Live data from Hacker News

Google Chrome Hacked?

vupen.com

111–120 of 223 posts

Re: Google Chrome Hacked?

#111

Earlier quoted context omitted.

The government is generally more worried about keeping foreign governments out of high-tech firms like Google than about their ability to hack high-tech firms like Google.

Which government are you referring to?

think he was being generic. as in "the man".

Re: Google Chrome Hacked?

#112

Earlier quoted context omitted.

Do police protect inner city poverty-stricken people victimized by gangs? It's pretty easy to argue that police only protect those who pay them.

Police don't really "protect" anyone, their job is to cleanup the mess and investigate after the fact.

They use intimidation and other tactics to keep crime confined to certain neighborhoods. They have a lot of strategies geared toward prevention.

If the police fail to respond to calls in the ghetto then the crime in the ghetto increases, for instance.

Re: Google Chrome Hacked?

#113
post #78

Earlier quoted context omitted.

Publicly announcing a security vulnerability, claiming that you're sharing it with other clients with the intent of using it for "weaponized ... offensive missions", and then demanding a fee to gain the information to protect against said weaponization, sounds an awful lot like extortion. In the offline world, I don't think you can legally run a business with a strategy of: discover a problem in the security at one o…

This is probably why they keep repeating that their customer is the government. You could probably sell Exxon's security vulnerabilities to the government and demand $N dollars from them to show them how to fix the problem. It's advertising the vulnerability with posts like this that seems most questionable (similar to extortion) to me.

I'd imagine that depends on which government you're talking about. Seems like selling the info to a foreign government could be treading into "espionage" territory.

Re: Google Chrome Hacked?

#114
post #57

Earlier quoted context omitted.

One difference is that it appears that these VUPEN folks are not entirely incompetent.

people were telling the same about HBGary before they started to tell the opposite. Though my post isn't about technical brilliance. Being in bed with Power and relaxing one's moral standards to better serve it always leads the same way....

excellent point.

relaxing more standards on par to being incompetent. only a little more damaging.

Re: Google Chrome Hacked?

#116
post #7

Earlier quoted context omitted.

Citation needed for such a serious accusation. They claim to be ethical. From their about page: "VUPEN follows a private responsible disclosure policy and reports all discovered vulnerabilities to the affected vendor under contract with VUPEN, and works with them to create a timetable pursuant to which the vulnerability information may be publicly disclosed."

http://www.vupen.com/english/services/ > As the world leader in vulnerability research, VUPEN Security provides weaponized and highly sophisticated exploits specifically designed for Law Enforcement and Intelligence Agencies to help them achieve their offensive missions using tailored and unique codes created in-house by VUPEN for vulnerabilities discovered by our researchers. Note also the "under contract with VUPEN…

Law Enforcement and Intelligence Agencies

Which countries? It does not specifically state US.

Re: Google Chrome Hacked?

#117
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

LOL, and Google does not have enough money to pay them a few measly billions to help fix their crown jewel chrome browser?? Don't make me laugh like that! Poor Google, not enough money, that'll be the day.

These things should not in my opinion be disclosed to (the idiot skript kiddie segment of) the public before the vendors have been given a good long window to fix them.

I prefer what VUPEN does when compared to irresponsible discoveries by black hats who do not give a shit about the integrity of the installed product and privacy / safety / security of how many millions of users, who can then be screwed over by every skript kiddie and his dog because they released the info straight to the public.

Sure, if the vendor has absolutely ignored you and your loud demos of the bug, and won't respond to threats to release, you might release the exploit to a small segment of the IRREPROACHABLE VANILLA WHITE HAT security community with the intention that they might help persuade the vendor to take it seriously. That's about as far as I'd want go with releasing serious exploits. Although of course grey/black hat stuff is fun - look, mum, I have a cool exploit!

If VUPEN are sworn to secrecy by their Government customer, and cannot tell the vendor or help them fix the bug, maybe it's time to get a new Government and public service. Your Government (US arrogances with a captial G) is trying to pwn you and spy on you. Fuck that, the government should answer to the will of the people (and don't talk to me about the farce we call democratic election. Democracy is where (almost) all the people are deeply involved in determining policy, it's more like the ideal soviet system, really, which was not realized AFAIK.)

Anyway, isn't that why you're carting guns around all these years, in case your (US) Government turns nasty and starts pwning your ass up down right and left with a canoe? (Not that it wasn't already.) Yes indeed, guns!! However let it not be said that I am inciting violent revolution with this sarcastic post, as I don't believe in or wish to promote that or any violent act.

Poor Google, not enough money. LOL!

Re: Google Chrome Hacked?

#118
post #78

Earlier quoted context omitted.

Publicly announcing a security vulnerability, claiming that you're sharing it with other clients with the intent of using it for "weaponized ... offensive missions", and then demanding a fee to gain the information to protect against said weaponization, sounds an awful lot like extortion. In the offline world, I don't think you can legally run a business with a strategy of: discover a problem in the security at one o…

This is probably why they keep repeating that their customer is the government. You could probably sell Exxon's security vulnerabilities to the government and demand $N dollars from them to show them how to fix the problem. It's advertising the vulnerability with posts like this that seems most questionable (similar to extortion) to me.

Which government(s)?

Re: Google Chrome Hacked?

#119
To what extent is this extortion? I mean, they have admitted to only selling to a government. That means they find and exploit vulnerabilities in software created by a private corporation, disclose the existence of a vulnerability publicly, but don't allow the corporate body the means of fixing it. This news, if publicised, would harm Google's reputation and goodwill, perhaps non-negligibly, and cause users to switch products. Unless, of course, Google outbids a government. Pay up or suffer - would this be extortion?

Re: Google Chrome Hacked?

#120
post #109
post #97

Looking at the video and time it took to launch the calc.exe, it could be pdf/flash exploit that they are using. Process count in process explorer started with 5 and at the end of the demo, it looked like they have 8. That tells there are 2 extra processes that are created (discounting 1 for calc.exe). I tried to see if pdf/flash creates new processes but I couldn't verify. Perhaps a chrome developer could get a clue…

They are obviously hiding something. When they flip back to Process Explorer, Chrome is perfectly sized to cover everything in the window except the calc.exe. My guess is there are other processes running that they're trying to hide that were used in the exploit.

[deleted]
Post reply on HN