Live data from Hacker News

Actively exploited sandbox RCE in all Chromium versions

nvd.nist.gov

121–130 of 524 posts

Re: Actively exploited sandbox RCE in all Chromium versions

#122

NIST probably had this one filed and ready to announce years ago like those news agencies have obituaries of famous old people pre-written

I know a regular old geezer who's written his own obituary. Publish this when I die.

I bet famous people have their people write one to distribute immediately.

Also, writing those for your family sucks, easier to do it when they are alive and can tell some key stories.

Re: Actively exploited sandbox RCE in all Chromium versions

#124
post #54
post #29

Earlier quoted context omitted.

The problem is they are being flooded with both fake AND real disclosures. Imagine if they tried to pay out $250,000 or more per bug? Would the cost be worth it? Maybe, but shareholders may not be pleased... Unless they viewed it as insurance against it being more financially sound for the finder to sell the exploit on the gray or black market instead...

They should just multiply a base rate against the severity level. Say the base rate is ranged so low-severity stuff is $500-1K base but high-severity stuff is $10K base. That would net a researcher ~$88K for this specific bug (8.8 severity).

That would create a perverse incentive to inflate the severity levels even more than they already are

Re: Actively exploited sandbox RCE in all Chromium versions

#125
post #31
post #22

Earlier quoted context omitted.

Which browser has a better security track record?

Firefox with uBlock Origin. It’s astonishing how many exploits uBO stops before they ever reach your browser engine. It’s the antivirus of the 2020s.

[flagged]

Re: Actively exploited sandbox RCE in all Chromium versions

#126

Earlier quoted context omitted.

Blackhat markets will always be able to pay better. Selling to Google though you aren't chancing jail time.

> Blackhat markets will always be able to pay better. ... than Google? > Selling to Google though you aren't chancing jail time. Why would you go to jail for selling a vulnerability? It's free speech.

Telling someone the steps to rob a bank world probably catch you some charges, I'm assuming.

Re: Actively exploited sandbox RCE in all Chromium versions

#127
post #111

Earlier quoted context omitted.

You let the market decide. Google could purchase the bugs on the same market blackhats do.

we really do not want to engineer a system in which using bugs to make money is considered economically legitimate activity. It is still crime. The main reason to report bugs and get the bounties for doing so is still because it makes the world safer and healthier. The money is there to make is to incentivize the work of finding and reporting them -- not to outbid the bad actors.

"Crime" is very flexible term. One country's criminal is another country hero. Maybe the author would sell the vulnerability to an organization making exploits for government use.

"Safety" is also a relative thing, when the world is safer for one party, it is usually worse for another.

Re: Actively exploited sandbox RCE in all Chromium versions

#128

Just one more reason to never use Chrome. Their removal of MV2 to prevent UBlock Origin from working is another.

This is like saying never use seatbelts because people still die in car accidents.

Chromium is still far superior on the security front than any other browser.

Re: Actively exploited sandbox RCE in all Chromium versions

#129
post #111

Earlier quoted context omitted.

You let the market decide. Google could purchase the bugs on the same market blackhats do.

we really do not want to engineer a system in which using bugs to make money is considered economically legitimate activity. It is still crime. The main reason to report bugs and get the bounties for doing so is still because it makes the world safer and healthier. The money is there to make is to incentivize the work of finding and reporting them -- not to outbid the bad actors.

> we really do not want to engineer a system in which using bugs to make money is considered economically legitimate activity. It is still crime.

"Making money from bugs" is not solely a black-market activity. There are plenty of grey and even white hat activities in this market.

Re: Actively exploited sandbox RCE in all Chromium versions

#130
post #112

Earlier quoted context omitted.

> Blackhat markets will always be able to pay better. ... than Google? > Selling to Google though you aren't chancing jail time. Why would you go to jail for selling a vulnerability? It's free speech.

"Aiding and Abetting" crime is also a crime. Free speech has nothing to do with it.

Has anyone actually been convicted of abetting a crime by selling a vulnerability, by itself, not conspiring with the buyer to commit a crime using said vulnerability? Not as far as I can see. It would be absurd to jail someone for accurately describing a bug.
Post reply on HN