Live data from Hacker News

Gaining access to anyones Arc browser without them even visiting a website

kibty.town

521–530 of 538 posts

Re: Gaining access to anyones Arc browser without them even visiting a website

#521
post #432

Earlier quoted context omitted.

The only feature Zen browser missing is tab folders, once they implement it I really don't have a reason to have Arc browser anymore.

Hell despite missing tab groups, Zen browser is the only browser that finally had a "good enough" vertical tabs implementation, which allowed me to finally drop Edge as my main browser.

What do you not like about Firefox's Tree Style Tabs? I might be open to an alternative.

Re: Gaining access to anyones Arc browser without them even visiting a website

#522

Earlier quoted context omitted.

Hell despite missing tab groups, Zen browser is the only browser that finally had a "good enough" vertical tabs implementation, which allowed me to finally drop Edge as my main browser.

What do you not like about Firefox's Tree Style Tabs? I might be open to an alternative.

I Cant't hide the tab bar without some userProfile.css hacks, while in Zen it has first class support.

It's more a matter of saving precious vertical space.

Re: Gaining access to anyones Arc browser without them even visiting a website

#523

Earlier quoted context omitted.

What do you not like about Firefox's Tree Style Tabs? I might be open to an alternative.

I Cant't hide the tab bar without some userProfile.css hacks, while in Zen it has first class support. It's more a matter of saving precious vertical space.

I see. Yes, I already hid the stock tab bar years ago and forgot about it.

Re: Gaining access to anyones Arc browser without them even visiting a website

#524
post #378

Earlier quoted context omitted.

Will you be increasing the bug bounty payout? $2,000 is a tiny fraction of what this bug is worth, I hope you will pay the discoverer a proper bounty. You've been handed a golden opportunity to set the right course.

Any new vulnerability will be sold to the highest bidder and/or exploited instead of being reported for the bug bounty because of this.

I know a lot of different people who do independent security research and have submitted vulns to bounty programs. Not a single one would even come close to saying "well, the bounty is low so I'll sell this on the black market."

Low bounties might mean that somebody doesn't bother to look at a product or doesn't bother to disclose beyond firing off an email or maybe even just publishes details on their blog on their own.

Bounties aren't really meant to compete with black markets. This is true even for the major tech companies that have large bounties.

Re: Gaining access to anyones Arc browser without them even visiting a website

#525

Earlier quoted context omitted.

> bold warning text in the Firebase docs. Unfortunately, we currently have an industry where highly paid "engineers" unironically believe that their job can be done by reading/watching random tutorials, googling for StackOverflow answers, and pasting code from gists. Attentively reading documentation or developing a mental model of how your tools work so that you know how they are built to be handled does not make it…

Reading/watching random tutorials and asking basic questions on SO __instead of reading the official docs__ is a trend I've observed for the last 10 years. Even for stuff pretty well documented like Python, Postgres, React, etc.

Google is really good at surfacing random blogs and SO questions instead of the official docs.

Re: Gaining access to anyones Arc browser without them even visiting a website

#526

It would be nice if I could download a version of the Arc browser with the cloud bits removed. I use it because of the UI/UX and pretty much ignore everything else. Really if there was a browser that let me keep organized spaces in a left panel plus create split screen views then it would immediately convince me to switch from Arc.

https://zen-browser.app/

I know about Zen and Floorp. For my day to day browsing Arc has:

# Split screen tabs

Zen and Floorp both have this but the UX for both is really clunky. Surely they'll improve but Arc felt like second nature.

# Little Arcs

As far as I know, neither Zen or Floorp have this feature and if they do then the UX is not as obvious as Arc. The UX around Little Arcs is almost perfect. If I click on a link, it opens as a modal that I can expand to its own tab if I need or dismiss by just clicking away. The same things happens in other apps so I don't lose context just because I wanted to look at a link quick. If I do want to bring that tab into a space then it's 1-2 clicks away. My only gripe with this is that the Little Arcs that are created from clicking links in other apps don't auto dismiss if you change focus but this might just be a setting I don't have configured.

# Inset meetings/videos

AFAIK neither has this feature either. Having videos that are playing just seamlessly pop-up picture-in-picture when navigating away from the video tab is useful enough but the meeting feature is key for me because my company uses Google Meet. I can navigate away from meetings to look-up info/check Slack/etc without losing focus on the meeting itself and getting back to the meeting tab or unmuting myself is 1 click away.

Sure all of these things could probably be accomplished by browser extensions but I think the UI/UX within Arc is pretty tough to compete with.

Re: Gaining access to anyones Arc browser without them even visiting a website

#527
post #25

Nice article, but this is hard to read without proper capitalization. My brain uses capitals to scan beginning and ending of text.

Young people (like me) use lowercaps like that all the time. Around 50% of the young people I know purposefully turn off auto-caps on their phone. Why? I really couldn't say. I think we just like the feel of it. The only reason I type with proper capitalization on HN and my blog is because I know older people read it.

Using uppercase is for writing (more formal).

using lowercase is for chat (less formal)

Re: Gaining access to anyones Arc browser without them even visiting a website

#528
post #432

Earlier quoted context omitted.

The only feature Zen browser missing is tab folders, once they implement it I really don't have a reason to have Arc browser anymore.

Hell despite missing tab groups, Zen browser is the only browser that finally had a "good enough" vertical tabs implementation, which allowed me to finally drop Edge as my main browser.

I'd be curious for your comparison to Waterfox, which added vertical tab integration a while ago.

Re: Gaining access to anyones Arc browser without them even visiting a website

#529
post #213

I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response…

So when there are near weekly reports of websites being compromised due to horrid Firebase configuration, did absolutely no one on your teams raise a red flag? Is there some super low-pri ticket that says "actually make sure we use ACLs on Firebase"?

Re: Gaining access to anyones Arc browser without them even visiting a website

#530

Earlier quoted context omitted.

At the end of the day this is an amateur mistake God I wish. More than one of my coworkers has made this exact mistake with our (thankfully internal) front-end apps.

If it's internal, did they really need to have auth?

The term of art is "Friendly fraud".

A significant amount of product stolen from retail stores actually goes out the back door.

Post reply on HN