Live data from Hacker News

Gaining access to anyones Arc browser without them even visiting a website

kibty.town

421–430 of 538 posts

Re: Gaining access to anyones Arc browser without them even visiting a website

#421

Oop and I just convinced my wife and brother to move over :o Props to her, she asked about the security and privacy of the browser and I played it off with some fanboy propaganda. Lesson learned on that one. If I only care about the vertical tabs, workspaces, and a (decent) mobile app are there any good equivalents right now?

I use Firefox with Sidebery for vertical (specifically, tree style) tabs, plus a userChrome.css to hide the native horizontal tabs. Firefox has mobile apps, and the Android app supports (some) browser extensions.

It works, it's boring, and it doesn't try to shove gimmicky features in my face.

Re: Gaining access to anyones Arc browser without them even visiting a website

#422

I know Firebase is awesome for plenty of reasons. And I’m not disparaging anyone who works hard on it. There’s a ton of great software behind the product. Unfortunately it’s at the root of almost all of my career’s worst bugs and mistakes (not necessarily caused by me), and it seems like a bit of train wreck in the wrong hands. I’ve had to rescue several clients from it, and have migrated three pretty huge applicatio…

[deleted]

Re: Gaining access to anyones Arc browser without them even visiting a website

#423
post #373
post #255

Earlier quoted context omitted.

$2000 is an absurdly small bounty here - you should up that

Ya this is fair! Honestly this was our first bounty ever awarded and we could have been more thoughtful. We’re currently setting up a proper program and based on that rubric will adjust accordingly.

> Honestly this was our first bounty ever awarded and we could have been more thoughtful

That’s corporate speak for “no, we won’t pay the researcher any more money.”

Re: Gaining access to anyones Arc browser without them even visiting a website

#424
post #57

Very small bounty, but I honestly believe this arc thing won’t last long… Browsers are hard and my only choice has been chrome and will remain so for the long foreseeable future. When I was younger I would enjoy switching to firefox, opera, etc.. But I always came back to chrome because it just worked and always performed when I needed. Chrome/chromium is the safest browser. People tend to fall for the shiny new thin…

> Chrome/chromium is the safest browser. Why do you say that?

1. Chrome's security team has a very good reputation.

2. I don't know how accurate it is in 2024, but there are comparisons like https://madaidans-insecurities.github.io/firefox-chromium.ht... out there.

Re: Gaining access to anyones Arc browser without them even visiting a website

#425

I'm amazed by how profoundly stupid this vulnerability is. To get arbitrary code execution, you literally just send somebody else's user ID, which is fairly trivial to obtain. I don't work at FAANG. I just work at some company that makes crap products you don't actually need, and even I would never build this kind of bug. But these people want to build a web browser , with all the security expertise and moral duty th…

[deleted]

Re: Gaining access to anyones Arc browser without them even visiting a website

#426

I just want to call out that there is a lot of blame put on firebase here in the comments but I think that's just people parroting stuff they don't actually know about (I don't use firebase, I have tried it out in the past though). This isn't some edge case or hard to solve thing in firebase, this is the easy stuff. The real issue here is that someone wrote an api that trusted the client to tell it who they were. At…

This is what happens when you hire solely based on leetcode skill. A shit-tier engineer can master leetcode within months, but a good engineer will probably struggle at Find Nth Smallest Sum problem because he spends more time reading and thinking about code.

Leetcode is a fucking joke to the industry, gone are the days when you actually had good code with devs who spent time thinking about information architecture. In my experience boomer devs are actually the only ones who write idiomatic code. Millennial and Gen-z devs are the worst, they have no understanding beyond basic function calling.

Re: Gaining access to anyones Arc browser without them even visiting a website

#427

Earlier quoted context omitted.

Hi Hursh, I'm Tom. A couple friends use Arc and they like it, so I had considered switching to it myself. Now, I won't, not really because of this vulnerability itself (startups make mistakes), but because you paid a measly $2k bounty for a bug that owns, in a dangerous way, all of your users. I won't use a browser made by a vendor who takes the security of their users this unseriously. By the way, I don't know for s…

So you're not going to use Arc. How much do you pay for the browser you do use?

Thousands

Re: Gaining access to anyones Arc browser without them even visiting a website

#428

Earlier quoted context omitted.

If the devs didn't take security seriously before, why would another node in the communication graph change anything?

because sometimes it's a deadline pushed by management so a change could result in allow more time for design, programming, review, or even full time security personnel. Nobody writes the best most secure software under deadline

Yes, the right person maybe can change the culture in the company (plus contribute lots of technical skills)

Re: Gaining access to anyones Arc browser without them even visiting a website

#429
post #213

I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response…

> including moving off Firebase

Firebase is not to blame here. It's a solid technology which just has to be used properly. Google highlights the fact that setting up ACLs is critical and provides examples on how to set them up correctly.

If none of the developers who were integrating the product into Arc bothered about dealing with the ACLs, then they are either noobs or simply didn't care about security.

Re: Gaining access to anyones Arc browser without them even visiting a website

#430

Earlier quoted context omitted.

Will you be increasing the bug bounty payout? $2,000 is a tiny fraction of what this bug is worth, I hope you will pay the discoverer a proper bounty. You've been handed a golden opportunity to set the right course.

> $2,000 is a tiny fraction of what this bug is worth The Browser Company raises $50mm at a $550mm post-money valuation in March [1]. They’ve raised $125mm altogether. Unless they’re absolute asshats, they’ll increase the bug payout. But people act truly when they don’t think they’re being watched—a vulnerability of this magnitude was worth $2k to this company. That’s…eyebrow raising. [1] https://techcrunch.com/2024/…

They have more users than what I could have guessed:

> As of July 2023, The Browser Company has 100,000+ users

https://www.boringbusinessnerd.com/startups/the-browser-comp....

Post reply on HN