Live data from Hacker News

The Deathray: A simple way for an untrusted site to freeze a Mac

auberon.xyz

131–140 of 199 posts

Re: The Deathray: A simple way for an untrusted site to freeze a Mac

#132

Earlier quoted context omitted.

are you saying that it corrupted the OS install / bricked your Mac?

I guess so. I tried safe Mode, deleting chrome via terminal in recovery. Mac stops rendering as soon as I enter my disk password and it continues to load the system. Now in recovery trying to reinstall lol

After doing a system update and waiting a long time I got my mac back and a crash report.

  "termination" : {"flags":0,"indicator":"monitoring timed out for service","code":1,"namespace":"WATCHDOG","details":["(1 monitored services unresponsive): checkin with service: WindowServer (0 induced crashes) returned not alive with context:","is_alive_func returned unhealthy : 0x2|33130:33130:1|04000000:04000000:04000000 0x4|30324:30324:0|04000400:04000400:04000400 0x5|99275:99275:2|04000400:04000400:04000400","40 seconds since last successful checkin, 139478 total successful checkins since 1481204 seconds ago, has not exited since first loaded"]},

Re: The Deathray: A simple way for an untrusted site to freeze a Mac

#133
post #127

Earlier quoted context omitted.

Do you think a regular user knows how to block a specific website or never click a link leading to it again? And what about the ads people, adding such a thing if you don't load their ads? I think this point of view is making it a bit too easy.

As someone who supports some bottom of the barrel "regular users".. they aren't monkeys. They have brains that function enough to process "oh, I shouldn't do that again".

Nitpick: monkeys have enough brains for "oh, I shouldn't do that again".

Re: The Deathray: A simple way for an untrusted site to freeze a Mac

#134

This has been around since 2011 when WebGL shipped. It's documented in the spec. It's a self correcting problem. You go to a site, it freezes your machine, you never visit the site again. No data is stolen, no privacy is lost. All that happens is the perp loses any audience. Turning off WebGL = no more Figma, no more Canva, no more Google Maps. A few self correcting sites seem acceptable. Evidence, it's been 15 years…

> It's a self correcting problem. You go to a site, it freezes your machine, you never visit the site again.

What do regular users do about a malicious ad that runs on thousands of different sites?

> Turning off WebGL = no more Figma, no more Canva, no more Google Maps

Which is why you should probably rather turn off the actual vulnerable API, i.e. WebGPU, not WebGL.

Re: The Deathray: A simple way for an untrusted site to freeze a Mac

#135
post #110

> Just hope that your browser doesn't automatically reopen the same tab when it starts up again Busted. My browser is configured to do just that.

Unplug your ethernet cable?

Can't websites install web workers for persistent full offline access these days?

Re: The Deathray: A simple way for an untrusted site to freeze a Mac

#136

There are more of these hiding in WebGPU. Some work on iOS as well. I reported them to Apple but they were closed as not having security relevance.

that's because they don't hav any security relevance.

Your definition of security doesn't include availability, then?

Re: The Deathray: A simple way for an untrusted site to freeze a Mac

#138
post #134

This has been around since 2011 when WebGL shipped. It's documented in the spec. It's a self correcting problem. You go to a site, it freezes your machine, you never visit the site again. No data is stolen, no privacy is lost. All that happens is the perp loses any audience. Turning off WebGL = no more Figma, no more Canva, no more Google Maps. A few self correcting sites seem acceptable. Evidence, it's been 15 years…

> It's a self correcting problem. You go to a site, it freezes your machine, you never visit the site again. What do regular users do about a malicious ad that runs on thousands of different sites? > Turning off WebGL = no more Figma, no more Canva, no more Google Maps Which is why you should probably rather turn off the actual vulnerable API, i.e. WebGPU, not WebGL.

It really ought to be something you can enable or disable per site. I was surprised to find its not.

Re: The Deathray: A simple way for an untrusted site to freeze a Mac

#140
post #134

This has been around since 2011 when WebGL shipped. It's documented in the spec. It's a self correcting problem. You go to a site, it freezes your machine, you never visit the site again. No data is stolen, no privacy is lost. All that happens is the perp loses any audience. Turning off WebGL = no more Figma, no more Canva, no more Google Maps. A few self correcting sites seem acceptable. Evidence, it's been 15 years…

> It's a self correcting problem. You go to a site, it freezes your machine, you never visit the site again. What do regular users do about a malicious ad that runs on thousands of different sites? > Turning off WebGL = no more Figma, no more Canva, no more Google Maps Which is why you should probably rather turn off the actual vulnerable API, i.e. WebGPU, not WebGL.

I just don’t think people are doing malicious ads like that. Like I’m sure it exists but like what’s the point? If you are the malicious person you pay money for ads to freeze someone’s computer and that’s it? It’s not even like you would gain anything from it
Post reply on HN