Live data from Hacker News

Gaining access to anyones Arc browser without them even visiting a website

kibty.town

371–380 of 538 posts

Re: Gaining access to anyones Arc browser without them even visiting a website

#371
That's how you ruin a company reputation. Not saying it is or not deserved, but how could anyone trust a browser that had such a big security fail.

And what about all the other that have not been reported or may be exploited ?

From now on, every time someone is going to suggest arc browser, there will be another one to remind everyone of that. That's going to be very difficult to overcome when your software already doesn't have that big of a market share.

Re: Gaining access to anyones Arc browser without them even visiting a website

#372
post #248
post #213

I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response…

> We’re also bolstering our security team, and have hired a new senior security engineer. Is there a reason why you don’t have any security-specific positions open on your careers site?

We did but we closed the roles by hiring folks. They just haven’t joined yet.

Re: Gaining access to anyones Arc browser without them even visiting a website

#373
post #255
post #213

I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response…

$2000 is an absurdly small bounty here - you should up that

Ya this is fair! Honestly this was our first bounty ever awarded and we could have been more thoughtful. We’re currently setting up a proper program and based on that rubric will adjust accordingly.

Re: Gaining access to anyones Arc browser without them even visiting a website

#374
post #370
post #302

Earlier quoted context omitted.

Hursh, can you please respond to the above commenter? As an early adopter, I find it fairly troubling to see a company that touts transparency hide the blog post and only publicly "own up to it" within the confines of a single HN thread.

We’re working on a proper security bulletin site that will have these front and center! This was a bit of a stopgap for now.

[deleted]

Re: Gaining access to anyones Arc browser without them even visiting a website

#375
post #250

Earlier quoted context omitted.

What is also strange that I only found out about account after download. Like it was standard thing for the browser. (Sure there are optional accounts in others but login-walled browser?)

Windows is practically login-walled[0] at this point so I imagine people are slowly getting to expect it. [0] witness the magic incantations needed https://www.tomshardware.com/how-to/install-windows-11-witho...

This is so super annoying for shared lab computers

Re: Gaining access to anyones Arc browser without them even visiting a website

#376
post #213

I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response…

Hi Hursh, I'm Tom. A couple friends use Arc and they like it, so I had considered switching to it myself. Now, I won't, not really because of this vulnerability itself (startups make mistakes), but because you paid a measly $2k bounty for a bug that owns, in a dangerous way, all of your users. I won't use a browser made by a vendor who takes the security of their users this unseriously.

By the way, I don't know for sure, but given the severity I suspect on the black market this bug would have gone for a _lot_ more than $2k.

Re: Gaining access to anyones Arc browser without them even visiting a website

#377
post #273

Earlier quoted context omitted.

Pay the guy properly. $2000 is an insult. It should be $50k. This kind of bug could be sold for 100-200k easily.

> This kind of bug could be sold for 100-200k easily Maybe not. If the browser is that buggy, there may be plenty of these lying around. The company itself is pricing the vulnerability at $2k. That should speak volumes to their internal view of their product.

[deleted]

Re: Gaining access to anyones Arc browser without them even visiting a website

#378
post #213

I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response…

Will you be increasing the bug bounty payout? $2,000 is a tiny fraction of what this bug is worth, I hope you will pay the discoverer a proper bounty. You've been handed a golden opportunity to set the right course.

Any new vulnerability will be sold to the highest bidder and/or exploited instead of being reported for the bug bounty because of this.

Re: Gaining access to anyones Arc browser without them even visiting a website

#379
post #260
post #213

I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response…

Thanks for the response. While people might nitpick on how things were handled, the fact that you checked if anyone was affected and fixed it promptly is a good thing.

The CTO and co-founder didn't check in on any of the concerns, completely disappeared after leaving a heartfelt comment. This comes off as incredibly disingenuous.

Re: Gaining access to anyones Arc browser without them even visiting a website

#380
post #37

Earlier quoted context omitted.

> power users Not that many. Most power users don't like to be forced for logging in, before they are able to use the browser.

confirmed i don't even like logging in WHILE using the browser and have never heard of arc

I've only heard of ARC the obsolete archive format ...
Post reply on HN