Live data from Hacker News

Gaining access to anyones Arc browser without them even visiting a website

kibty.town

31–40 of 538 posts

Re: Gaining access to anyones Arc browser without them even visiting a website

#31

Great research. As I've said elsewhere, Firebase's authentication model is inherently broken and causes loads of issues, and people would be better off writing a small microservice or serverless function that fronts Firebase. Also, for anyone trying to read the article, they should put `/oneko.js` in their adblocker.

> Also, for anyone trying to read the article, they should put `/oneko.js` in their adblocker. Only if you hate cats, pixel art, or are easily distracted.

Looks like someone already added it to uBlock Origin since I see no cat.

Or maybe the cat doesn't support Firefox...

Re: Gaining access to anyones Arc browser without them even visiting a website

#32
post #29

the developers working with firebase should enforce common-sense document crud restrictions in the rules. that's just how firebase is. everyone knows it. now, when talking about ARC BROWSER, i am seriously starting to doubt the competence of the team. I mean, if the rules are broken (no tests? no rules whatsoever?), what else is broken with ARC? are we to await a data leak from ARC? any browser recommendations with p…

Did you took a look at the zen browser? It's an arc clone based on Firefox https://zen-browser.app/

Re: Gaining access to anyones Arc browser without them even visiting a website

#33
post #7
post #5

There are a lot of major security vulnerabilities in the world that were made understandably, and can be forgiven if they're handled responsibly and fixed. This is not one of them. In my opinion, this shows a kind of reputation-ruining incompetency that would convince me to never use Arc ever again.

You’d think that a company shipping a browser would pay a little more attention to security rules. Also, shame on firebase for not making this a bit more idiot proof. And really? $2500? That’s it? You could’ve owned literally every user of Arc… The NSA would’ve paid a couple more zeros on that.

The page says $2,000.

Re: Gaining access to anyones Arc browser without them even visiting a website

#35
post #9
post #7

Earlier quoted context omitted.

You’d think that a company shipping a browser would pay a little more attention to security rules. Also, shame on firebase for not making this a bit more idiot proof. And really? $2500? That’s it? You could’ve owned literally every user of Arc… The NSA would’ve paid a couple more zeros on that.

Are there a lot of Arc users? It seems like a pretty niche browser even compared to other niches.

Lots of developers and power users make a good chunk of Arc's use base. If you're after some interesting credentials then "every Arc user" is a perfect group with little noise.

Re: Gaining access to anyones Arc browser without them even visiting a website

#36
This is a nice investigation and a great read. Sad that they don't normally do bug bounties. $2000 seems small considering the severity of this vulnerability. Though I guess the size and finances of the company is a factor. It takes some serious skills, effort and luck to discover something like that. It should be well compensated.

Re: Gaining access to anyones Arc browser without them even visiting a website

#37
post #9

Earlier quoted context omitted.

Are there a lot of Arc users? It seems like a pretty niche browser even compared to other niches.

Lots of developers and power users make a good chunk of Arc's use base. If you're after some interesting credentials then "every Arc user" is a perfect group with little noise.

> power users

Not that many. Most power users don't like to be forced for logging in, before they are able to use the browser.

Re: Gaining access to anyones Arc browser without them even visiting a website

#38
post #37

Earlier quoted context omitted.

Lots of developers and power users make a good chunk of Arc's use base. If you're after some interesting credentials then "every Arc user" is a perfect group with little noise.

> power users Not that many. Most power users don't like to be forced for logging in, before they are able to use the browser.

confirmed

i don't even like logging in WHILE using the browser and have never heard of arc

Re: Gaining access to anyones Arc browser without them even visiting a website

#40
post #31

Earlier quoted context omitted.

> Also, for anyone trying to read the article, they should put `/oneko.js` in their adblocker. Only if you hate cats, pixel art, or are easily distracted.

Looks like someone already added it to uBlock Origin since I see no cat. Or maybe the cat doesn't support Firefox...

Did you enable the ui.prefersReducedMotion setting? That hides the cat from what I can tell
Post reply on HN