Live data from Hacker News

Gaining access to anyones Arc browser without them even visiting a website

kibty.town

41–50 of 538 posts

Re: Gaining access to anyones Arc browser without them even visiting a website

#41
post #25

Nice article, but this is hard to read without proper capitalization. My brain uses capitals to scan beginning and ending of text.

If you were using Arc you could add a Boost for "Case: toggle between different capitalization settings - they will apply to all text on the webpage" [1]

/s

[1] https://resources.arc.net/hc/en-us/articles/19212718608151-B...

Re: Gaining access to anyones Arc browser without them even visiting a website

#42
post #40
post #31

Earlier quoted context omitted.

Looks like someone already added it to uBlock Origin since I see no cat. Or maybe the cat doesn't support Firefox...

Did you enable the ui.prefersReducedMotion setting? That hides the cat from what I can tell

Hmm not that I remember. But I have reduced motion enabled on my phone system wide and maybe that synced to my desktop on its own.

Which is scary come to think of it.

Re: Gaining access to anyones Arc browser without them even visiting a website

#43
post #10
post #5

There are a lot of major security vulnerabilities in the world that were made understandably, and can be forgiven if they're handled responsibly and fixed. This is not one of them. In my opinion, this shows a kind of reputation-ruining incompetency that would convince me to never use Arc ever again.

Also, firebase? seriously? this is a company with like, low level software engineers on payroll, and they are using a CRUD backend in a box. cost effective I guess? I wouldn't even have firebase on the long list for a backend if I were architecting something like this. Especially when feature-parity competitors like Supabase just wrap a normal DBMS and auth model.

> low level software engineers on payroll

How does The Browser Company make money? They're giving their product away for free.

Browsers are complicated. It doesn't inspire confidence that the folks in charge of that complexity can't get their heads around a business model.

(Aside: none of their stated company values have anything to do with the product or engineering [1]. They're all about how people feel.)

[1] https://thebrowser.company/values/

Re: Gaining access to anyones Arc browser without them even visiting a website

#44

$2000 is an insulting amount for such a huge vuln

Yeah, you have to have some solid backbone not to sell this off to some malicious party for 20-50x that amount...

A malicious party who wants a vulnerability in a browser effectively nobody uses?

Re: Gaining access to anyones Arc browser without them even visiting a website

#46
post #37

Earlier quoted context omitted.

Lots of developers and power users make a good chunk of Arc's use base. If you're after some interesting credentials then "every Arc user" is a perfect group with little noise.

> power users Not that many. Most power users don't like to be forced for logging in, before they are able to use the browser.

If I had to guess, the typical Arc user is a Mac user in tech. It doesn't run on Linux, most windows users wouldn't run it, and non-tech people haven't heard of it.

Then most engineering IC people will most likely run Firefox or Chrome, so you're probably looking at designers/founders/managers as your target.

Probably some interesting targets there, but not the type that the NSA cares about. Just pure conjecture on my part of course ;).

Re: Gaining access to anyones Arc browser without them even visiting a website

#48
post #46
post #37

Earlier quoted context omitted.

> power users Not that many. Most power users don't like to be forced for logging in, before they are able to use the browser.

If I had to guess, the typical Arc user is a Mac user in tech. It doesn't run on Linux, most windows users wouldn't run it, and non-tech people haven't heard of it. Then most engineering IC people will most likely run Firefox or Chrome, so you're probably looking at designers/founders/managers as your target. Probably some interesting targets there, but not the type that the NSA cares about. Just pure conjecture on m…

The only person I ever saw using Arc was a designer at a tech startup, so this checks out.

Re: Gaining access to anyones Arc browser without them even visiting a website

#49

$2000 is an insulting amount for such a huge vuln

Yeah, you have to have some solid backbone not to sell this off to some malicious party for 20-50x that amount...

Am I too optimistic? I feel like most regular people I know wouldn’t sell this off. Most people are not antisocial criminals by nature, and also wouldn’t know how to contact a “state actor” even if they wanted to.

Re: Gaining access to anyones Arc browser without them even visiting a website

#50
post #25

Nice article, but this is hard to read without proper capitalization. My brain uses capitals to scan beginning and ending of text.

If you were using Arc you could add a Boost for "Case: toggle between different capitalization settings - they will apply to all text on the webpage" [1] /s [1] https://resources.arc.net/hc/en-us/articles/19212718608151-B...

this made me laugh. 10/10
Post reply on HN