Live data from Hacker News

Critical Google Chrome hole plugged in 24 hours

arstechnica.com

1–10 of 26 posts

Re: Critical Google Chrome hole plugged in 24 hours

#2
"To date, most successful attacks against Chrome exploit Adobe Flash, which is protected by a significantly more porous sandbox."

I notice that pretty much every time I read articles about Pwn2Own and similar. It's high time that Flash was abandoned as a ubiquitous part of the web. It is to web development as Outlook Express was to desktop software in the 90s - sure it's everywhere, but it's not doing much good by being so.

Re: Critical Google Chrome hole plugged in 24 hours

#5
post #4
post #3

With a response time like that it seems like antivirus software is becoming increasingly irrelevant.

Meanwhile, critical Android security holes remain unpatched for more than 2 yrs.

A real security hole, or one like "if someone watches you type your PIN code, they'll know your PIN code"?

Re: Critical Google Chrome hole plugged in 24 hours

#6
The Chrome Release blog says it's fixed: http://googlechromereleases.blogspot.com/2012/03/chrome-stab...

And that the SVN commit history is available: http://build.chromium.org/f/chromium/perf/dashboard/ui/chang...

But I don't see any commit that look even remotely related to this exploit. What's up?

Re: Critical Google Chrome hole plugged in 24 hours

#7
post #6

The Chrome Release blog says it's fixed: http://googlechromereleases.blogspot.com/2012/03/chrome-stab... And that the SVN commit history is available: http://build.chromium.org/f/chromium/perf/dashboard/ui/chang... But I don't see any commit that look even remotely related to this exploit. What's up?

Well... They would hopefully be smarter than committing the fix to the public SVN.

By committing the fix, they would effectively be releasing a step-by-step guide on how to exploit the vulnerability.

Re: Critical Google Chrome hole plugged in 24 hours

#8
post #7
post #6

The Chrome Release blog says it's fixed: http://googlechromereleases.blogspot.com/2012/03/chrome-stab... And that the SVN commit history is available: http://build.chromium.org/f/chromium/perf/dashboard/ui/chang... But I don't see any commit that look even remotely related to this exploit. What's up?

Well... They would hopefully be smarter than committing the fix to the public SVN. By committing the fix, they would effectively be releasing a step-by-step guide on how to exploit the vulnerability.

But it's still an open source project -- perhaps the commits are more evident in their git repo? http://git.chromium.org/gitweb/

Certainly if you build Chromium from git/SVN now, the bug is fixed.

I just find it a little strange that their changelog / list of commits in each version is not true.

Re: Critical Google Chrome hole plugged in 24 hours

#9
post #2

"To date, most successful attacks against Chrome exploit Adobe Flash, which is protected by a significantly more porous sandbox." I notice that pretty much every time I read articles about Pwn2Own and similar. It's high time that Flash was abandoned as a ubiquitous part of the web. It is to web development as Outlook Express was to desktop software in the 90s - sure it's everywhere, but it's not doing much good by be…

I keep it disabled in Chrome and selectively enable it for sites I trust or as-needed. I'm glad to see that it's less necessary over time.

Re: Critical Google Chrome hole plugged in 24 hours

#10
post #5
post #4

Earlier quoted context omitted.

Meanwhile, critical Android security holes remain unpatched for more than 2 yrs.

A real security hole, or one like "if someone watches you type your PIN code, they'll know your PIN code"?

Security holes that render the permissions system completely useless, since even a no-permissions app can end up doing anything.
Post reply on HN