Live data from Hacker News

Gaining access to anyones Arc browser without them even visiting a website

kibty.town

111–120 of 538 posts

Re: Gaining access to anyones Arc browser without them even visiting a website

#111

    > i discovered that there was a arc featured called easels, easels 
    > are a whiteboard like interface, and you can share them with people, 
    > and they can view them on the web. when i clicked the share button 
    > however, there was no requests in my mitmproxy instance, so whats 
    > happening here?
I first noticed this on a flight to Paris. I was building a Flutter app using Firestore, and tho I had not paid for the onboard wifi (I was doing local development) I was connected and all of my Firestore calls were succeeding.

I thought this was novel, and assumed it was just something to do with websockets, so I switched to another, non-firebase-but-yes-websockets project and noticed it didn't work.

At the time, I debated moving calls to Firebase just so that I could work for free while I was on flights, but realized the ROI wasn't remotely there. Glad to finally have someone else acknowledge it happening, and give some insight as to why.

Re: Gaining access to anyones Arc browser without them even visiting a website

#113
post #5

There are a lot of major security vulnerabilities in the world that were made understandably, and can be forgiven if they're handled responsibly and fixed. This is not one of them. In my opinion, this shows a kind of reputation-ruining incompetency that would convince me to never use Arc ever again.

Honestly I’ve always considered Arc to be a wolf in sheep’s clothing, especially when it comes to privacy. 50-60mm cash at 500mm (!) valuation and no business model is a big red flag when it comes to something as important, as personal as a browser. This is not a charity. Someone, somehow will have to pay for that.

Yeah I’m so torn. It’s honestly the best browser UX I’ve seen, the right combination of vertical tabs, auto archiving, spaces/collections, sync, etc. I don’t care for Easels, but the core is good.

Except… the growth hacks have started to creep in. They overlay an advert for their own AI services on top of regular Google search results pages in their mobile app. Not even a browser chrome UI element, it’s literally over the page content. That feels like a huge violation of what it means to be a browser.

I don’t want their AI features. I don’t want growth hacks. I don’t want to sign in except for sync. I’d happily pay $40 a year for Arc as a product-focused-product, but as a VC-focused-product it’s heading downhill.

Re: Gaining access to anyones Arc browser without them even visiting a website

#114

Can we have Arc added to the title of the post to better alert people who use or know people who use the browser?

Huge agree. I didn’t realize this applied to me the first time I saw this story yesterday. It was the rename that got me to click.

Honestly I strongly feel the title should be “fundamental bug in Arc browser (CVE 123-4567)” or similar.

Re: Gaining access to anyones Arc browser without them even visiting a website

#116
post #57

Very small bounty, but I honestly believe this arc thing won’t last long… Browsers are hard and my only choice has been chrome and will remain so for the long foreseeable future. When I was younger I would enjoy switching to firefox, opera, etc.. But I always came back to chrome because it just worked and always performed when I needed. Chrome/chromium is the safest browser. People tend to fall for the shiny new thin…

> Chrome/chromium is the safest browser.

Why do you say that?

Re: Gaining access to anyones Arc browser without them even visiting a website

#117
post #85
post #5

There are a lot of major security vulnerabilities in the world that were made understandably, and can be forgiven if they're handled responsibly and fixed. This is not one of them. In my opinion, this shows a kind of reputation-ruining incompetency that would convince me to never use Arc ever again.

On the other hand, this is pretty impressive: aug 25 5:48pm: got initial contact over signal (encrypted) with arc co-founder hursh aug 25 6:02pm: vulnerability poc executed on hursh's arc account aug 25 6:13pm: added to slack channel after details disclosed over encrypted format aug 26 9:41pm: vulnerability patched, bounty awarded sep 6 7:49pm: cve assigned (CVE-2024-45489) Four hours from out-of-the-blue initial con…

Reacting fast is the least the vendor could do. Bare minimum. This should not be applauded. It should be treated as "well, at least they reacted at a reasonable speed so the root cause was probably not malice".

In other words, a quick turnaround with a fix does not lessen the impact of being negligent about security when designing the product.

Re: Gaining access to anyones Arc browser without them even visiting a website

#118
post #80

Earlier quoted context omitted.

That seems like a perfectly reasonable thing to sync. Accessibility settings are exactly the type of thing you shouldn’t have to configure again and again on every device. Either way, you can disable syncing of system settings.

> That seems like a perfectly reasonable thing to sync. Accessibility settings are exactly the type of thing you shouldn’t have to configure again and again on every device. No, because I disabled motion on my phone because the wiggling of icons on the main screen annoyed me, not because I have motion sickness. Nothing wiggles on the desktop (yet). This option doesn't even belong in accessibility IMO, it should be a…

Gotta be honest, the aggressive and unreasonable snark completely turns me off from helping you. It feels that regardless of the obviousness of the setting, you’ll find some nitpick to shout back at me about it. Since I don’t work for Apple or yourself, I don’t have to justify their choices or be the recipient of your unjustified and unprompted bad humour. I’m making a conscious choice to not soil my Friday on account of some internet rando. You’re on your own for this one.

I genuinely wish you a calm weekend and peaceful start of the week.

Re: Gaining access to anyones Arc browser without them even visiting a website

#119
Thank you for sharing this. I have been using Arc since the first week of beta.

The fact that they don't even mentioned this bug/fix on any of their social media is quite alarming.

I enjoyed my time with Arc, but I can't possibly see myself continuing to use it after the way they handled this.

Re: Gaining access to anyones Arc browser without them even visiting a website

#120

I just wanted to say, I enjoyed the little pixel art cat that runs towards wherever you click immensely. It’s one of those fun, whimsical little touches that I don’t see all that often. A reminder that the internet can be a fun, whimsical place if we want it to be :)

For the curious, that specific cat goes back to 1989:

https://en.wikipedia.org/wiki/Neko_(software)

Post reply on HN