Live data from Hacker News

Coinbase: Responding to Firefox 0-days in the wild

blog.coinbase.com

21–30 of 97 posts

Re: Coinbase: Responding to Firefox 0-days in the wild

#22

>We collected IOCs from the host in question and started hunting broadly in our network. We did not see any of the IOCs anywhere else in our environment, and blacklisted all the IOCs that we had at that time. Can someone explain what they mean by IOCs?

https://en.wikipedia.org/wiki/Indicator_of_compromise

Re: Coinbase: Responding to Firefox 0-days in the wild

#23
post #9

Does it a help in this case if one runs the browser in a sandbox? E.g. in docker? They can then break out from the browser, but only get to docker with that exploit, and it's unlikely they have a docker exploit too at hand, is it?

They can then break out from the browser, but only get to docker with that exploit, and it's unlikely they have a docker exploit too at hand, is it? If you are running Firefox on X11 (which most Linux users probably still do), you do not need to escape Docker. You can make screenshot, capture keystrokes, and send keystrokes, all through the X11 socket. (Furthermore, you do not need a Docker exploit, a Linux kernel ex…

> If you are running Firefox on X11 (which most Linux users probably still do), you do not need to escape Docker. You can make screenshot, capture keystrokes, and send keystrokes, all through the X11 socket.

Also, this is why Wayland is much more restrictive about these types of operations. People love to complain that "I could do thing with X without special privileges" but the world has moved on since X was designed and it absolutely has not kept up.

Re: Coinbase: Responding to Firefox 0-days in the wild

#25
post #5

Earlier quoted context omitted.

"We're not run by idiots"?

"We didn't literally start out with trading cards."

That's not a great one, Nintendo started out as a playing card company after all. Where you start is quite irrelevant. It's where you end up that matters, and I think MtGox demonstrates that quite clearly.

Re: Coinbase: Responding to Firefox 0-days in the wild

#26
> CVE-2019–11707 was simultaneously discovered by Samuel Groß of Google’s Project Zero and the attacker.

At least another time in the last week I read on other threads on HN or related links that vulnerability were found almost the same time by independent people.

Here we have a researcher from Google’s Project Zero and the attacker.

How do you explain these coincidences?

What is the chance that some prominent researchers being targeted and their systems are actually exploited?

Re: Coinbase: Responding to Firefox 0-days in the wild

#27

> CVE-2019–11707 was simultaneously discovered by Samuel Groß of Google’s Project Zero and the attacker. At least another time in the last week I read on other threads on HN or related links that vulnerability were found almost the same time by independent people. Here we have a researcher from Google’s Project Zero and the attacker. How do you explain these coincidences? What is the chance that some prominent resear…

This is not an uncommon phenomenon and not specific to vuln research. It happens all the time in mathematics, the sciences... [0]

Far more likely: there is a related cause that made two people think to try the same thing at approximately the same time. Someone publishes a new JIT type confusion bug, someone realizes "oh man it never occurred to me that X could trigger bug type Y", they start digging, and...

[0]: https://en.wikipedia.org/wiki/Multiple_discovery

Re: Coinbase: Responding to Firefox 0-days in the wild

#28
post #23

Earlier quoted context omitted.

They can then break out from the browser, but only get to docker with that exploit, and it's unlikely they have a docker exploit too at hand, is it? If you are running Firefox on X11 (which most Linux users probably still do), you do not need to escape Docker. You can make screenshot, capture keystrokes, and send keystrokes, all through the X11 socket. (Furthermore, you do not need a Docker exploit, a Linux kernel ex…

> If you are running Firefox on X11 (which most Linux users probably still do), you do not need to escape Docker. You can make screenshot, capture keystrokes, and send keystrokes, all through the X11 socket. Also, this is why Wayland is much more restrictive about these types of operations. People love to complain that "I could do thing with X without special privileges" but the world has moved on since X was designe…

People are totally right to complain about basic features being left out, not not having a standard secured low-overhead video recording and screenshotting is simply stupid and harmful for Linux.

Re: Coinbase: Responding to Firefox 0-days in the wild

#29

Coinbase should be hiring pentesters and giving them employee level access - even access to commit and deploy code. Any insider shouldn't be able to steal more than the hot wallet, and even that should be hard. I actually wouldn't put much effort into border security. At coinbases level of risk, evildoers will have no qualms bribing an employee to install a backdoor in their machine.

Why do you believe that is not the case?

Re: Coinbase: Responding to Firefox 0-days in the wild

#30

> CVE-2019–11707 was simultaneously discovered by Samuel Groß of Google’s Project Zero and the attacker. At least another time in the last week I read on other threads on HN or related links that vulnerability were found almost the same time by independent people. Here we have a researcher from Google’s Project Zero and the attacker. How do you explain these coincidences? What is the chance that some prominent resear…

The article clearly states that the attackers and the researchers use very different ways of triggering the vulnerability. It is a coincidence.
Post reply on HN