Live data from Hacker News

Google Chrome Hacked?

vupen.com

151–160 of 223 posts

Re: Google Chrome Hacked?

#151
post #149

Earlier quoted context omitted.

On an otherwise empty page? Yes, it is extremely likely when combined with the payload delay. If you manage to make a single tab commit that much memory as a delta without Flash (remember, 13 MB to > 400 MB) please screenshot about:memory and get back to me. The scroll bars on the tab are revealing, too. I may be guessing but it is an educated guess. Additionally, there were multiple claims so I would not call that s…

No, it's not extremely likely. Given that most browser exploits utilize some sort of a heap spray, a growing memory usage is almost standard pattern for a browser vuln.

The delay? The scroll bars?

There is evidence that this is Flash. However, since everyone seems to want to attack individual parts of that evidence without applying Occam's Razor, I concede it could be something other than Flash. It could be Java, too. It could be a "standard browser exploit" too, whatever that is. Could be cosmic rays too.

The tendency to look for ways to prove me wrong with an alternate theory (which yours is) as opposed to acknowledging that multiple theories are possible with zero evidence aggravates me among technical people. In the absence of a disclosure we are both right.

Re: Google Chrome Hacked?

#152

Earlier quoted context omitted.

Yeah, that's the part that seemed odd to me as well, though someone knowledgeable in this area of law (at least in the better-settled offline case) could give some better info. I believe it'd be okay, and probably actually happens, for a private security consultant to do threat assessments for a (non-criminal) client, e.g. prepare a report for DHS on the security of U.S. oil installations. But it seems like they'd be…

Google could easily sue them into oblivion for libel. They would be forced to reveal the exploit during proceedings to prove their innocence.

one is not obliged to prove innocence in a sensible court of law

Re: Google Chrome Hacked?

#153
post #43

Earlier quoted context omitted.

Why not? This is highly specialized research that not even well-paid Google employees were able to do. This is actually quite common in recent years for bug hunters and exploit developers. I can think of a dozen or so companies that do the same thing. Immunity is another example. Trying to use a moral argument to get out of compensating someone when you have the resources to do so is shameful. Sorry, but this stuff i…

"Why not? This is highly specialized research that not even well-paid Google employees were able to do." Correction: not even well-paid Google employees did . They may yet be able, and an existence proof may be all the help they need to find and fix it. Don't give up hope yet.

I can fix it right now. Delete the flash player - problem solved. Chrome still works.

Re: Google Chrome Hacked?

#154

Earlier quoted context omitted.

Do police protect inner city poverty-stricken people victimized by gangs? It's pretty easy to argue that police only protect those who pay them.

Police don't really "protect" anyone, their job is to cleanup the mess and investigate after the fact.

> Police don't really "protect" anyone

Sure they do, they discourage crime by finding and jailing criminals. Prevention is protection.

Re: Google Chrome Hacked?

#155
post #149

Earlier quoted context omitted.

On an otherwise empty page? Yes, it is extremely likely when combined with the payload delay. If you manage to make a single tab commit that much memory as a delta without Flash (remember, 13 MB to > 400 MB) please screenshot about:memory and get back to me. The scroll bars on the tab are revealing, too. I may be guessing but it is an educated guess. Additionally, there were multiple claims so I would not call that s…

No, it's not extremely likely. Given that most browser exploits utilize some sort of a heap spray, a growing memory usage is almost standard pattern for a browser vuln.

so google can fix it for 99% cases with ulimit or similar windows thing. problem solved

Re: Google Chrome Hacked?

#156
post #155
post #149

Earlier quoted context omitted.

No, it's not extremely likely. Given that most browser exploits utilize some sort of a heap spray, a growing memory usage is almost standard pattern for a browser vuln.

so google can fix it for 99% cases with ulimit or similar windows thing. problem solved

No, Google can fix by not letting programs downloaded from the Internet write to arbitrary memory locations.

Actually, you can fix it, too: chromium is open source.

Re: Google Chrome Hacked?

#157
post #142

Earlier quoted context omitted.

I don't see why not. As long as you don't actually break into Exxon and commit I crime. The real reason your scenario is unlikely is just that Exxon practically owns the government, so they would change the laws or something to fuck you over. But I mean what if you discovered a security vulnerability at McDonalds or something, a way to pick their locks. Why are you morally obligated to disclose it without compensatio…

It is possible to be an accessory to a crime. If you plan a bank robbery and give the details to somebody else to perform, you're still guilty. Hell, you're still guilty even if you never perform the crime (conspiracy to commit ...)! If you send a letter to a bank saying "I have found a breach in the kind of vault you use at your banks, I'm giving the details to some expert robbers but you can't have it unless you pa…

FYI, the industry has rejected the doublespeak term "responsible disclosure". Even Microsoft has issued statements denouncing the term. Most prefer to call that "coordinated disclosure". This accurately communicates the idea, without sneaking in someone's moral judgement.

Re: Google Chrome Hacked?

#158

Earlier quoted context omitted.

On an exploit like this, I expect a patch. I'm sure people at Google and abroad (if the exploit exists in Chromium) are scrambling to find it, both for the e-cred and just to make other people safer.

Agreed, no need to freak out, the sky's not falling. I expect Google will either find the spoit on their own, or pay what to them is a pitance to become a customer and acquire it that way. Sounds like a good company to have on the payroll anyway, doing what three years of Pwn2own hasn't managed to.

they did say "exclusive"

Re: Google Chrome Hacked?

#159

Earlier quoted context omitted.

On an exploit like this, I expect a patch. I'm sure people at Google and abroad (if the exploit exists in Chromium) are scrambling to find it, both for the e-cred and just to make other people safer.

Agreed, no need to freak out, the sky's not falling. I expect Google will either find the spoit on their own, or pay what to them is a pitance to become a customer and acquire it that way. Sounds like a good company to have on the payroll anyway, doing what three years of Pwn2own hasn't managed to.

I thought Pwn2own didn't even try to?

Re: Google Chrome Hacked?

#160
post #44
post #31

Earlier quoted context omitted.

The net result in this case is the government owning a zero-day root exploit for every Chrome/Win citizen’s computer. It’s worse than zero-day because we have no reason to expect a patch, so the window of attack will stay open.

Out of speculation, would this tie in at all to an article I saw on HN a while back about the Government hiring 3rd parties to hack Google for some reason?

maybe Govt is envious because Google is already more powerful and capable and certainly better liked than it!
Post reply on HN