Live data from Hacker News

Actively exploited sandbox RCE in all Chromium versions

nvd.nist.gov

491–500 of 527 posts

Re: Actively exploited sandbox RCE in all Chromium versions

#492

Earlier quoted context omitted.

Before the LLMs made the emdash the tool of the electronic oppressor I used it often enough and other people did too. I hate that it's basically become the little hitler moustache of punctuation. There was at least one guy who was really enjoying his tiny little moustache until he couldn't anymore. That is the emdash for me.

> the emdash has become the little hitler moustache of punctuation Legendary. Miss that shit too. Ez way to shit on Windows users who had to double up endashes like they were impoverished. I guess in your analogy the double endash is Stalin’s mustache and the Soviet Union in general - Gaudy, excessive, starving for more

In the spirit of good pedantic fun, I'll point out that en dashes are no less inconvenient than em dashes for the average Windows user to insert. The hyphen-minus immediately accessible on the keyboard was (and is) used for the common typewriting kludge attested in Garner's[1] as well as the LaTeX-syntax triple-hyphen em dash (which, might I add, for lack of a better place to do so, isn't one of the ways I've seen dashes used by LLMs or disguised by their operators).

1. (. . . Modern American Usage) https://i.vgy.me/UYqs89.png

Re: Actively exploited sandbox RCE in all Chromium versions

#493

Earlier quoted context omitted.

> SPAs will be slow no matter what. Uh…no? You’re presumably talking about specific terrible prebuilt frameworks - not someone building a nice vanilla SPA.

At this point SPA pretty much implies React. But even if you optimize everything the best you could and avoid any third-party runtime dependencies, it's still going to be significantly more work to make API requests and do client-side rendering vs just rendering HTML server-side.

> At this point SPA pretty much implies React

At this point, app pretty much implies React - ask an LLM for an app and see if that’s not what you get.

Re: Actively exploited sandbox RCE in all Chromium versions

#494
post #355

Earlier quoted context omitted.

Google should have been split up into shreds like 2 decades ago. Search wants to have income from ads? Good sell it to anybody who pays the most, just like every single newspaper does. Gmail wants to sell our data, or ad space? Good sell them, and not just reuse them internally. Chrome wants to monetize every single request you do? Go, sell them on the open market. And not this fake, "we're separate companies, but on…

Google is the answer to an Internet that largely blocks ads and uses backdoors to circumvent pay walls. A single massive pillar with enough surface area to carry all the dead weight. If people want a better internet, they can start fostering one, rather than endlessly complain that someone else should be fostering it for them. There will probably be upwards of 1000 people who read this comment that have used Google s…

I dont like ads. Would you be willing to pay for content? Obviously not, stupid.

This comment in general, not aimed at you.

Re: Actively exploited sandbox RCE in all Chromium versions

#495

Earlier quoted context omitted.

That's a good point but you never know that from the start, "this app won't scale well" is a hard sell for a new project in my opinion

Especially today, single-user stuff, especially in categories of things like health, especially when you’re writing your own stuff, that’s when you know from the start that scaling doesn’t matter! =] Related, and more powerful than my comments in this thread are going to be: https://www.robinsloan.com/notes/home-cooked-app/

I don't only mean "scale" in terms of users but also scale in terms of features.

So you have to guarantee that your product will stay low users and low features forever or spend a very high effort to try to partially overcome that block when you change your mind.

And guaranteeing that it will stay low features is much harder than low users I think.

In exchange for that you get a better talent pool for recruiting but does that matter if your product has to stay low scale anyways?

Re: Actively exploited sandbox RCE in all Chromium versions

#496
post #355

Earlier quoted context omitted.

Google should have been split up into shreds like 2 decades ago. Search wants to have income from ads? Good sell it to anybody who pays the most, just like every single newspaper does. Gmail wants to sell our data, or ad space? Good sell them, and not just reuse them internally. Chrome wants to monetize every single request you do? Go, sell them on the open market. And not this fake, "we're separate companies, but on…

Google is the answer to an Internet that largely blocks ads and uses backdoors to circumvent pay walls. A single massive pillar with enough surface area to carry all the dead weight. If people want a better internet, they can start fostering one, rather than endlessly complain that someone else should be fostering it for them. There will probably be upwards of 1000 people who read this comment that have used Google s…

I pay for email and search.

There are hundreds of us, hundreds.

Re: Actively exploited sandbox RCE in all Chromium versions

#497
post #254
post #63

Earlier quoted context omitted.

Pre-flood, they didn’t pay more did they? > viewed it as insurance Of course. Beyond the ethics, the social obligation, sleeping well at night by compensating hardworking people fairly. “We can’t pay more or we’d have to hire more human reviewers” should never be a massive company’s line of thinking.

https://bughunters.google.com/about/key-stats Total rewards given $81,933,423

Increasing each year, interesting. Would have to really dive in to answer my own question. Thanks!

Re: Actively exploited sandbox RCE in all Chromium versions

#498
post #353
post #71

Earlier quoted context omitted.

Maybe needs a Good-Guy-Buy-It-Now w/instant delivery at a fair price. (OK that’s kind of a threat—you’re running an auction and you have the price the corp has to pay to avoid the auction ending.) $1k is so dumb and the fact we’re discussing auctions is proof (hello, Sundar, what you doing over there?). Guess this will change after the next e.g. nationwide hospital ransomware by a hacker who publicly laments bounty r…

> Guess this will change after the next e.g. nationwide hospital ransomware by a hacker who publicly laments bounty rates, if the news cycle accommodates the story long enough. Negotiating with terrorists or black mailers is a bad idea.

Agreed. Paying security researchers fair rates is a good idea though right? Keeps future researchers honest?

Re: Actively exploited sandbox RCE in all Chromium versions

#499

Earlier quoted context omitted.

Despite what people are saying here, chrome has a really excellent track record. Nobody is perfect. Switching just because chrome got exploited one time will likely result in you switching to something worse. If you're paranoid, disable JIT.

It's not about switching because chrome got exploited one time, it's about switching not to reward unethical behavior.

well one someone posts on an article about an exploit in chrome saying that the exploit is a reason to switch, i think its fair to say its not about "not reward[ing] unethical behaviour"

Re: Actively exploited sandbox RCE in all Chromium versions

#500
post #388
post #350

Earlier quoted context omitted.

uBlock Origin won't help with this kind of targeted exploit, and Firefox has a much worse security track record.

It absolutely does help, because it blocks hundreds of thousands of shady origins.

That blocks all sorts of abuse, but a targeted exploit would be delivered on a clean domain.
Post reply on HN