Live data from Hacker News

Gaining access to anyones Arc browser without them even visiting a website

kibty.town

361–370 of 538 posts

Re: Gaining access to anyones Arc browser without them even visiting a website

#361
post #328
post #242

Earlier quoted context omitted.

It's extremely irritating, distracting, and breaks focus on the content instead of the annoying stylistic choice, just an fyi..but I imagine you probably like that this is true and purposely try to annoy the people that aren't in the little club. If not, then I suggest not doing it. The tone I perceive from it is "F**** the reader"

> ... you probably like that this is true and purposely try to annoy ... I don't know if you meant to direct this at the person you're replying to but I'm convinced the overwhelming majority of people don't get out of bed in the morning with any of that in mind It's comments like these that make me reconsider what hateful meanings others might read into my communications or mistakes

Yes I mean this to anyone repeatedly, consciously fighting natural convention and muscle memory to purposely type every letter in lowercase, knowing that this produces in the reader a slight dissonance and distraction constantly, and choosing to do this instead of using convention that everyone understands so that "syntax" does not become the focus and instead the content of the message does.

Otherwise they're "drawing attention" to the style and themselves for narcissistic reasons. I would simply assume they'd have to know the annoyance this brings to the reader, so I assume it's on purpose.

I would feel the same about someone writing code in a consistently purposeful unorthodox style and against convention in such an obvious and effortful way that no one is used to. Personally, and YMMV, I like to try to write in as clear a way as I can to get my point across as much as possible. Useless stylistic fluff in something that isn't poetry, seems counter to that purpose.

>mistakes

It's not a mistake though to ensure every letter one writes is not following convention and English syntax. Accidents and mistakes are a different thing.

Re: Gaining access to anyones Arc browser without them even visiting a website

#362
post #213

I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response…

Hursh / ha470, where did you go? There are lots of good questions in the replies to your thread, yet you went dark immediately after posting more than 8 hours ago. It's hard to imagine what could be more pressing than addressing people's concerns after a major security incident such as this.

To be honest, I'm a bit disappointed. For future reference, this doesn't seem like a good strategy to contain reputational damage.

Re: Gaining access to anyones Arc browser without them even visiting a website

#363
post #278
post #254

Earlier quoted context omitted.

And what, you’re going to find them a new CTO? What kind of magical world do you live in where problems are solved by leaders resigning, instead of stepping up and taking accountability?

Taking accountability can and should include admitting you're the wrong person for the job and resigning.

CTO is simply a title, the proper response here would be to hire a head of security and build it into the culture from the ground up.

I'm looking at all of the Arc Max features which probably need to be architected correctly to be secure/privacy-preserving.

They could take a lot of inspiration from iCloud Private Relay and iOS security architectures in addition to really understanding the Chrome security model.

Re: Gaining access to anyones Arc browser without them even visiting a website

#364
post #124

Earlier quoted context omitted.

Them acknowledging the issue, then fixing it within 28 hours isn't good enough for you? That kind of response makes me happy to continue using Arc.

Where did they acknowledge the issue? There’s nothing about this issue on their website or their Twitter feed.

They only acknowledged the issue after the write up from the researcher and claimed they thought they didn't need to include it in the release notes because it was a "backend fix".

Re: Gaining access to anyones Arc browser without them even visiting a website

#365
post #25

Nice article, but this is hard to read without proper capitalization. My brain uses capitals to scan beginning and ending of text.

Young people (like me) use lowercaps like that all the time. Around 50% of the young people I know purposefully turn off auto-caps on their phone.

Why? I really couldn't say. I think we just like the feel of it. The only reason I type with proper capitalization on HN and my blog is because I know older people read it.

Re: Gaining access to anyones Arc browser without them even visiting a website

#367
post #219

Earlier quoted context omitted.

There isn't really anything you can do to convince me that your team has the expertise to maintain a browser after this. It doesn't matter that you have fixed it, your team is clearly not capable of writing a secure browser, now or ever. I think this should be a resigning matter for the CTO.

Surprise surprise, turns out it takes a looong time for every software startup to finally strip out all the hacky stuff from their MVP days. Apparently nobody on this startup community forum has ever built a startup before. Pro tip: if stuff like this violently upsets you, never be an early adopter of anything. Wait 5-10 years and then make your move. Personally, I expect stuff like this from challenger alternatives,…

[flagged]

Re: Gaining access to anyones Arc browser without them even visiting a website

#368
post #249

Earlier quoted context omitted.

my brother uses arc browser , he is a developer . I think he saw it from somebody using it (maybe theo t3 or some other creator he watches) , and he found it cool (plus there were lot of videos flooded with saying arc is really great IDK) If someone finds something cool on the internet. They are going to try it , given that they are capable to do so. He had a mac so he was able to do so , Even I tried to run arc on w…

> He had a mac so he was able to do so How? I have mac as well but when I've download it some time ago it required login. Has that changed?

No. You still need to create a login.

Everyone else at work likes it, so I signed up with my work e-mail address and use it for work. All of my complicated browsing needs are done for work, so there's a good fit there.

Re: Gaining access to anyones Arc browser without them even visiting a website

#369
post #278

Earlier quoted context omitted.

Taking accountability can and should include admitting you're the wrong person for the job and resigning.

CTO is simply a title, the proper response here would be to hire a head of security and build it into the culture from the ground up. I'm looking at all of the Arc Max features which probably need to be architected correctly to be secure/privacy-preserving. They could take a lot of inspiration from iCloud Private Relay and iOS security architectures in addition to really understanding the Chrome security model.

If the devs didn't take security seriously before, why would another node in the communication graph change anything?

Re: Gaining access to anyones Arc browser without them even visiting a website

#370
post #302

Earlier quoted context omitted.

Was the post written for HN users only? I cannot see it on your blog page ( https://arc.net/blog ). It’s not posted on your twitter either. Your whole handling seems to be responding only if there is enough noise about it.

Hursh, can you please respond to the above commenter? As an early adopter, I find it fairly troubling to see a company that touts transparency hide the blog post and only publicly "own up to it" within the confines of a single HN thread.

We’re working on a proper security bulletin site that will have these front and center! This was a bit of a stopgap for now.
Post reply on HN