Live data from Hacker News

Google Chrome Hacked?

vupen.com

121–130 of 223 posts

Re: Google Chrome Hacked?

#121

Earlier quoted context omitted.

Police don't really "protect" anyone, their job is to cleanup the mess and investigate after the fact.

They use intimidation and other tactics to keep crime confined to certain neighborhoods. They have a lot of strategies geared toward prevention. If the police fail to respond to calls in the ghetto then the crime in the ghetto increases, for instance.

I'm curious if you have a link to decent evidence of this. From both personal experience and per city data I've found, police response times are universally pretty dismal but I would be interested to see the same data broken down by neighborhood.

Re: Google Chrome Hacked?

#122
post #117
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

LOL, and Google does not have enough money to pay them a few measly billions to help fix their crown jewel chrome browser?? Don't make me laugh like that! Poor Google, not enough money, that'll be the day. These things should not in my opinion be disclosed to (the idiot skript kiddie segment of) the public before the vendors have been given a good long window to fix them. I prefer what VUPEN does when compared to irr…

"VUPEN provides vulnerability research and intelligence for defensive and offensive security." so, they are I presume happy to help the US CIA/MIL fvck people over (who most likely don't deserve it).

Re: Google Chrome Hacked?

#123
post #117
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

LOL, and Google does not have enough money to pay them a few measly billions to help fix their crown jewel chrome browser?? Don't make me laugh like that! Poor Google, not enough money, that'll be the day. These things should not in my opinion be disclosed to (the idiot skript kiddie segment of) the public before the vendors have been given a good long window to fix them. I prefer what VUPEN does when compared to irr…

You have solid points, but your rhetoric and diction is unnecessarily inflammatory and immature.

Re: Google Chrome Hacked?

#124
post #55

Earlier quoted context omitted.

I saw a similar mentality on the Skype for Mac thread, as if there is a huge incentive to just make up vulnerabilities. More or less, when HN threads don't want something to be true ("terrible Chrome vulnerability with no public info and no pending patch!"), they make up controversies to keep them from having to accept that it's true. It's a bad habit.

I have over the years participated on a number of communities "for smart people", and this is the case in all of them. People have their particular points of view, and when there is some evidence against what the group considers to be good they use all kinds of ad-hominem attacks. I know it is just human nature, but it is sad that people don't see these patterns occurring.

Be fair. Exceptional claims require exceptional evidence. They offer no evidence at all. Scepticism is healthy.

Re: Google Chrome Hacked?

#125
post #78

Earlier quoted context omitted.

This is probably why they keep repeating that their customer is the government. You could probably sell Exxon's security vulnerabilities to the government and demand $N dollars from them to show them how to fix the problem. It's advertising the vulnerability with posts like this that seems most questionable (similar to extortion) to me.

Yeah, that's the part that seemed odd to me as well, though someone knowledgeable in this area of law (at least in the better-settled offline case) could give some better info. I believe it'd be okay, and probably actually happens, for a private security consultant to do threat assessments for a (non-criminal) client, e.g. prepare a report for DHS on the security of U.S. oil installations. But it seems like they'd be…

Google could easily sue them into oblivion for libel. They would be forced to reveal the exploit during proceedings to prove their innocence.

Re: Google Chrome Hacked?

#126
post #55

Earlier quoted context omitted.

I saw a similar mentality on the Skype for Mac thread, as if there is a huge incentive to just make up vulnerabilities. More or less, when HN threads don't want something to be true ("terrible Chrome vulnerability with no public info and no pending patch!"), they make up controversies to keep them from having to accept that it's true. It's a bad habit.

I have over the years participated on a number of communities "for smart people", and this is the case in all of them. People have their particular points of view, and when there is some evidence against what the group considers to be good they use all kinds of ad-hominem attacks. I know it is just human nature, but it is sad that people don't see these patterns occurring.

What slashdot and Kuro5hin?

Re: Google Chrome Hacked?

#127
This video is extremely suspicious to the point of probably being an outright lie. I would wager money that this vulnerability is a Flash exploit sold as a Chrome exploit.

It is not an accident that they hid Process Explorer after the exploit. They closed it before minimizing everything else intentionally. If you do not believe me follow the mouse pointer. The screencaster moved toward bringing Process Explorer top-level at 0:56 then realized it would show the entire thing and restored Chrome on top of it instead. With that in mind it is obvious that they do not want you to see what changed when it ran so instead we have to work with what is visible:

Process Explorer before: http://i.imgur.com/e31Rb.png

Process Explorer after: http://i.imgur.com/JfPTY.png

First item of interest is that Chrome shot up to over 400 MB of memory used which indicates that Flash is almost certainly involved.

Second, observe how long it takes for Calculator to start. Again, consistent with Flash being involved and Chrome delay-loading it.

Third, there are scroll bars on the tab. Big ones. This says there is an invisible item on the page taking up a lot of space which again points to Flash. I saved the exact same content to a file and look how small I can go without scroll bars: http://i.imgur.com/R0eqk.png

Fourth, flip back side by side through each photo and notice what disappears. The Windows search indexer disappears between screenshot A and B and this is what Vupen is intentionally covering up. You can still observe it indirectly based on the rows and colors at right. It is my understanding that the child processes of SearchIndexer.exe run at all times and not as some kind of cron but I do not use Windows so please correct me if I am wrong. At any rate they do disappear between A and B.

It would be very intelligent of them to blog post this as a Chrome sandbox bust (which is sort of newsworthy) and gain that link bait attention but, privately, use the exploit as the Flash and Windows vulnerability it most likely is.

Re: Google Chrome Hacked?

#128

Earlier quoted context omitted.

http://www.vupen.com/english/services/ > As the world leader in vulnerability research, VUPEN Security provides weaponized and highly sophisticated exploits specifically designed for Law Enforcement and Intelligence Agencies to help them achieve their offensive missions using tailored and unique codes created in-house by VUPEN for vulnerabilities discovered by our researchers. Note also the "under contract with VUPEN…

Law Enforcement and Intelligence Agencies Which countries? It does not specifically state US.

I'm pretty sure they limit their customer base to NATO signatories.

Re: Google Chrome Hacked?

#129

To what extent is this extortion? I mean, they have admitted to only selling to a government. That means they find and exploit vulnerabilities in software created by a private corporation, disclose the existence of a vulnerability publicly, but don't allow the corporate body the means of fixing it. This news, if publicised, would harm Google's reputation and goodwill, perhaps non-negligibly, and cause users to switch…

I don't believe this crappy little security firm has more resources than Google, even in the Security Research Dept. They can go find it themselves and fix it. Anyway, it's probably mostly a windows bug. If you line the right bytes up together in windows' RAM, it will void itself and yield 'root' or whatever wiener name they have for it. Who knows, maybe they Govt is trying to screw google, and told them to do a fake release. Their post doesn't make them sound like real pros.

Re: Google Chrome Hacked?

#130
post #31
post #24

Earlier quoted context omitted.

The reality is that there is probably no chance that they would ever find these bugs if they weren't funded to do it and the only way to be funded is to have customers. The net result is probably safer software for all.

The net result in this case is the government owning a zero-day root exploit for every Chrome/Win citizen’s computer. It’s worse than zero-day because we have no reason to expect a patch, so the window of attack will stay open.

so, avoid .gov and similar :) it's a silly TLD anyway.

Did the .gov pwn TPB and put their exploit up there?

Post reply on HN