Earlier quoted context omitted.
$2000 is an absurdly small bounty here - you should up that
Ya this is fair! Honestly this was our first bounty ever awarded and we could have been more thoughtful. We’re currently setting up a proper program and based on that rubric will adjust accordingly.
Gaining access to anyones Arc browser without them even visiting a website
401–410 of 538 posts
Re: Gaining access to anyones Arc browser without them even visiting a website
#402Re: Gaining access to anyones Arc browser without them even visiting a website
#403Earlier quoted context omitted.
Hi Hursh, I'm Tom. A couple friends use Arc and they like it, so I had considered switching to it myself. Now, I won't, not really because of this vulnerability itself (startups make mistakes), but because you paid a measly $2k bounty for a bug that owns, in a dangerous way, all of your users. I won't use a browser made by a vendor who takes the security of their users this unseriously. By the way, I don't know for s…
Selling vulnerability on the black market is immoral and may be illegal. The goal of bug bounty programs was initially to signal "we won't sue white hat researchers who disclose their findings to us", when did it evolve into "pay me more than criminals would, or else"?
If your app is paying out $2K and a competing app pays out $100K, why would anyone bother searching for bugs in your app? Every minute spent researching your app pay 1/50th of what you'd get searching in the competing app (unless your app has 50x more bugs I suppose, but perhaps then you have bigger problems...).
I'm always so confused by the negative responses to people asking for higher bug bounties. It feels like it still comes from this weird entitlement that researchers owe you the bug report. Perhaps they do. But you know what they definitely don't owe you? Looking for new bugs! Ultimately this attitude always leads to the same place: the places that pay more protect their users better. It is thus completely reasonable to decide not to use a product as a user if the company that makes the product isn't paying high bug bounties. It's the same as discovering that a restaurant is cheeping out on health inspections and deciding to no longer eat there.
Re: Gaining access to anyones Arc browser without them even visiting a website
#404Re: Gaining access to anyones Arc browser without them even visiting a website
#405Earlier quoted context omitted.
> lowercase without caps reads with a warmer, informal tone No, it reads as "I'm uneducated and don't know how to write the English language properly". It's incredibly obnoxious for people to use as an affectation.
To me, proper capitalization is easier to parse - not massively so, but a little bit. So writing without caps is a bit of a jerk move. You're making it harder for me to read, either because you're lazy or because you want to affect a style. In either case it's a bit of a jerk move. It's more of a jerk move when it's done on a discussion board, because what you write once is read multiple times. So the cost multiplies…
Mobile operating systems (or is it just iOS?) by default turn the shift on automatically when starting a new sentence and are pretty consistently fast and right. It’s more surprising to me when someone doesn’t use proper capitalisation from mobile.
Re: Gaining access to anyones Arc browser without them even visiting a website
#406Earlier quoted context omitted.
Hursh, can you please respond to the above commenter? As an early adopter, I find it fairly troubling to see a company that touts transparency hide the blog post and only publicly "own up to it" within the confines of a single HN thread.
We’re working on a proper security bulletin site that will have these front and center! This was a bit of a stopgap for now.
Browser security is more than finding the best PR strategy, it's a mindset that prioritizes the user's well being over the product's image. I've deleted my account and uninstalled Arc. Not because of the issue in itself, but because it's clear what the response has been aiming to protect (not my data).
Re: Gaining access to anyones Arc browser without them even visiting a website
#407Earlier quoted context omitted.
> also wouldn’t know how to contact a “state actor” even if they wanted to. That's why brokerages like Zerodium exist - you can sell it to them, and they'll sell it onto state actors.
How does this work in practice? What systems are in place to prevent someone selling an exploit and then turning around and disclosing it properly as soon as they have the money, potentially getting even more money through legal channels? Is there some sort of escrow?
Re: Gaining access to anyones Arc browser without them even visiting a website
#408Earlier quoted context omitted.
> $2,000 is a tiny fraction of what this bug is worth The Browser Company raises $50mm at a $550mm post-money valuation in March [1]. They’ve raised $125mm altogether. Unless they’re absolute asshats, they’ll increase the bug payout. But people act truly when they don’t think they’re being watched—a vulnerability of this magnitude was worth $2k to this company. That’s…eyebrow raising. [1] https://techcrunch.com/2024/…
"We will let anyone run arbitrary JavaScript on all your web pages if you send them a referral link" is surely a 6-7 figure vulnerability for a web browser. That this vulnerability was discoverable using about two steps of analysis tools suggests many more issues are in the product.
Re: Gaining access to anyones Arc browser without them even visiting a website
#409Earlier quoted context omitted.
To me, proper capitalization is easier to parse - not massively so, but a little bit. So writing without caps is a bit of a jerk move. You're making it harder for me to read, either because you're lazy or because you want to affect a style. In either case it's a bit of a jerk move. It's more of a jerk move when it's done on a discussion board, because what you write once is read multiple times. So the cost multiplies…
I use lowercase in most places precisely because it forces me to use shorter sentences and split text into paragraphs. The result is easier on the reader. It's just a habit from chat rooms and instant messengers of the beginning of this century. Most of my mates who write like that are well over 30. This whole subthread is one projection after another.
Re: Gaining access to anyones Arc browser without them even visiting a website
#410Earlier quoted context omitted.
Was the post written for HN users only? I cannot see it on your blog page ( https://arc.net/blog ). It’s not posted on your twitter either. Your whole handling seems to be responding only if there is enough noise about it.
Not a good look it not being on the main page! I personally use [zen browser]( https://github.com/zen-browser/desktop); I like the ideas of Arc, but it always seemed sketchy to me, especially it being Chromium-based and closed-source.