Live data from Hacker News

Google Chrome Hacked?

vupen.com

181–190 of 223 posts

Re: Google Chrome Hacked?

#181
post #7
post #4

Earlier quoted context omitted.

I'm not too sure that's the business VUPEN is in. Sure, it doesn't hurt them much to share their latest Safari exploit given how slow Apple is on the fix, but with Google their window has the potential to be very short.

Citation needed for such a serious accusation. They claim to be ethical. From their about page: "VUPEN follows a private responsible disclosure policy and reports all discovered vulnerabilities to the affected vendor under contract with VUPEN, and works with them to create a timetable pursuant to which the vulnerability information may be publicly disclosed."

Chaouki Bekar, VUPEN’s CEO and head of research, confirmed that the company had no plans to share any details about their findings with Google, nor was it aware of any steps users could take to mitigate the threat from this attack.

“No, we did not alert Google as we only share our vulnerability research with our Government customers for defensive and offensive security,” Bekar wrote in response to an emailed request for comment. “Unfortunately, we are not aware of any mitigation to protect against these vulnerabilities.”

http://krebsonsecurity.com/2011/05/security-group-claims-to-...

Re: Google Chrome Hacked?

#182

This video is extremely suspicious to the point of probably being an outright lie. I would wager money that this vulnerability is a Flash exploit sold as a Chrome exploit. It is not an accident that they hid Process Explorer after the exploit. They closed it before minimizing everything else intentionally. If you do not believe me follow the mouse pointer. The screencaster moved toward bringing Process Explorer top-l…

I can get Chrome to chew through all of RAM and swap just by repeatedly changing the src= attribute of an img tag (which, by the way, I'd like suggestions on avoiding). Flash isn't required to eat lots of RAM.

Re: Google Chrome Hacked?

#183

This video is extremely suspicious to the point of probably being an outright lie. I would wager money that this vulnerability is a Flash exploit sold as a Chrome exploit. It is not an accident that they hid Process Explorer after the exploit. They closed it before minimizing everything else intentionally. If you do not believe me follow the mouse pointer. The screencaster moved toward bringing Process Explorer top-l…

[deleted]

Re: Google Chrome Hacked?

#184
post #7

Earlier quoted context omitted.

Citation needed for such a serious accusation. They claim to be ethical. From their about page: "VUPEN follows a private responsible disclosure policy and reports all discovered vulnerabilities to the affected vendor under contract with VUPEN, and works with them to create a timetable pursuant to which the vulnerability information may be publicly disclosed."

Chaouki Bekar, VUPEN’s CEO and head of research, confirmed that the company had no plans to share any details about their findings with Google, nor was it aware of any steps users could take to mitigate the threat from this attack. “No, we did not alert Google as we only share our vulnerability research with our Government customers for defensive and offensive security,” Bekar wrote in response to an emailed request…

Oh, nice guys.

Sounds to me like VUPEN is a cyberweapons dealer.

Re: Google Chrome Hacked?

#185

This video is extremely suspicious to the point of probably being an outright lie. I would wager money that this vulnerability is a Flash exploit sold as a Chrome exploit. It is not an accident that they hid Process Explorer after the exploit. They closed it before minimizing everything else intentionally. If you do not believe me follow the mouse pointer. The screencaster moved toward bringing Process Explorer top-l…

Actually, Chrome has been sandboxing Flash since last December. http://blog.chromium.org/2010/12/rolling-out-sandbox-for-ado...

So even if the exploit is using vulnerability in Flash, it still needs to escape the Flash sandbox in Chrome.

Re: Google Chrome Hacked?

#186
post #23

vupen: "Hey Google, your browser has a very nasty bug that allows for potentially horrible things to happen. We thought we'd share that with the world. If you'd like to know where it is though, you'd better give us money."

I'm tired of doing volunteer work for corporations, personally.

Don't think of it as volunteer work -- think of it as a non-financial exchange of value. You provide beta testing in exchange for significantly more affordable software and/or earlier access. If you want rock solid reliability, there are companies and operating systems that provide it, with the price tag and turnaround time to match.

Re: Google Chrome Hacked?

#187
post #153
post #43

Earlier quoted context omitted.

"Why not? This is highly specialized research that not even well-paid Google employees were able to do." Correction: not even well-paid Google employees did . They may yet be able, and an existence proof may be all the help they need to find and fix it. Don't give up hope yet.

I can fix it right now. Delete the flash player - problem solved. Chrome still works.

I don't see how Flash can be the culprit or solution considering it is sandboxed. Chrome must contain a massive exploit.

Re: Google Chrome Hacked?

#188
This seems extremely unethical to me. Now that the world knows there is massive exploit in Chrome, there are bound to be more hackers attempting to abuse it - and have a few hints from the video. By blogging about this and not disclosing it to Google, they are actually increasing the risk of millions of individuals and companies being hacked.

Edit: Then again, blogging about it also makes Google aware of the exploit. I'm sure they have tons of resources working on it that wouldn't have otherwise...

Re: Google Chrome Hacked?

#189
post #187
post #153

Earlier quoted context omitted.

I can fix it right now. Delete the flash player - problem solved. Chrome still works.

I don't see how Flash can be the culprit or solution considering it is sandboxed. Chrome must contain a massive exploit.

I thought the point was that they broke the sandboxing.

Re: Google Chrome Hacked?

#190
post #122
post #117

Earlier quoted context omitted.

LOL, and Google does not have enough money to pay them a few measly billions to help fix their crown jewel chrome browser?? Don't make me laugh like that! Poor Google, not enough money, that'll be the day. These things should not in my opinion be disclosed to (the idiot skript kiddie segment of) the public before the vendors have been given a good long window to fix them. I prefer what VUPEN does when compared to irr…

"VUPEN provides vulnerability research and intelligence for defensive and offensive security." so, they are I presume happy to help the US CIA/MIL fvck people over (who most likely don't deserve it).

You may want to check the spelling on your profanity there.
Post reply on HN