Earlier quoted context omitted.
As a person that recently started using it: it has something like "tree style tabs", and sort of a hybrid merge of the concepts of tabs and bookmarks. In other words, the tabs work more like files on disk -- open/closed, sorted into folders. I'm probably not explaining it well either, but I encourage you to try it if you ever wanted to experiment with alternative tab management (tree style tab, tab groups etc). It's…
Firefox has a heavily customizable tree style tab extension.
Gaining access to anyones Arc browser without them even visiting a website
481–490 of 538 posts
Re: Gaining access to anyones Arc browser without them even visiting a website
#482Re: Gaining access to anyones Arc browser without them even visiting a website
#483Earlier quoted context omitted.
Will you be increasing the bug bounty payout? $2,000 is a tiny fraction of what this bug is worth, I hope you will pay the discoverer a proper bounty. You've been handed a golden opportunity to set the right course.
> $2,000 is a tiny fraction of what this bug is worth The Browser Company raises $50mm at a $550mm post-money valuation in March [1]. They’ve raised $125mm altogether. Unless they’re absolute asshats, they’ll increase the bug payout. But people act truly when they don’t think they’re being watched—a vulnerability of this magnitude was worth $2k to this company. That’s…eyebrow raising. [1] https://techcrunch.com/2024/…
Re: Gaining access to anyones Arc browser without them even visiting a website
#484Earlier quoted context omitted.
Any new vulnerability will be sold to the highest bidder and/or exploited instead of being reported for the bug bounty because of this.
Most of the vulnerabilities I've disclosed, and I've seen disclosed, were disclosed for free, with no expectation of getting anything. Why do you think every researcher is an amoral penny pincher who will just sell exploits without caring for the consequences?
Re: Gaining access to anyones Arc browser without them even visiting a website
#485Earlier quoted context omitted.
Ya this is fair! Honestly this was our first bounty ever awarded and we could have been more thoughtful. We’re currently setting up a proper program and based on that rubric will adjust accordingly.
$200k for this big bug.
Re: Gaining access to anyones Arc browser without them even visiting a website
#486Re: Gaining access to anyones Arc browser without them even visiting a website
#487Earlier quoted context omitted.
Let's set aside morality for a second. There is a reason low payouts are bad without even having to consider the black market: it pushes people to search for bugs in a competitor's app that pays more instead of in your app! If your app is paying out $2K and a competing app pays out $100K, why would anyone bother searching for bugs in your app? Every minute spent researching your app pay 1/50th of what you'd get searc…
Bug bounties are always in relation to severity, number of users potentially at risk, and market cap. A browser operating at a deficit from a small company with a small market share cannot pay 100k even if they wanted to. If you and a couple friends released an app that had 50k users and you’d not even broken even, can I claim my 100k by finding a critical RCE?
Long story short, there are ways to creatively solve this problem, or avoid it, but simply exclaiming “well it would be too hard to do the necessary thing” is probably not a good solution.
Re: Gaining access to anyones Arc browser without them even visiting a website
#488I'm amazed by how profoundly stupid this vulnerability is. To get arbitrary code execution, you literally just send somebody else's user ID, which is fairly trivial to obtain. I don't work at FAANG. I just work at some company that makes crap products you don't actually need, and even I would never build this kind of bug. But these people want to build a web browser , with all the security expertise and moral duty th…
Re: Gaining access to anyones Arc browser without them even visiting a website
#489Earlier quoted context omitted.
Hi Hursh, I'm Tom. A couple friends use Arc and they like it, so I had considered switching to it myself. Now, I won't, not really because of this vulnerability itself (startups make mistakes), but because you paid a measly $2k bounty for a bug that owns, in a dangerous way, all of your users. I won't use a browser made by a vendor who takes the security of their users this unseriously. By the way, I don't know for s…
So you're not going to use Arc. How much do you pay for the browser you do use?