Live data from Hacker News

Gaining access to anyones Arc browser without them even visiting a website

kibty.town

531–538 of 538 posts

Re: Gaining access to anyones Arc browser without them even visiting a website

#531
post #250

Earlier quoted context omitted.

What is also strange that I only found out about account after download. Like it was standard thing for the browser. (Sure there are optional accounts in others but login-walled browser?)

Windows is practically login-walled[0] at this point so I imagine people are slowly getting to expect it. [0] witness the magic incantations needed https://www.tomshardware.com/how-to/install-windows-11-witho...

Hilariously (in the absurd way), this affects my girlfriend, who prefers and uses the Microsoft account feature AND onedrive exactly how Microsoft would hope she would, and STILL gets fucked by their stupidity.

Her laptop has a mediatek wifi card that doesn't have built in Windows drivers. Re-installing Windows requires you play the above game, so you can get into Windows, install the driver, and then immediately log into Microsoft.com.

Re: Gaining access to anyones Arc browser without them even visiting a website

#532
post #52

According to this article, Arc requires an account and sends Google's Firebase the hostname of every page you visit along with your user ID. Does this make Arc the least private web browser currently being used?

When I downloaded it a few months ago and it required an account to even use it, my gut feeling was that I should just stick with Firefox.

Re: Gaining access to anyones Arc browser without them even visiting a website

#533
post #501
post #445

Earlier quoted context omitted.

Didn't they already have these rules in place? And the vulnerability was when the owner was updating the resource to have a new owner?

Unclear if they had these rules in place already but I'm curious... If the rule permits writing when the userid matches, presumably there is nothing stopping the write operation to change the userid value, to your point. Which then leads me to the next question, what is the practical way to write rules against that operation?

In my limited experience, I've seen it handled by adding the user's ID in the path of any resource that belongs to a particular user, so that the user ID from the resource path can be compared with the authenticated user ID as a security rule condition.

But as expected, you can validate the incoming data as well https://firebase.google.com/docs/firestore/security/rules-co... but this would need to be done for any attribute that might lead to a change of ownership.

Re: Gaining access to anyones Arc browser without them even visiting a website

#534

Earlier quoted context omitted.

The sibling comment to this by sieabahlpark is already dead but to respond in case they get a chance to read the thread again anways: The engineers already closed the hole, the blog post was already published, more work was (/is still?) going to be done to make a new site to hide them in. I wasn't asking for them to move engineers off patching to blog posting, I was asking for the already created blog posting to be m…

Every comment I make is immediately dead upon me posting, it's been that way for about a year. I believe transparency is necessary, but also have been in the situation where the alarms are going off and you slip on making sure disclosures are optimally distributed. Generally I'm just concerned that it's documented at all. Now if they maintained not revealing the security issue over the following week I'd agree. Shoul…

(I've vouched for this comment, maybe that helps.)

Re: Gaining access to anyones Arc browser without them even visiting a website

#535
post #122

Earlier quoted context omitted.

This convinced me to never use Arc again. I created a small guide to migrate from it to an open-source alternative: https://gist.github.com/clouedoc/4acc8355782f394152d8ce19cea... TL;DR: it's not possible to export data from Arc, but it's possible to copy-paste the folder to a Chrome profile, and Firefox and other browsers will detect&import it.

Unfortunately, Zen Browser simply isn't an alternative. If you like Arc, then Zen's UI for tabs and splitting views isn't really anywhere close to satisfying the same needs.

I was literally using Arc because of the ability to hide most of the userchrome.

Every time I open split views or tabs I curse. I've said this in the past but layering view multiplexors has to be the most stupid modern "super-user" trap. You have the ability to open multiple browser windows and composite them side by side, use it.

Does anyone know of any other browsers that are chromium based and have very little features aside the ability to hide most of the UI?

Re: Gaining access to anyones Arc browser without them even visiting a website

#536
post #213

I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response…

I would like to respectfully provide the suggestion of allowing for the use of Arc without being signed into an account. Although I understand browser/device sync is part of most modern browsers, and the value it provides, normally it is a choice to use this feature. Arc still provides a lot of attractive features, even without browser sync on.

Re: Gaining access to anyones Arc browser without them even visiting a website

#537
post #216

How could one sell a vulnerability like this to let's say Mossad? Write them an email?

https://www.mossad.gov.il/contact-us/en Interestingly enough, contains a field for entering your Father's name (but not your mother's).

I assume this is similar to Russia where people get their father's name assigned as middle name

Re: Gaining access to anyones Arc browser without them even visiting a website

#538

Earlier quoted context omitted.

Can you explain how you could get someone else's user id? I get that this is still a big vulnerability but am trying to understand how that would happen.

It says in the article. If you share one of your snippets, or make/accept a friend request, that all uses the same id

ah gotcha thanks
Post reply on HN