Live data from Hacker News

Gaining access to anyones Arc browser without them even visiting a website

kibty.town

151–160 of 538 posts

Re: Gaining access to anyones Arc browser without them even visiting a website

#151
post #5

There are a lot of major security vulnerabilities in the world that were made understandably, and can be forgiven if they're handled responsibly and fixed. This is not one of them. In my opinion, this shows a kind of reputation-ruining incompetency that would convince me to never use Arc ever again.

I agree & disagree. Browsers are very important part of our life. If someone compromises our browsers , they basically compromise every single aspect of privacy and can lead to insane scams. And because arc browser is new , they wanted to build fast and so they used tools like firebase / firestore to be capable of moving faster (they are a startup) Now I have read the article but I am still not sure how much of this…

>>Did you know that chrome gives an unfair advantage to its user sites by giving system information (core usage etc.) and some other things which are not supposed to be seen by browsers only to the websites starting with *.google.com ?

Yeah so using chrome based browsers like Arc is giving more power to Google to do shady stuff while also being a victim of the third party unsafe code.

Re: Gaining access to anyones Arc browser without them even visiting a website

#152
post #148
post #124

Earlier quoted context omitted.

Them acknowledging the issue, then fixing it within 28 hours isn't good enough for you? That kind of response makes me happy to continue using Arc.

[flagged]

A pleasant user experience?

Re: Gaining access to anyones Arc browser without them even visiting a website

#153
post #85
post #5

There are a lot of major security vulnerabilities in the world that were made understandably, and can be forgiven if they're handled responsibly and fixed. This is not one of them. In my opinion, this shows a kind of reputation-ruining incompetency that would convince me to never use Arc ever again.

On the other hand, this is pretty impressive: aug 25 5:48pm: got initial contact over signal (encrypted) with arc co-founder hursh aug 25 6:02pm: vulnerability poc executed on hursh's arc account aug 25 6:13pm: added to slack channel after details disclosed over encrypted format aug 26 9:41pm: vulnerability patched, bounty awarded sep 6 7:49pm: cve assigned (CVE-2024-45489) Four hours from out-of-the-blue initial con…

"They put the bandaid over the wound caused by a flagrant disregard for the users privacy, security, and safety."

Phew, glad that's over and will never happen again.

Re: Gaining access to anyones Arc browser without them even visiting a website

#155

$2000 is an insulting amount for such a huge vuln

Judging by blog posts on HN, I got the impression that these vulnerabilities are often not rewarded at all, or rewarded by a minuscule amount. It almost seems like companies are begging hackers to sell these exploits. Perhaps because they aren't penalized by the regulator for breaches?

Re: Gaining access to anyones Arc browser without them even visiting a website

#156
post #130
post #121

Earlier quoted context omitted.

What sort of data does Arc track? Our plain-english Privacy Policy summarizes it well: We don’t know which websites you visit

From the quoted snippet, every page load is leaking both the domain and authed user’s ID to Firebase.

Yeah but if they super promise to not look at incoming Firebase queries they're not tracking you, right?

Re: Gaining access to anyones Arc browser without them even visiting a website

#157
post #117
post #85

Earlier quoted context omitted.

On the other hand, this is pretty impressive: aug 25 5:48pm: got initial contact over signal (encrypted) with arc co-founder hursh aug 25 6:02pm: vulnerability poc executed on hursh's arc account aug 25 6:13pm: added to slack channel after details disclosed over encrypted format aug 26 9:41pm: vulnerability patched, bounty awarded sep 6 7:49pm: cve assigned (CVE-2024-45489) Four hours from out-of-the-blue initial con…

Reacting fast is the least the vendor could do. Bare minimum. This should not be applauded. It should be treated as "well, at least they reacted at a reasonable speed so the root cause was probably not malice". In other words, a quick turnaround with a fix does not lessen the impact of being negligent about security when designing the product.

> Reacting fast is the least the vendor could do.

And yet, so few do. Let's remind ourselves the bar sank into the floor a long time ago.

Re: Gaining access to anyones Arc browser without them even visiting a website

#158
post #148
post #124

Earlier quoted context omitted.

Them acknowledging the issue, then fixing it within 28 hours isn't good enough for you? That kind of response makes me happy to continue using Arc.

[flagged]

1) What's with the hostility?

2) What exactly do I deserve?

Re: Gaining access to anyones Arc browser without them even visiting a website

#160
post #130

Earlier quoted context omitted.

From the quoted snippet, every page load is leaking both the domain and authed user’s ID to Firebase.

Yeah but if they super promise to not look at incoming Firebase queries they're not tracking you, right?

The super promise died with crypto, now you have to add no backsies. My site uses No Backsies Proofs (NBPs) which are encrypted to prove that all my super promises are backed by a no backsie which is stored in the no backsie vault in Antarctica.
Post reply on HN