Live data from Hacker News

Google Chrome Hacked?

vupen.com

171–180 of 223 posts

Re: Google Chrome Hacked?

#171

Earlier quoted context omitted.

Actually, you can fix it, too: chromium is open source. Good to see this tired claim getting its play in this thread. I wondered how long it would be until it showed up. I think everyone who says "go fix it, it's open-source" should instead be required to come back with a diff within 24 hours.

People are quick to demand bug fixes or better security, but they never seem interested in actually doing the work. I don't use Chrome or Windows, so I have almost negative personal interest in this story. However, some people probably do use Chrome and Windows, and those people's demands should be tempered by reality. If they didn't find this bug, why did they expect Google to? I think everyone who says "go fix it,…

The person you replied to did not demand anything but instead theorized about a way to fix it.

I love how you assert that literally anybody could check out Chromium and fix the sandbox, a sensitive security-essential part of the browser, with very little effort required to appreciate the source and all of the moving parts.

Re: Google Chrome Hacked?

#172
post #109
post #97

Looking at the video and time it took to launch the calc.exe, it could be pdf/flash exploit that they are using. Process count in process explorer started with 5 and at the end of the demo, it looked like they have 8. That tells there are 2 extra processes that are created (discounting 1 for calc.exe). I tried to see if pdf/flash creates new processes but I couldn't verify. Perhaps a chrome developer could get a clue…

They are obviously hiding something. When they flip back to Process Explorer, Chrome is perfectly sized to cover everything in the window except the calc.exe. My guess is there are other processes running that they're trying to hide that were used in the exploit.

It would have been trivial for them to patch Process Explorer to hide whatever they wanted anyway.

Re: Google Chrome Hacked?

#173
post #99

Earlier quoted context omitted.

people were telling the same about HBGary before they started to tell the opposite. Though my post isn't about technical brilliance. Being in bed with Power and relaxing one's moral standards to better serve it always leads the same way....

> it always leads the same way.... To profit? I believe most people would get into bed with the government if offered the correct incentives. I probably would, too. It's unfortunate, but that's how things work. Is it immoral not to relax your morals to, e.g., secure a better life for yourself and your family? (Apologies for being meta, but I've recently begun studying morality/ethics so I'm exploring ideas for which…

As you are researching I'd check out the writing and thoughts of Norwegian Philosopher Arne Næss. He has a lot to say about different levels of rationality which are quite interesting. He began his philosophical as a hard-core rationalist with the Vienna school but later in life expanded rationality to include a larger rationality and human feeling. Also Christopher Alexander has insight here about including human feeling as an objective instead of solely subjective part of decision making.

http://www.amazon.com/Lifes-Philosophy-Reason-Feeling-Deeper... http://en.wikipedia.org/wiki/Arne_N%C3%A6ss

Re: Google Chrome Hacked?

#174
post #138

Earlier quoted context omitted.

> First item of interest is that Chrome shot up to over 400 MB of memory used which indicates that Flash is almost certainly involved. Is this really the basis of your claim? A complete guess that a 400MB increase in memory must be due to a secret use of Flash?

On an otherwise empty page? Yes, it is extremely likely when combined with the payload delay. If you manage to make a single tab commit that much memory as a delta without Flash (remember, 13 MB to > 400 MB) please screenshot about:memory and get back to me. The scroll bars on the tab are revealing, too. I may be guessing but it is an educated guess. Additionally, there were multiple claims so I would not call that s…

* If you manage to make a single tab commit that much memory as a delta without Flash*

Not 100% sure, and I haven't tried it, but I suspect it would be possible using this bug: http://code.google.com/p/chromium/issues/detail?id=25047

Re: Google Chrome Hacked?

#175
post #99

Earlier quoted context omitted.

> it always leads the same way.... To profit? I believe most people would get into bed with the government if offered the correct incentives. I probably would, too. It's unfortunate, but that's how things work. Is it immoral not to relax your morals to, e.g., secure a better life for yourself and your family? (Apologies for being meta, but I've recently begun studying morality/ethics so I'm exploring ideas for which…

As you are researching I'd check out the writing and thoughts of Norwegian Philosopher Arne Næss. He has a lot to say about different levels of rationality which are quite interesting. He began his philosophical as a hard-core rationalist with the Vienna school but later in life expanded rationality to include a larger rationality and human feeling. Also Christopher Alexander has insight here about including human fe…

Thanks for the info. Arne looks like a really interesting character.

Re: Google Chrome Hacked?

#176
post #109

Earlier quoted context omitted.

They are obviously hiding something. When they flip back to Process Explorer, Chrome is perfectly sized to cover everything in the window except the calc.exe. My guess is there are other processes running that they're trying to hide that were used in the exploit.

It would have been trivial for them to patch Process Explorer to hide whatever they wanted anyway.

Nah, the vupen marketing guys are too lazy to patch it.

Re: Google Chrome Hacked?

#177

Earlier quoted context omitted.

People are quick to demand bug fixes or better security, but they never seem interested in actually doing the work. I don't use Chrome or Windows, so I have almost negative personal interest in this story. However, some people probably do use Chrome and Windows, and those people's demands should be tempered by reality. If they didn't find this bug, why did they expect Google to? I think everyone who says "go fix it,…

The person you replied to did not demand anything but instead theorized about a way to fix it. I love how you assert that literally anybody could check out Chromium and fix the sandbox, a sensitive security-essential part of the browser, with very little effort required to appreciate the source and all of the moving parts.

I love how you assert that literally everybody is too dumb to understand computer programs that they use.

Re: Google Chrome Hacked?

#178

Earlier quoted context omitted.

The person you replied to did not demand anything but instead theorized about a way to fix it. I love how you assert that literally anybody could check out Chromium and fix the sandbox, a sensitive security-essential part of the browser, with very little effort required to appreciate the source and all of the moving parts.

I love how you assert that literally everybody is too dumb to understand computer programs that they use.

Not dumb, there's just a lot of skills assumed to work on the security components of a modern Web browser. I would never claim that I could turn around and fix this bug as an outside developer. Words in my mouth.

Re: Google Chrome Hacked?

#179

Earlier quoted context omitted.

I love how you assert that literally everybody is too dumb to understand computer programs that they use.

Not dumb, there's just a lot of skills assumed to work on the security components of a modern Web browser. I would never claim that I could turn around and fix this bug as an outside developer. Words in my mouth.

In my opinion, this is one step away from sacrificing a virgin to make it rain. We should control our own software destiny and not just hope other people will do it for us.

Re: Google Chrome Hacked?

#180
post #152

Earlier quoted context omitted.

Google could easily sue them into oblivion for libel. They would be forced to reveal the exploit during proceedings to prove their innocence.

one is not obliged to prove innocence in a sensible court of law

At least in the US, civil court cases do not have the presumption of innocence, only criminal cases do.
Post reply on HN