Live data from Hacker News

Gaining access to anyones Arc browser without them even visiting a website

kibty.town

161–170 of 538 posts

Re: Gaining access to anyones Arc browser without them even visiting a website

#161
post #122

Earlier quoted context omitted.

This convinced me to never use Arc again. I created a small guide to migrate from it to an open-source alternative: https://gist.github.com/clouedoc/4acc8355782f394152d8ce19cea... TL;DR: it's not possible to export data from Arc, but it's possible to copy-paste the folder to a Chrome profile, and Firefox and other browsers will detect&import it.

Unfortunately, Zen Browser simply isn't an alternative. If you like Arc, then Zen's UI for tabs and splitting views isn't really anywhere close to satisfying the same needs.

At least Firefox seems to be borrowing some of the UI features slowly. At least the Mozilla Foundation is very public with their wants and goals.

Re: Gaining access to anyones Arc browser without them even visiting a website

#162
https://www.crunchbase.com/organization/the-browser-company/...

> Total Funding Amount $68M

the browser company normally does not do bug bounties, but for this catastrophic of a vuln, they decided to award me with $2,000 USD

I'm struggling to put into words how disappointing I find this.

Re: Gaining access to anyones Arc browser without them even visiting a website

#163
User identity must be derived from security context, typically at the edge of the system.

But it’s so much easier for developers to think of userid as just another parameter, and they forget, and oops now they trust a random user-supplied parameter.

Re: Gaining access to anyones Arc browser without them even visiting a website

#164
post #132
post #52

According to this article, Arc requires an account and sends Google's Firebase the hostname of every page you visit along with your user ID. Does this make Arc the least private web browser currently being used?

I trashed Arc immediately after install when I found out having an account was mandatory. That seemed so silly, like toothbrushes-requiring-wifi absurd. How much moreso now.

Truly. I was looking for a privacy respecting Chromium-based browser to use for Web MiniDisc (https://web.minidisc.wiki/) and came across some enthusiastic praise for Arc. I downloaded it and it immediately wanted me to create an account to even use it. How can that possibly respect my privacy? It went right in the trash.

Re: Gaining access to anyones Arc browser without them even visiting a website

#165
post #5

There are a lot of major security vulnerabilities in the world that were made understandably, and can be forgiven if they're handled responsibly and fixed. This is not one of them. In my opinion, this shows a kind of reputation-ruining incompetency that would convince me to never use Arc ever again.

The mandatory account just to try Arc was always a massive red flag to me - and led to me never trying it. Now I’m glad I didn’t!

You could have just borrowed someone else’s, it appears.

Re: Gaining access to anyones Arc browser without them even visiting a website

#166

Earlier quoted context omitted.

I tend to agree with this. Why re-invent the wheel by spending engineering effort building a CRUD backend? If you're trying to bring value to market, focus on your core differentiator and use existing tooling for your boilerplate stuff.

It’s the “chrome replacement we have been waiting for”, but (if I read this right), my data is still sent to Firebase? Also it’s a browser, not a “tinder but for cats” startup idea I’m writing for my cousin for a beer. It’s not only not a smart engineering decision, it’s also a terrible product, reputation and marketing decision.

> a “tinder but for cats” startup idea

Needs a name. Meowr? Hissr?

Re: Gaining access to anyones Arc browser without them even visiting a website

#167

https://www.crunchbase.com/organization/the-browser-company/... > Total Funding Amount $68M the browser company normally does not do bug bounties, but for this catastrophic of a vuln, they decided to award me with $2,000 USD I'm struggling to put into words how disappointing I find this.

This is 100% company culture, probably the ones that decide this kind of things are not technical or don't understand how important is this.

Re: Gaining access to anyones Arc browser without them even visiting a website

#169
post #124

Thank you for sharing this. I have been using Arc since the first week of beta. The fact that they don't even mentioned this bug/fix on any of their social media is quite alarming. I enjoyed my time with Arc, but I can't possibly see myself continuing to use it after the way they handled this.

Them acknowledging the issue, then fixing it within 28 hours isn't good enough for you? That kind of response makes me happy to continue using Arc.

They afaik never said that they ‘fixed’ the issue where they’re sending Google your every visited url.

Re: Gaining access to anyones Arc browser without them even visiting a website

#170
post #32
post #29

the developers working with firebase should enforce common-sense document crud restrictions in the rules. that's just how firebase is. everyone knows it. now, when talking about ARC BROWSER, i am seriously starting to doubt the competence of the team. I mean, if the rules are broken (no tests? no rules whatsoever?), what else is broken with ARC? are we to await a data leak from ARC? any browser recommendations with p…

Did you took a look at the zen browser? It's an arc clone based on Firefox https://zen-browser.app/

I did. It’s like 20 % an Arc clone, and 80 % of UX papercuts. Like, you can’t have ‘add tab’ button on top when the new tab gets added to the bottom. Or that one sidebar button opens a side window to the right of the sidebar, while another below it opens the favorites to the left and moves the whole sidebar from underneath your mouse.

Looks like a minimal effort css restyle of Firefox.

Post reply on HN