Live data from Hacker News

Google Chrome Hacked?

vupen.com

191–200 of 223 posts

Re: Google Chrome Hacked?

#191

Earlier quoted context omitted.

Not dumb, there's just a lot of skills assumed to work on the security components of a modern Web browser. I would never claim that I could turn around and fix this bug as an outside developer. Words in my mouth.

In my opinion, this is one step away from sacrificing a virgin to make it rain. We should control our own software destiny and not just hope other people will do it for us.

http://ycombinator.com/newsguidelines.html

Re: Google Chrome Hacked?

#192

Earlier quoted context omitted.

Link?

Well, I was close... - Gov. and Law Enforcement Agencies in Countries Members or Partners of NATO, ANZUS or ASEAN http://www.vupen.com/english/services/ba-gov.php

ASEAN includes such well-known liberal democracies as Burma, Vietnam, Laos and Brunei.

Re: Google Chrome Hacked?

#193

Earlier quoted context omitted.

In my opinion, this is one step away from sacrificing a virgin to make it rain. We should control our own software destiny and not just hope other people will do it for us.

http://ycombinator.com/newsguidelines.html

Please avoid introducing classic flamewar topics unless you have something genuinely new to say about them.

Re: Google Chrome Hacked?

#194

This video is extremely suspicious to the point of probably being an outright lie. I would wager money that this vulnerability is a Flash exploit sold as a Chrome exploit. It is not an accident that they hid Process Explorer after the exploit. They closed it before minimizing everything else intentionally. If you do not believe me follow the mouse pointer. The screencaster moved toward bringing Process Explorer top-l…

I can get Chrome to chew through all of RAM and swap just by repeatedly changing the src= attribute of an img tag (which, by the way, I'd like suggestions on avoiding). Flash isn't required to eat lots of RAM.

Re: "suggestions on avoiding"

Is this for a rollover, animation, or something else? (Mind posting a code snippet up somewhere?)

Re: Google Chrome Hacked?

#196
Impressive, but not surprising. Chrome isn't magical; ASLR and DEP have been bypassed in the past, and even if its own sandbox is perfect, the kernel it's sitting under is a huge attack surface.

Re: Google Chrome Hacked?

#197
post #148
post #40

Earlier quoted context omitted.

"Who cares if they sound unprofessional to you? Very obviously they produce." Sadly we can't verify that in this case. Because you know, we're not the CIA.

VUPEN cracks Chrome for the Government!!!!! On Windoze, even! I would have thought if they really had a US govt / CIA / military / espionage customer, said customer would NOT want them to reveal ANYTHING about the exploit to Google nor the public, especially not its existance. So, they told us that there is an exploit, and now it's top hax0r news, might likely feature in mainstream news. Most sensible people will mos…

Dude, chill.

Re: Google Chrome Hacked?

#198
post #196

Impressive, but not surprising. Chrome isn't magical; ASLR and DEP have been bypassed in the past, and even if its own sandbox is perfect, the kernel it's sitting under is a huge attack surface.

ASLR and DEP, by and large, have nothing to do with the kernel. ASLR is a function of the binary loader and memory allocators, which are in userland. DEP is a function of userland memory protection flags (they're handled on the bare metal by the kernel, but the kernel just sets what it's told to by the userland). I'd put any amount of money down on the table that there is no kernel vulnerability here at all -- if there was one, I assure you that it'd be more than a Chrome vuln.

Re: Google Chrome Hacked?

#199
post #153
post #43

Earlier quoted context omitted.

"Why not? This is highly specialized research that not even well-paid Google employees were able to do." Correction: not even well-paid Google employees did . They may yet be able, and an existence proof may be all the help they need to find and fix it. Don't give up hope yet.

I can fix it right now. Delete the flash player - problem solved. Chrome still works.

There's absolutely no evidence that this has anything to do with Flash. In fact, even if it was via Flash, there would still have to be another vulnerability to escape the Chrome sandbox, which could very likely be exploited via other means.

Re: Google Chrome Hacked?

#200
post #31

Earlier quoted context omitted.

The net result in this case is the government owning a zero-day root exploit for every Chrome/Win citizen’s computer. It’s worse than zero-day because we have no reason to expect a patch, so the window of attack will stay open.

On an exploit like this, I expect a patch. I'm sure people at Google and abroad (if the exploit exists in Chromium) are scrambling to find it, both for the e-cred and just to make other people safer.

If if Google does find a serious security flaw, how can they be sure it's the same one?
Post reply on HN