the exploit, I just want to point out that this kind of thing could easily be fabricated. There are plenty of interests that benefit from unfortunate news about their competitors.

Post reply on HN