Live data from Hacker News

Gaining access to anyones Arc browser without them even visiting a website

kibty.town

11–20 of 538 posts

Re: Gaining access to anyones Arc browser without them even visiting a website

#11
I just wanted to say, I enjoyed the little pixel art cat that runs towards wherever you click immensely. It’s one of those fun, whimsical little touches that I don’t see all that often. A reminder that the internet can be a fun, whimsical place if we want it to be :)

Re: Gaining access to anyones Arc browser without them even visiting a website

#12
while researching, i saw some data being sent over to the server, like this query everytime you visit a site

I'm not surprised in the least --- basically the vast majority of software these days is spyware. Looking at Arc's privacy page, it appears to be mainly marketing fluff similar to what I've seen from other companies. I have yet to find a privacy policy that says frankly "we only know your IP and time you downloaded the software, for the few weeks before the server logs are overwritten."

Re: Gaining access to anyones Arc browser without them even visiting a website

#13

I just wanted to say, I enjoyed the little pixel art cat that runs towards wherever you click immensely. It’s one of those fun, whimsical little touches that I don’t see all that often. A reminder that the internet can be a fun, whimsical place if we want it to be :)

It's doing great for being a 35-year-old cat!

https://en.wikipedia.org/wiki/Neko_(software)

Re: Gaining access to anyones Arc browser without them even visiting a website

#14
Great research. As I've said elsewhere, Firebase's authentication model is inherently broken and causes loads of issues, and people would be better off writing a small microservice or serverless function that fronts Firebase.

Also, for anyone trying to read the article, they should put `/oneko.js` in their adblocker.

Re: Gaining access to anyones Arc browser without them even visiting a website

#16
post #9
post #7

Earlier quoted context omitted.

You’d think that a company shipping a browser would pay a little more attention to security rules. Also, shame on firebase for not making this a bit more idiot proof. And really? $2500? That’s it? You could’ve owned literally every user of Arc… The NSA would’ve paid a couple more zeros on that.

Are there a lot of Arc users? It seems like a pretty niche browser even compared to other niches.

Having arbitrary browser access would be pretty valuable, even for just a small number of users.

Re: Gaining access to anyones Arc browser without them even visiting a website

#17
post #8

OP is talking about the Arc browser, not the Arc language, the Arc "Atomic React" project, or any of scores of other projects with that name.

https://arc.net/faq

I'm definitely not the target audience... Even after reading the faq I have no idea what it does

Re: Gaining access to anyones Arc browser without them even visiting a website

#18

Great research. As I've said elsewhere, Firebase's authentication model is inherently broken and causes loads of issues, and people would be better off writing a small microservice or serverless function that fronts Firebase. Also, for anyone trying to read the article, they should put `/oneko.js` in their adblocker.

> Also, for anyone trying to read the article, they should put `/oneko.js` in their adblocker.

Only if you hate cats, pixel art, or are easily distracted.

Post reply on HN