Live data from Hacker News

Google Chrome Hacked?

vupen.com

161–170 of 223 posts

Re: Google Chrome Hacked?

#161
post #149

Earlier quoted context omitted.

No, it's not extremely likely. Given that most browser exploits utilize some sort of a heap spray, a growing memory usage is almost standard pattern for a browser vuln.

The delay? The scroll bars? There is evidence that this is Flash. However, since everyone seems to want to attack individual parts of that evidence without applying Occam's Razor, I concede it could be something other than Flash. It could be Java, too. It could be a "standard browser exploit" too, whatever that is. Could be cosmic rays too. The tendency to look for ways to prove me wrong with an alternate theory (whi…

You seem to only want to receive an answer that starts with "You bring up credible evidence, but maybe there's an alternate scenario playing out here, for which I believe the following holds true..." Now I can do that, but since we're all speculating, this is implied. No one is saying you're dead wrong, we're just posting alternate hypothesis and you're taking this very personally.

Let's apply Occam's razor: a) There is no reason why Flash (or another plugin) needs to take up a large amount of space on the page. If I were to write a flash exploit, it'd be a 1x1 object with whatever ActionScript that triggers the vulnerability, no need for a large area. b) VUPEN is a bunch of extremely talented folks and I believe they have little to gain by posting a fabricated exploit video. c) The delay can also be caused by a rather advanced heap-grooming technique, it can be JS garbage collection invoked many times, it can literally be them trying the payload numerous times. Implying it's probably flash is just as speculative as we're being.

Relax man, no one's disagreeing with you to be an asshole, no one's trying to argue with you, we're all just speculating.

Re: Google Chrome Hacked?

#162
post #155

Earlier quoted context omitted.

so google can fix it for 99% cases with ulimit or similar windows thing. problem solved

No, Google can fix by not letting programs downloaded from the Internet write to arbitrary memory locations. Actually, you can fix it, too: chromium is open source.

Actually, you can fix it, too: chromium is open source.

Good to see this tired claim getting its play in this thread. I wondered how long it would be until it showed up. I think everyone who says "go fix it, it's open-source" should instead be required to come back with a diff within 24 hours.

Re: Google Chrome Hacked?

#163
post #49
post #24

Earlier quoted context omitted.

The reality is that there is probably no chance that they would ever find these bugs if they weren't funded to do it and the only way to be funded is to have customers. The net result is probably safer software for all.

I'm confused. Why would the government want to break Chrome? Also, if they are not going to release the exploit soon (especially to Google), why are you saying 'safer software for all'?

The Govt in question is obviously the US Govt. They want to know how to break Chrome, and every other net-facing app, so that they can hack your computer and spy on you, whoever you might be. Did you know, the CIA does do espionage?

Re: Google Chrome Hacked?

#164
post #153
post #43

Earlier quoted context omitted.

"Why not? This is highly specialized research that not even well-paid Google employees were able to do." Correction: not even well-paid Google employees did . They may yet be able, and an existence proof may be all the help they need to find and fix it. Don't give up hope yet.

I can fix it right now. Delete the flash player - problem solved. Chrome still works.

Sadly, one aspect of security is psychological acceptability. If nobody will do the secure thing, it's not secure.

Re: Google Chrome Hacked?

#165

Earlier quoted context omitted.

you know that there is more than one government on earth... and all of them arent pro free-speech :) Safer software for all, because it's a better thing that VUPEN discover the bug than if it's discovered by some criminals who keep it secret and scam/hack

Arguably, that's exactly what VUPEN is doing here. They're keeping it secret, and only letting those who are willing to pay have the necessary knowledge regarding this vulnerability and any possible workarounds. It might not be a scam, but I do find it morally questionable to hide the details of a bug of this significance.

s/ those who are willing to pay / those (ONLY) who asked for and funded research into such a hack /

Re: Google Chrome Hacked?

#166
post #95

Earlier quoted context omitted.

you know that there is more than one government on earth... and all of them arent pro free-speech :) Safer software for all, because it's a better thing that VUPEN discover the bug than if it's discovered by some criminals who keep it secret and scam/hack

Thanks for your response, but my question remains. Why would a entity as big as "the government" would invest in breaking one browser used by a minority (~10%) of users in the web? Wouldn't it be much easier to just compromise their Internet connections?

Let's say that, like most everyone else in the world, they already know how to break firefox and internet explorer, etc. They don't want to spy on your net, they want to steal your files.

Re: Google Chrome Hacked?

#167
post #163
post #49

Earlier quoted context omitted.

I'm confused. Why would the government want to break Chrome? Also, if they are not going to release the exploit soon (especially to Google), why are you saying 'safer software for all'?

The Govt in question is obviously the US Govt. They want to know how to break Chrome, and every other net-facing app, so that they can hack your computer and spy on you, whoever you might be. Did you know, the CIA does do espionage?

Yeah, and no other governments do, especially not the french...

Re: Google Chrome Hacked?

#168

Earlier quoted context omitted.

Do police protect inner city poverty-stricken people victimized by gangs? It's pretty easy to argue that police only protect those who pay them.

Police don't really "protect" anyone, their job is to cleanup the mess and investigate after the fact.

they do protect the Government...

Re: Google Chrome Hacked?

#169
post #161

Earlier quoted context omitted.

The delay? The scroll bars? There is evidence that this is Flash. However, since everyone seems to want to attack individual parts of that evidence without applying Occam's Razor, I concede it could be something other than Flash. It could be Java, too. It could be a "standard browser exploit" too, whatever that is. Could be cosmic rays too. The tendency to look for ways to prove me wrong with an alternate theory (whi…

You seem to only want to receive an answer that starts with "You bring up credible evidence, but maybe there's an alternate scenario playing out here, for which I believe the following holds true..." Now I can do that, but since we're all speculating, this is implied. No one is saying you're dead wrong, we're just posting alternate hypothesis and you're taking this very personally. Let's apply Occam's razor: a) There…

No, I do not want to receive an answer. That would imply that I asked a question in my OP.

Re: Google Chrome Hacked?

#170

Earlier quoted context omitted.

No, Google can fix by not letting programs downloaded from the Internet write to arbitrary memory locations. Actually, you can fix it, too: chromium is open source.

Actually, you can fix it, too: chromium is open source. Good to see this tired claim getting its play in this thread. I wondered how long it would be until it showed up. I think everyone who says "go fix it, it's open-source" should instead be required to come back with a diff within 24 hours.

People are quick to demand bug fixes or better security, but they never seem interested in actually doing the work.

I don't use Chrome or Windows, so I have almost negative personal interest in this story. However, some people probably do use Chrome and Windows, and those people's demands should be tempered by reality. If they didn't find this bug, why did they expect Google to?

I think everyone who says "go fix it, it's open-source" should instead be required to come back with a diff within 24 hours.

I think everyone should be required to give me a pony.

Post reply on HN