Nice article, but this is hard to read without proper capitalization. My brain uses capitals to scan beginning and ending of text.
/s
[1] https://resources.arc.net/hc/en-us/articles/19212718608151-B...
41–50 of 538 posts
Nice article, but this is hard to read without proper capitalization. My brain uses capitals to scan beginning and ending of text.
/s
[1] https://resources.arc.net/hc/en-us/articles/19212718608151-B...
Earlier quoted context omitted.
Looks like someone already added it to uBlock Origin since I see no cat. Or maybe the cat doesn't support Firefox...
Did you enable the ui.prefersReducedMotion setting? That hides the cat from what I can tell
Which is scary come to think of it.
There are a lot of major security vulnerabilities in the world that were made understandably, and can be forgiven if they're handled responsibly and fixed. This is not one of them. In my opinion, this shows a kind of reputation-ruining incompetency that would convince me to never use Arc ever again.
Also, firebase? seriously? this is a company with like, low level software engineers on payroll, and they are using a CRUD backend in a box. cost effective I guess? I wouldn't even have firebase on the long list for a backend if I were architecting something like this. Especially when feature-parity competitors like Supabase just wrap a normal DBMS and auth model.
How does The Browser Company make money? They're giving their product away for free.
Browsers are complicated. It doesn't inspire confidence that the folks in charge of that complexity can't get their heads around a business model.
(Aside: none of their stated company values have anything to do with the product or engineering [1]. They're all about how people feel.)
Earlier quoted context omitted.
Lots of developers and power users make a good chunk of Arc's use base. If you're after some interesting credentials then "every Arc user" is a perfect group with little noise.
> power users Not that many. Most power users don't like to be forced for logging in, before they are able to use the browser.
Then most engineering IC people will most likely run Firefox or Chrome, so you're probably looking at designers/founders/managers as your target.
Probably some interesting targets there, but not the type that the NSA cares about. Just pure conjecture on my part of course ;).
Earlier quoted context omitted.
> power users Not that many. Most power users don't like to be forced for logging in, before they are able to use the browser.
If I had to guess, the typical Arc user is a Mac user in tech. It doesn't run on Linux, most windows users wouldn't run it, and non-tech people haven't heard of it. Then most engineering IC people will most likely run Firefox or Chrome, so you're probably looking at designers/founders/managers as your target. Probably some interesting targets there, but not the type that the NSA cares about. Just pure conjecture on m…
$2000 is an insulting amount for such a huge vuln
Yeah, you have to have some solid backbone not to sell this off to some malicious party for 20-50x that amount...
Nice article, but this is hard to read without proper capitalization. My brain uses capitals to scan beginning and ending of text.
If you were using Arc you could add a Boost for "Case: toggle between different capitalization settings - they will apply to all text on the webpage" [1] /s [1] https://resources.arc.net/hc/en-us/articles/19212718608151-B...