Live data from Hacker News

Gaining access to anyones Arc browser without them even visiting a website

kibty.town

331–340 of 538 posts

Re: Gaining access to anyones Arc browser without them even visiting a website

#331
post #109
post #78

Earlier quoted context omitted.

It’s just another dumb social media trend, like tYpiNg LiKe tHiS. Hopefully it too will phase out. Search for “lowercase trend” and you’ll find reports of it going years back, there’s nothing worth being fascinated about. It has seeped into HN as well. Look closely and you’ll notice several commenters type like that.

Strange to label a failure to capitalize words as a "dumb social media trend", as I'm sure people have been doing that for many years prior to social media. And nobody tYpEs lIkE tHiS except when making a joke.

What do you mean by "before" social media here? Surely not handwritten or typewritered letters, I guess you mean like 2005-2010ish?

The term wasn't popular then but with reddit's and Facebook's infancies being twenty years ago, "social media" (which I understand to refer to platforms where you can talk to people and post things about different topics, so broader and more person-oriented than an SMF forum but narrower than the WWW) have been around for a while

The first time I saw lowercase writing like this was two years ago on the Discord guild/community of a game which got popular on tiktok. I don't know the average age but the (statistical) mode was probably in the range of 13–16

Re: Gaining access to anyones Arc browser without them even visiting a website

#332
post #309

Earlier quoted context omitted.

Reading/watching random tutorials and asking basic questions on SO __instead of reading the official docs__ is a trend I've observed for the last 10 years. Even for stuff pretty well documented like Python, Postgres, React, etc.

Most official documentation is awful, and just an API reference. It's (almost) like asking someone to learn english and then pointing them to a dictionary. And that's because a lot of devs think it's perfectly dandy to just put perfunctory docstrings in their methods, point it at whatever "doc generation" tool, wire it up to a github.io domain and call it a day. There is a reason people crave, want and seek things li…

I remember writing a Twitter library when that was a thing, and being severely disappointed at the quality of the API documentation. There seemed to be little choice other than to experiment to see what responses you’d receive (and hope that it wouldn’t change underneath you). Same was often true with some of the GitHub APIs, although it’s been a few years since I’ve spent time with them.

Re: Gaining access to anyones Arc browser without them even visiting a website

#333
post #132
post #52

According to this article, Arc requires an account and sends Google's Firebase the hostname of every page you visit along with your user ID. Does this make Arc the least private web browser currently being used?

I trashed Arc immediately after install when I found out having an account was mandatory. That seemed so silly, like toothbrushes-requiring-wifi absurd. How much moreso now.

I had the same response when I downloaded Dart and discovered that a programming language thought it was acceptable to send telemetry.

Re: Gaining access to anyones Arc browser without them even visiting a website

#334
post #255
post #213

I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response…

$2000 is an absurdly small bounty here - you should up that

50k or 100k would be far more appropriate given the severity of this issue. But overall, this makes me think there's probably a lot more vulnerabilities in Arc that are undiscovered/unpatched.

Also, there's the whole notion of every URL you visit being sent to Firebase -- were these logged? Awful for a browser.

Re: Gaining access to anyones Arc browser without them even visiting a website

#335
post #255

Earlier quoted context omitted.

$2000 is an absurdly small bounty here - you should up that

50k or 100k would be far more appropriate given the severity of this issue. But overall, this makes me think there's probably a lot more vulnerabilities in Arc that are undiscovered/unpatched. Also, there's the whole notion of every URL you visit being sent to Firebase -- were these logged? Awful for a browser.

[deleted]

Re: Gaining access to anyones Arc browser without them even visiting a website

#336
post #254
post #219

Earlier quoted context omitted.

There isn't really anything you can do to convince me that your team has the expertise to maintain a browser after this. It doesn't matter that you have fixed it, your team is clearly not capable of writing a secure browser, now or ever. I think this should be a resigning matter for the CTO.

And what, you’re going to find them a new CTO? What kind of magical world do you live in where problems are solved by leaders resigning, instead of stepping up and taking accountability?

[deleted]

Re: Gaining access to anyones Arc browser without them even visiting a website

#337

Earlier quoted context omitted.

Not a good look it not being on the main page! I personally use [zen browser]( https://github.com/zen-browser/desktop); I like the ideas of Arc, but it always seemed sketchy to me, especially it being Chromium-based and closed-source.

Heads up: HN doesn't support link naming markdown and some of the extra characters broke the hyperlink. In case the parent can't fix it in time for the edit window: https://github.com/zen-browser/desktop

I wouldn't be surprised if some HN client apps support markdown.

Re: Gaining access to anyones Arc browser without them even visiting a website

#338
post #8

OP is talking about the Arc browser, not the Arc language, the Arc "Atomic React" project, or any of scores of other projects with that name.

https://arc.net/faq I'm definitely not the target audience... Even after reading the faq I have no idea what it does

As a person that recently started using it: it has something like "tree style tabs", and sort of a hybrid merge of the concepts of tabs and bookmarks. In other words, the tabs work more like files on disk -- open/closed, sorted into folders. I'm probably not explaining it well either, but I encourage you to try it if you ever wanted to experiment with alternative tab management (tree style tab, tab groups etc). It's a concept that clicked for me quickly once I started using it, and now I'm angry since I want to use Firefox for philosophical reasons but don't want to go back to regular tabs.

Re: Gaining access to anyones Arc browser without them even visiting a website

#339
post #213

I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response…

Will you be increasing the bug bounty payout? $2,000 is a tiny fraction of what this bug is worth, I hope you will pay the discoverer a proper bounty. You've been handed a golden opportunity to set the right course.

> $2,000 is a tiny fraction of what this bug is worth

The Browser Company raises $50mm at a $550mm post-money valuation in March [1]. They’ve raised $125mm altogether.

Unless they’re absolute asshats, they’ll increase the bug payout. But people act truly when they don’t think they’re being watched—a vulnerability of this magnitude was worth $2k to this company. That’s…eyebrow raising.

[1] https://techcrunch.com/2024/03/21/the-browser-company-raises...

Re: Gaining access to anyones Arc browser without them even visiting a website

#340
post #10

Earlier quoted context omitted.

Also, firebase? seriously? this is a company with like, low level software engineers on payroll, and they are using a CRUD backend in a box. cost effective I guess? I wouldn't even have firebase on the long list for a backend if I were architecting something like this. Especially when feature-parity competitors like Supabase just wrap a normal DBMS and auth model.

> low level software engineers on payroll How does The Browser Company make money? They're giving their product away for free. Browsers are complicated. It doesn't inspire confidence that the folks in charge of that complexity can't get their heads around a business model. (Aside: none of their stated company values have anything to do with the product or engineering [1]. They're all about how people feel.) [1] https…

> Browsers are complicated. It doesn't inspire confidence that the folks in charge of that complexity can't get their heads around a business model.

Unfortunately you are also describing Mozilla here.

Post reply on HN