Live data from Hacker News

Gaining access to anyones Arc browser without them even visiting a website

kibty.town

51–60 of 538 posts

Re: Gaining access to anyones Arc browser without them even visiting a website

#51
post #19
post #3

[flagged]

I got downvoted for calling it a dog?? Now that's ruff!!

Good pun :)

HN tends to be a little hard on brief comments. My current understanding is that comments with little substance are totally acceptable provided they're good natured.

For example this comment by dang "There's nothing wrong with submitting a comment saying just "Thanks."" https://news.ycombinator.com/item?id=37251836.

Also from the guidelines "Comments should get more thoughtful and substantive, not less, as a topic gets more divisive": this post's topic doesn't likely qualify as divisive.

Re: Gaining access to anyones Arc browser without them even visiting a website

#54
post #31

Earlier quoted context omitted.

> Also, for anyone trying to read the article, they should put `/oneko.js` in their adblocker. Only if you hate cats, pixel art, or are easily distracted.

Looks like someone already added it to uBlock Origin since I see no cat. Or maybe the cat doesn't support Firefox...

I use uBlock Origin and Firefox (on Mac) and see the cat.

Re: Gaining access to anyones Arc browser without them even visiting a website

#55
post #53

For context: what is this 'arc' that the blog post mentions? I presumes it's not Paul Graham's Lisp dialect in this context? EDIT: seems to be a browser or so?

Yes it's a new browser who tries to change the UX from traditional browsers: https://arc.net/

Re: Gaining access to anyones Arc browser without them even visiting a website

#56
post #5

There are a lot of major security vulnerabilities in the world that were made understandably, and can be forgiven if they're handled responsibly and fixed. This is not one of them. In my opinion, this shows a kind of reputation-ruining incompetency that would convince me to never use Arc ever again.

I agree & disagree.

Browsers are very important part of our life. If someone compromises our browsers , they basically compromise every single aspect of privacy and can lead to insane scams.

And because arc browser is new , they wanted to build fast and so they used tools like firebase / firestore to be capable of moving faster (they are a startup)

Now I have read the article but I am still not sure how much of this can be contributed to firebase or arc

On the following page from same author (I think) https://env.fail/posts/firewreck-1 , tldr states

- Firebase allows for easy misconfiguration of security rules with zero warnings

- This has resulted in hundreds of sites exposing a total of ~125 Million user records, including plaintext passwords & sensitive billing information

So because firebase advocates itself to the developers as being safe yet not being safe , I think arc succumbed to it.

firestore has a tendency to not abide by the system proxy settings in the Swift SDK for firebase, so going off my hunch,

Also , you say that you have been convinced to never use arc again.

Did you know that chrome gives an unfair advantage to its user sites by giving system information (core usage etc.) and some other things which are not supposed to be seen by browsers only to the websites starting with *.google.com ?

this is just recently discovered , just imagine if something more serious is also just waiting in the shadows Couldn't this also be considered a major security vulnerability just waiting to be happen if some other exploit like this can be discovered / google.com is leaked and now your cpu information and way more other stuff which browsers shouldn't know is with a malicious threat actor ?

Re: Gaining access to anyones Arc browser without them even visiting a website

#57
Very small bounty, but I honestly believe this arc thing won’t last long…

Browsers are hard and my only choice has been chrome and will remain so for the long foreseeable future.

When I was younger I would enjoy switching to firefox, opera, etc..

But I always came back to chrome because it just worked and always performed when I needed.

Chrome/chromium is the safest browser.

People tend to fall for the shiny new thing and then realize it was just hype.

Please be very careful about what software you choose to perform most of your activities.

The same applies to these “new ai IDEs” that keep popping up every other say.

Re: Gaining access to anyones Arc browser without them even visiting a website

#58

Earlier quoted context omitted.

Yeah, you have to have some solid backbone not to sell this off to some malicious party for 20-50x that amount...

Am I too optimistic? I feel like most regular people I know wouldn’t sell this off. Most people are not antisocial criminals by nature, and also wouldn’t know how to contact a “state actor” even if they wanted to.

> also wouldn’t know how to contact a “state actor” even if they wanted to.

That's why brokerages like Zerodium exist - you can sell it to them, and they'll sell it onto state actors.

Re: Gaining access to anyones Arc browser without them even visiting a website

#59
post #7
post #5

There are a lot of major security vulnerabilities in the world that were made understandably, and can be forgiven if they're handled responsibly and fixed. This is not one of them. In my opinion, this shows a kind of reputation-ruining incompetency that would convince me to never use Arc ever again.

You’d think that a company shipping a browser would pay a little more attention to security rules. Also, shame on firebase for not making this a bit more idiot proof. And really? $2500? That’s it? You could’ve owned literally every user of Arc… The NSA would’ve paid a couple more zeros on that.

yes. I feel sad that now we have created an incentive where selling to the govt.'s is often much lucrative than telling to the vulnerable party (arc in this case)

(just imagine , this author was great for telling the company , this is also a cross platform exploit with very serious issues (I think arc is available on ios as well))

how many of such huge vulnerabilities exist but we just don't know about it , because the author hasn't disclosed it to the public or vulnerable party but rather nsa or some govt. agency

Re: Gaining access to anyones Arc browser without them even visiting a website

#60
post #57

Very small bounty, but I honestly believe this arc thing won’t last long… Browsers are hard and my only choice has been chrome and will remain so for the long foreseeable future. When I was younger I would enjoy switching to firefox, opera, etc.. But I always came back to chrome because it just worked and always performed when I needed. Chrome/chromium is the safest browser. People tend to fall for the shiny new thin…

…Firefox as an alternative to Chrome!? Am I really that old!?

I used Chrome for years and years, right from when it first came out. Since then, I switched back to Firefox, and have used it for years. It works perfectly fine.

Post reply on HN