Live data from Hacker News

The fake browser update scam gets a makeover

krebsonsecurity.com

161–170 of 196 posts

Re: The fake browser update scam gets a makeover

#161
post #150

Earlier quoted context omitted.

To be fair, WordPress core has gotten better. The bigger problem is that there are many WordPress plugins, and many of the plugins can't even pretend to be related to being secure. Until developers are widely taught how to develop secure software, the problem will just keep moving around. We can't make software development environments where it's impossible to create a vulnerability, and we will never convince users…

Very over the top, but bear with me. For example: if your community of plugin developers cannot produce secure(ish) plugins, then it's probably time to get rid of the plugin system altogether. "Plugins endanger our users, we no longer allow them." Being a player that powers a vast part of all websites, gives a responsibility. Taking up that responsibility includes making unpopular decisions. While "getting rid of the…

Do what Chrome has done and continually improve plugin security. Plugins should ask for permissions. Would require an overhaul of WP though.

Re: The fake browser update scam gets a makeover

#162
post #82
post #78

Earlier quoted context omitted.

Could you give some other concrete, practical examples of use cases for cryptocurrencies instead of the passive-aggressive snark?

Preserving privacy, reliable transactions with no, i repeat, no bank or govmnt involvement, no kyc. No/low fees (on some currencies), public immutable databases...

These feel more like theoretical selling points, not documented uses of.

Re: The fake browser update scam gets a makeover

#163
post #63

Earlier quoted context omitted.

I really think Monero in particular deserves way more criticism for their practice. Bitcoin is one thing, Monero is created for and marketed towards cybercriminals, you don't need to be a communications expert to get that premise. I haven't seen it used once for any legitimate purpose. Atleast with Bitcoin and Ethereum you can get buy some legitimate things like VPNs or NFTs https://arstechnica.com/information-techno…

You could say exactly the same thing about any form of encryption. I haven't bought much with Monero, but I always offer it because I adore the premise. I personally think its great, one of the few truly valuable cryptocurrencies.

> > I haven't seen it used once for any legitimate purpose

> You could say exactly the same thing about any form of encryption.

Maybe YOU could, and maybe you'd even be telling the truth, if you're going to this site over http and and not https.

Re: The fake browser update scam gets a makeover

#164

Earlier quoted context omitted.

I would argue that a world that didn't have JS would make these types of attacks more common, not less common. Because in that world, people would have to download desktop apps for everything, which would make people used to downloading desktop apps from random Web pages, which would make malware easier to distribute. In fact, we don't have to imagine that world: it was the world of the late 90s.

Native applications should be downloaded via your distributions' channels, not from random websites.

but realistically they aren't, so why are you even mentioning it?

not every app is on the windows or Mac App store, not every app is on the Linux package managers. even so there is no sandboxing so you're just waiting until one of them gets compromised and hope nothing bad happens

sandboxing hostile apps is the only true way to protect yourself, and even that isn't perfect

Re: The fake browser update scam gets a makeover

#165
post #105

Earlier quoted context omitted.

Full screen still requires a direct user action. So there should still be a step/click between the banner ad and the takeover. But wow.

Can't it be clicking the ad?

If the page is running arbitrary JS served by ads, the site itself is compromised.

Re: The fake browser update scam gets a makeover

#166

Earlier quoted context omitted.

Native applications should be downloaded via your distributions' channels, not from random websites.

but realistically they aren't, so why are you even mentioning it? not every app is on the windows or Mac App store, not every app is on the Linux package managers. even so there is no sandboxing so you're just waiting until one of them gets compromised and hope nothing bad happens sandboxing hostile apps is the only true way to protect yourself, and even that isn't perfect

>even so there is no sandboxing

Lenovo sells all-in-one PCs that run Android, and in a world without Javascript, you can imagine such a thing having become much more common that it actually has become so far in our world (e.g., with more enhancements done to Android to work well with a mouse) and of course Android has very solid sandboxing of apps.

Re: The fake browser update scam gets a makeover

#167
post #99

Earlier quoted context omitted.

What’s the threat model here? Javascript sandbox escapes are extremely rare these days (subjectively they happen less frequently that image or video codec bugs).

Apart from js escapes, you are protected even if you run random executables from the Internet, or any untrusted software in general. More reasons: https://forum.qubes-os.org/t/how-to-pitch-qubes-os/4499/15

> run random executables from the Internet

Well, here's your actual problem. That's a vastly different threat model!

Modern browsers are very well sandboxed.

Re: The fake browser update scam gets a makeover

#168
post #167

Earlier quoted context omitted.

Apart from js escapes, you are protected even if you run random executables from the Internet, or any untrusted software in general. More reasons: https://forum.qubes-os.org/t/how-to-pitch-qubes-os/4499/15

> run random executables from the Internet Well, here's your actual problem. That's a vastly different threat model! Modern browsers are very well sandboxed.

Even with the original threat model, CVEs in the web browsers are much more frequent than in the hardware virtualization with Xen, aren't they?

Re: The fake browser update scam gets a makeover

#169

Earlier quoted context omitted.

You have to pay for the initial insert but it's then hosted forever for free. For reads, you can either download the data from nodes in the network which works somewhat like a torrent, or find a service that has a full copy of the blockchain and is providing it via a HTTP interface.

No absolute guarantee of forever.

I guess there are some ways the ethereum network can cease to exist, when that happens there are probably bigger things to worry about

Re: The fake browser update scam gets a makeover

#170
post #82
post #78

Earlier quoted context omitted.

Could you give some other concrete, practical examples of use cases for cryptocurrencies instead of the passive-aggressive snark?

Preserving privacy, reliable transactions with no, i repeat, no bank or govmnt involvement, no kyc. No/low fees (on some currencies), public immutable databases...

How is having every transaction on the blockchain considered private? If someone knows your wallet address they can see everything you've done
Post reply on HN