Earlier quoted context omitted.
Police don't really "protect" anyone, their job is to cleanup the mess and investigate after the fact.
They use intimidation and other tactics to keep crime confined to certain neighborhoods. They have a lot of strategies geared toward prevention. If the police fail to respond to calls in the ghetto then the crime in the ghetto increases, for instance.
Google Chrome Hacked?
121–130 of 223 posts
Re: Google Chrome Hacked?
#122Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…
LOL, and Google does not have enough money to pay them a few measly billions to help fix their crown jewel chrome browser?? Don't make me laugh like that! Poor Google, not enough money, that'll be the day. These things should not in my opinion be disclosed to (the idiot skript kiddie segment of) the public before the vendors have been given a good long window to fix them. I prefer what VUPEN does when compared to irr…
Re: Google Chrome Hacked?
#123Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…
LOL, and Google does not have enough money to pay them a few measly billions to help fix their crown jewel chrome browser?? Don't make me laugh like that! Poor Google, not enough money, that'll be the day. These things should not in my opinion be disclosed to (the idiot skript kiddie segment of) the public before the vendors have been given a good long window to fix them. I prefer what VUPEN does when compared to irr…
Re: Google Chrome Hacked?
#124Earlier quoted context omitted.
I saw a similar mentality on the Skype for Mac thread, as if there is a huge incentive to just make up vulnerabilities. More or less, when HN threads don't want something to be true ("terrible Chrome vulnerability with no public info and no pending patch!"), they make up controversies to keep them from having to accept that it's true. It's a bad habit.
I have over the years participated on a number of communities "for smart people", and this is the case in all of them. People have their particular points of view, and when there is some evidence against what the group considers to be good they use all kinds of ad-hominem attacks. I know it is just human nature, but it is sad that people don't see these patterns occurring.
Re: Google Chrome Hacked?
#125Earlier quoted context omitted.
This is probably why they keep repeating that their customer is the government. You could probably sell Exxon's security vulnerabilities to the government and demand $N dollars from them to show them how to fix the problem. It's advertising the vulnerability with posts like this that seems most questionable (similar to extortion) to me.
Yeah, that's the part that seemed odd to me as well, though someone knowledgeable in this area of law (at least in the better-settled offline case) could give some better info. I believe it'd be okay, and probably actually happens, for a private security consultant to do threat assessments for a (non-criminal) client, e.g. prepare a report for DHS on the security of U.S. oil installations. But it seems like they'd be…
Re: Google Chrome Hacked?
#126Earlier quoted context omitted.
I saw a similar mentality on the Skype for Mac thread, as if there is a huge incentive to just make up vulnerabilities. More or less, when HN threads don't want something to be true ("terrible Chrome vulnerability with no public info and no pending patch!"), they make up controversies to keep them from having to accept that it's true. It's a bad habit.
I have over the years participated on a number of communities "for smart people", and this is the case in all of them. People have their particular points of view, and when there is some evidence against what the group considers to be good they use all kinds of ad-hominem attacks. I know it is just human nature, but it is sad that people don't see these patterns occurring.
Re: Google Chrome Hacked?
#127It is not an accident that they hid Process Explorer after the exploit. They closed it before minimizing everything else intentionally. If you do not believe me follow the mouse pointer. The screencaster moved toward bringing Process Explorer top-level at 0:56 then realized it would show the entire thing and restored Chrome on top of it instead. With that in mind it is obvious that they do not want you to see what changed when it ran so instead we have to work with what is visible:
Process Explorer before: http://i.imgur.com/e31Rb.png
Process Explorer after: http://i.imgur.com/JfPTY.png
First item of interest is that Chrome shot up to over 400 MB of memory used which indicates that Flash is almost certainly involved.
Second, observe how long it takes for Calculator to start. Again, consistent with Flash being involved and Chrome delay-loading it.
Third, there are scroll bars on the tab. Big ones. This says there is an invisible item on the page taking up a lot of space which again points to Flash. I saved the exact same content to a file and look how small I can go without scroll bars: http://i.imgur.com/R0eqk.png
Fourth, flip back side by side through each photo and notice what disappears. The Windows search indexer disappears between screenshot A and B and this is what Vupen is intentionally covering up. You can still observe it indirectly based on the rows and colors at right. It is my understanding that the child processes of SearchIndexer.exe run at all times and not as some kind of cron but I do not use Windows so please correct me if I am wrong. At any rate they do disappear between A and B.
It would be very intelligent of them to blog post this as a Chrome sandbox bust (which is sort of newsworthy) and gain that link bait attention but, privately, use the exploit as the Flash and Windows vulnerability it most likely is.
Re: Google Chrome Hacked?
#128Earlier quoted context omitted.
http://www.vupen.com/english/services/ > As the world leader in vulnerability research, VUPEN Security provides weaponized and highly sophisticated exploits specifically designed for Law Enforcement and Intelligence Agencies to help them achieve their offensive missions using tailored and unique codes created in-house by VUPEN for vulnerabilities discovered by our researchers. Note also the "under contract with VUPEN…
Law Enforcement and Intelligence Agencies Which countries? It does not specifically state US.
Re: Google Chrome Hacked?
#129To what extent is this extortion? I mean, they have admitted to only selling to a government. That means they find and exploit vulnerabilities in software created by a private corporation, disclose the existence of a vulnerability publicly, but don't allow the corporate body the means of fixing it. This news, if publicised, would harm Google's reputation and goodwill, perhaps non-negligibly, and cause users to switch…
Re: Google Chrome Hacked?
#130Earlier quoted context omitted.
The reality is that there is probably no chance that they would ever find these bugs if they weren't funded to do it and the only way to be funded is to have customers. The net result is probably safer software for all.
The net result in this case is the government owning a zero-day root exploit for every Chrome/Win citizen’s computer. It’s worse than zero-day because we have no reason to expect a patch, so the window of attack will stay open.
Did the .gov pwn TPB and put their exploit up there?