Live data from Hacker News

A Tale of Two Pwnies (Part 1)

blog.chromium.org

1–10 of 82 posts

Re: A Tale of Two Pwnies (Part 1)

#2
WOW.

I read the whole thing, but I was unable to visualize the vulnerability after about the second paragraph describing it.

Maybe it's more mundane than I picture in my head, but I would love to look over someone's shoulder as they went through that process.

Re: A Tale of Two Pwnies (Part 1)

#4
What's amazing about this bug is that at every step you learn something that makes Pinkie Pie more terrifying while simultaneously making the Chrome security model sound more and more forbidding.

Re: A Tale of Two Pwnies (Part 1)

#6
This really takes you into the mind of a hacker(the malicious kind). Judging from what I saw it seems they combine a ton of small exploits to produce a major security breach. The amount of understanding of the underlying system you need to have in order to put these exploits together is mind boggling.

What do we do against people like this?

Re: A Tale of Two Pwnies (Part 1)

#7
post #4

What's amazing about this bug is that at every step you learn something that makes Pinkie Pie more terrifying while simultaneously making the Chrome security model sound more and more forbidding.

The other thing I wonder about is that in 2040, will we be still worrying about buffer overflows?

Re: A Tale of Two Pwnies (Part 1)

#9
post #4

What's amazing about this bug is that at every step you learn something that makes Pinkie Pie more terrifying while simultaneously making the Chrome security model sound more and more forbidding.

The other thing I wonder about is that in 2040, will we be still worrying about buffer overflows?

I really doubt that we'll be using programming environments where memory corruption is possible in 2040.

Re: A Tale of Two Pwnies (Part 1)

#10

This really takes you into the mind of a hacker(the malicious kind). Judging from what I saw it seems they combine a ton of small exploits to produce a major security breach. The amount of understanding of the underlying system you need to have in order to put these exploits together is mind boggling. What do we do against people like this?

Pay them to find the bugs!
Post reply on HN