Live data from Hacker News

Gaining access to anyones Arc browser without them even visiting a website

kibty.town

251–260 of 538 posts

Re: Gaining access to anyones Arc browser without them even visiting a website

#251
post #213

I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response…

no mention of the pitiful bounty reward (2000 usd). only sorry and thanks. Please award this person a proper bounty.

Re: Gaining access to anyones Arc browser without them even visiting a website

#252

Earlier quoted context omitted.

Yeah, you have to have some solid backbone not to sell this off to some malicious party for 20-50x that amount...

Am I too optimistic? I feel like most regular people I know wouldn’t sell this off. Most people are not antisocial criminals by nature, and also wouldn’t know how to contact a “state actor” even if they wanted to.

Opportunity makes a thief. Most people does not have the opportunity even if they have skill.

Re: Gaining access to anyones Arc browser without them even visiting a website

#253

Arc was recommended to me by a friend. I deleted upon finding out I needed an account to use it. The excuse Arc gives is in case you want to sync. I'm capable of opting into that.

"in case" is good excuse if the account is optional. Which is not case here.

Re: Gaining access to anyones Arc browser without them even visiting a website

#254
post #219
post #213

I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response…

There isn't really anything you can do to convince me that your team has the expertise to maintain a browser after this. It doesn't matter that you have fixed it, your team is clearly not capable of writing a secure browser, now or ever. I think this should be a resigning matter for the CTO.

And what, you’re going to find them a new CTO? What kind of magical world do you live in where problems are solved by leaders resigning, instead of stepping up and taking accountability?

Re: Gaining access to anyones Arc browser without them even visiting a website

#255
post #213

I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response…

$2000 is an absurdly small bounty here - you should up that

Re: Gaining access to anyones Arc browser without them even visiting a website

#256
Damn, that is bad. While I enjoyed reading through the write-up, I think a "summary section" at the top would have benefited me lol.

Someone recently recommended Arc to me, I installed it on my macbook and then never actually used it when I realized there's no Linux version available, and I like a consistent browser experience across all my devices.

Re: Gaining access to anyones Arc browser without them even visiting a website

#257
post #181

Earlier quoted context omitted.

As someone with an app built on firebase, yes. As the author rightly points out, it's very easy to misconfigure, but basic security practices like these are highlighted in bright, bold warning text in the Firebase docs. Security rules are meant to be taken seriously, and it's your only line of defense.

> bold warning text in the Firebase docs. Unfortunately, we currently have an industry where highly paid "engineers" unironically believe that their job can be done by reading/watching random tutorials, googling for StackOverflow answers, and pasting code from gists. Attentively reading documentation or developing a mental model of how your tools work so that you know how they are built to be handled does not make it…

This may or may not be fair, but in my view, the type of person that would opt for a firebase solution is probably the type of person most vulnerable to foot guns.

Re: Gaining access to anyones Arc browser without them even visiting a website

#258

Earlier quoted context omitted.

Are you defining amateurs as people who are not your coworkers? It can still be an amateur mistake.

Coworker implies paid work, and therefore they are not amateurs. They very well may make the same mistakes, but those mistakes would be professional mistakes.

Why this level of pedantry when the meaning is absolutely clear? A professional can make an amateur mistake. This makes perfect sense. That isn't implying the professional is actually an amateur, but that he made a mistake that an amateur would make.

Re: Gaining access to anyones Arc browser without them even visiting a website

#259
post #219
post #213

I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response…

There isn't really anything you can do to convince me that your team has the expertise to maintain a browser after this. It doesn't matter that you have fixed it, your team is clearly not capable of writing a secure browser, now or ever. I think this should be a resigning matter for the CTO.

Well, the current team perhaps.

But it's also likely part of the startup mentally of "move fast and break things", which is not entirely compatible with the goal of the browser.

Re: Gaining access to anyones Arc browser without them even visiting a website

#260
post #213

I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response…

Thanks for the response.

While people might nitpick on how things were handled, the fact that you checked if anyone was affected and fixed it promptly is a good thing.

Post reply on HN