Live data from Hacker News

Google Chrome Hacked?

vupen.com

101–110 of 223 posts

Re: Google Chrome Hacked?

#101
post #23

vupen: "Hey Google, your browser has a very nasty bug that allows for potentially horrible things to happen. We thought we'd share that with the world. If you'd like to know where it is though, you'd better give us money."

I think you'd be biting off the hand that feeds you. If you eliminate what is arguably a distasteful arrangement here, you also eliminate the incentive to continue doing it. You might get this bug for free, but you get a hidden loss, a bunch of future bugs that you'll never hear about.

Think about the audacity of farmers, who make a profit for food, which you need to live. But nobody thinks like that for some reason.

Earning profit just means you've done something for someone who really wanted it done. It's a necessary signal.

Re: Google Chrome Hacked?

#102

Earlier quoted context omitted.

Wouldn't "the government" keep quiet about even having found an exploit? Why let VUPEN publicize this if they intend to use it?

The government is generally more worried about keeping foreign governments out of high-tech firms like Google than about their ability to hack high-tech firms like Google.

Which government are you referring to?

Re: Google Chrome Hacked?

#103
post #11

Not saying this isn't true, as I'm sure VUPEN is quite legit, but what stops me from creating a keyboard shortcut to calculator.exe, opening a random website which loads for a few seconds, and then pressing ctrl+alt+f6 or something to open calculator?

If you're sure it is quite legit, why are you suggesting this? It is similar to what news networks do by adding a quotation mark to something they know is false just to suggest something they want to be true.

Re: Google Chrome Hacked?

#104
post #42

Earlier quoted context omitted.

Who cares if they sound unprofessional to you? Very obviously they produce.

I am still waiting for that obvious evidence. That includes more details and also tests on the latest dev version of Chrome (Chromium). I am not defending Google in any way, but some claim with no real evidence shouldn't convince anybody.

Given that at least some of their customers will probably ask for this vulnerability, you have to judge whether this is a reputable company that would have a reputation to lose if they started spewing out false reports about their capabilities. It appears to be, so I would default to believing it.

Re: Google Chrome Hacked?

#105
post #49
post #24

Earlier quoted context omitted.

The reality is that there is probably no chance that they would ever find these bugs if they weren't funded to do it and the only way to be funded is to have customers. The net result is probably safer software for all.

I'm confused. Why would the government want to break Chrome? Also, if they are not going to release the exploit soon (especially to Google), why are you saying 'safer software for all'?

Maybe I'm naive but it could simply be because they are evaluating it for internal use. The FBI and CIA don't want to use vulnerable browsers any more than we do.

Re: Google Chrome Hacked?

#106
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

[deleted]

Re: Google Chrome Hacked?

#107
post #31

Earlier quoted context omitted.

The net result in this case is the government owning a zero-day root exploit for every Chrome/Win citizen’s computer. It’s worse than zero-day because we have no reason to expect a patch, so the window of attack will stay open.

On an exploit like this, I expect a patch. I'm sure people at Google and abroad (if the exploit exists in Chromium) are scrambling to find it, both for the e-cred and just to make other people safer.

Agreed, no need to freak out, the sky's not falling. I expect Google will either find the spoit on their own, or pay what to them is a pitance to become a customer and acquire it that way. Sounds like a good company to have on the payroll anyway, doing what three years of Pwn2own hasn't managed to.

Re: Google Chrome Hacked?

#108
post #56

Earlier quoted context omitted.

That's a poor example. Policeman get paid to protect everyone; police protection is not (usually) a subscription service.

Do police protect inner city poverty-stricken people victimized by gangs? It's pretty easy to argue that police only protect those who pay them.

Police don't really "protect" anyone, their job is to cleanup the mess and investigate after the fact.

Re: Google Chrome Hacked?

#109
post #97

Looking at the video and time it took to launch the calc.exe, it could be pdf/flash exploit that they are using. Process count in process explorer started with 5 and at the end of the demo, it looked like they have 8. That tells there are 2 extra processes that are created (discounting 1 for calc.exe). I tried to see if pdf/flash creates new processes but I couldn't verify. Perhaps a chrome developer could get a clue…

They are obviously hiding something. When they flip back to Process Explorer, Chrome is perfectly sized to cover everything in the window except the calc.exe. My guess is there are other processes running that they're trying to hide that were used in the exploit.

Re: Google Chrome Hacked?

#110
post #23

vupen: "Hey Google, your browser has a very nasty bug that allows for potentially horrible things to happen. We thought we'd share that with the world. If you'd like to know where it is though, you'd better give us money."

I think you'd be biting off the hand that feeds you. If you eliminate what is arguably a distasteful arrangement here, you also eliminate the incentive to continue doing it. You might get this bug for free, but you get a hidden loss, a bunch of future bugs that you'll never hear about. Think about the audacity of farmers, who make a profit for food, which you need to live . But nobody thinks like that for some reason…

I felt the same way until this comment below:

> http://www.vupen.com/english/services/ > As the world leader in vulnerability research, VUPEN Security provides weaponized and highly sophisticated exploits specifically designed for Law Enforcement and Intelligence Agencies to help them achieve their offensive missions using tailored and unique codes created in-house by VUPEN for vulnerabilities discovered by our researchers. Note also the "under contract with VUPEN" part of the disclosure bit.

Post reply on HN