Actively exploited sandbox RCE in all Chromium versions
121–130 of 518 posts
Re: Actively exploited sandbox RCE in all Chromium versions
#122NIST probably had this one filed and ready to announce years ago like those news agencies have obituaries of famous old people pre-written
I bet famous people have their people write one to distribute immediately.
Also, writing those for your family sucks, easier to do it when they are alive and can tell some key stories.
Re: Actively exploited sandbox RCE in all Chromium versions
#123Doesn't everyone else immediately update everything on their computer before they start doing anything?
Re: Actively exploited sandbox RCE in all Chromium versions
#124Earlier quoted context omitted.
The problem is they are being flooded with both fake AND real disclosures. Imagine if they tried to pay out $250,000 or more per bug? Would the cost be worth it? Maybe, but shareholders may not be pleased... Unless they viewed it as insurance against it being more financially sound for the finder to sell the exploit on the gray or black market instead...
They should just multiply a base rate against the severity level. Say the base rate is ranged so low-severity stuff is $500-1K base but high-severity stuff is $10K base. That would net a researcher ~$88K for this specific bug (8.8 severity).
Re: Actively exploited sandbox RCE in all Chromium versions
#125Re: Actively exploited sandbox RCE in all Chromium versions
#126Earlier quoted context omitted.
Blackhat markets will always be able to pay better. Selling to Google though you aren't chancing jail time.
> Blackhat markets will always be able to pay better. ... than Google? > Selling to Google though you aren't chancing jail time. Why would you go to jail for selling a vulnerability? It's free speech.
Re: Actively exploited sandbox RCE in all Chromium versions
#127Earlier quoted context omitted.
You let the market decide. Google could purchase the bugs on the same market blackhats do.
we really do not want to engineer a system in which using bugs to make money is considered economically legitimate activity. It is still crime. The main reason to report bugs and get the bounties for doing so is still because it makes the world safer and healthier. The money is there to make is to incentivize the work of finding and reporting them -- not to outbid the bad actors.
"Safety" is also a relative thing, when the world is safer for one party, it is usually worse for another.
Re: Actively exploited sandbox RCE in all Chromium versions
#128Just one more reason to never use Chrome. Their removal of MV2 to prevent UBlock Origin from working is another.
Chromium is still far superior on the security front than any other browser.
Re: Actively exploited sandbox RCE in all Chromium versions
#129Earlier quoted context omitted.
You let the market decide. Google could purchase the bugs on the same market blackhats do.
we really do not want to engineer a system in which using bugs to make money is considered economically legitimate activity. It is still crime. The main reason to report bugs and get the bounties for doing so is still because it makes the world safer and healthier. The money is there to make is to incentivize the work of finding and reporting them -- not to outbid the bad actors.
"Making money from bugs" is not solely a black-market activity. There are plenty of grey and even white hat activities in this market.
Re: Actively exploited sandbox RCE in all Chromium versions
#130Earlier quoted context omitted.
> Blackhat markets will always be able to pay better. ... than Google? > Selling to Google though you aren't chancing jail time. Why would you go to jail for selling a vulnerability? It's free speech.
"Aiding and Abetting" crime is also a crime. Free speech has nothing to do with it.