Live data from Hacker News

Gaining access to anyones Arc browser without them even visiting a website

kibty.town

481–490 of 538 posts

Re: Gaining access to anyones Arc browser without them even visiting a website

#481

Earlier quoted context omitted.

As a person that recently started using it: it has something like "tree style tabs", and sort of a hybrid merge of the concepts of tabs and bookmarks. In other words, the tabs work more like files on disk -- open/closed, sorted into folders. I'm probably not explaining it well either, but I encourage you to try it if you ever wanted to experiment with alternative tab management (tree style tab, tab groups etc). It's…

Firefox has a heavily customizable tree style tab extension.

Yeah, I tried it, but it does a fundamentally different thing than Arc

Re: Gaining access to anyones Arc browser without them even visiting a website

#483

Earlier quoted context omitted.

Will you be increasing the bug bounty payout? $2,000 is a tiny fraction of what this bug is worth, I hope you will pay the discoverer a proper bounty. You've been handed a golden opportunity to set the right course.

> $2,000 is a tiny fraction of what this bug is worth The Browser Company raises $50mm at a $550mm post-money valuation in March [1]. They’ve raised $125mm altogether. Unless they’re absolute asshats, they’ll increase the bug payout. But people act truly when they don’t think they’re being watched—a vulnerability of this magnitude was worth $2k to this company. That’s…eyebrow raising. [1] https://techcrunch.com/2024/…

It doesn't matter what bug bounty pay pay. If it was 200k people would say it's not enough.

Re: Gaining access to anyones Arc browser without them even visiting a website

#484
post #378

Earlier quoted context omitted.

Any new vulnerability will be sold to the highest bidder and/or exploited instead of being reported for the bug bounty because of this.

Most of the vulnerabilities I've disclosed, and I've seen disclosed, were disclosed for free, with no expectation of getting anything. Why do you think every researcher is an amoral penny pincher who will just sell exploits without caring for the consequences?

Wanting money to live = penny pinching. Very cool.

Re: Gaining access to anyones Arc browser without them even visiting a website

#485
post #401
post #373

Earlier quoted context omitted.

Ya this is fair! Honestly this was our first bounty ever awarded and we could have been more thoughtful. We’re currently setting up a proper program and based on that rubric will adjust accordingly.

$200k for this big bug.

My comment has been downvoted twice, but I don't see it grayed out, I wonder why.

Re: Gaining access to anyones Arc browser without them even visiting a website

#486

Earlier quoted context omitted.

I wouldn't be surprised if some HN client apps support markdown.

I use the Octal app on iOS which does, though it seems the trailing ; broke the link for this md renderer.

I think GP is my most downvoted comment ever. Of all things haha.

Re: Gaining access to anyones Arc browser without them even visiting a website

#487

Earlier quoted context omitted.

Let's set aside morality for a second. There is a reason low payouts are bad without even having to consider the black market: it pushes people to search for bugs in a competitor's app that pays more instead of in your app! If your app is paying out $2K and a competing app pays out $100K, why would anyone bother searching for bugs in your app? Every minute spent researching your app pay 1/50th of what you'd get searc…

Bug bounties are always in relation to severity, number of users potentially at risk, and market cap. A browser operating at a deficit from a small company with a small market share cannot pay 100k even if they wanted to. If you and a couple friends released an app that had 50k users and you’d not even broken even, can I claim my 100k by finding a critical RCE?

No, because you probably haven’t bothered to find said CVE. There’s a strange refusal to understand the simplest market considerations here. I understand it sucks and you may not be able to afford it, but the consequence, regardless of all the reasons you can give, is that you will get less of the right kind of attention (security researchers). Now, you can hope that you will also get less of the wrong kind of attention too, and if you’re lucky all of these will scale together. Or, alternatively, you can for example not start by introducing features like Boosts that have a higher probability of adding security vulnerabilities, counter-acting the initial benefit of riding in Chrome’s security by using the same engine. Browsers are particularly sensitive products. It’s a tough space because you’re asking users to live their life in there. In theory using Chromium as a base should be a good hack to be able to do this while plausibly offering comparable security to the well established players.

Long story short, there are ways to creatively solve this problem, or avoid it, but simply exclaiming “well it would be too hard to do the necessary thing” is probably not a good solution.

Re: Gaining access to anyones Arc browser without them even visiting a website

#488

I'm amazed by how profoundly stupid this vulnerability is. To get arbitrary code execution, you literally just send somebody else's user ID, which is fairly trivial to obtain. I don't work at FAANG. I just work at some company that makes crap products you don't actually need, and even I would never build this kind of bug. But these people want to build a web browser , with all the security expertise and moral duty th…

Can you explain how you could get someone else's user id? I get that this is still a big vulnerability but am trying to understand how that would happen.

Re: Gaining access to anyones Arc browser without them even visiting a website

#489

Earlier quoted context omitted.

Hi Hursh, I'm Tom. A couple friends use Arc and they like it, so I had considered switching to it myself. Now, I won't, not really because of this vulnerability itself (startups make mistakes), but because you paid a measly $2k bounty for a bug that owns, in a dangerous way, all of your users. I won't use a browser made by a vendor who takes the security of their users this unseriously. By the way, I don't know for s…

So you're not going to use Arc. How much do you pay for the browser you do use?

Statistically, Tom is using a browser that cost him $0. Why are you asking?
Post reply on HN