Live data from Hacker News

Google tracks individual users per Chrome installation ID

github.com

641–642 of 642 posts

Re: Google tracks individual users per Chrome installation ID

#641
post #508

Earlier quoted context omitted.

Perhaps. Perhaps not. As a thought experiment: How long would it be safe to go without browser updates with a browser of complexity/capabilies of links, if 50% of people used it? With many people combing through it, would it become effectively unexploitable?

Probably not very long. Even with a small attack surface, if half the world uses it, the zero-days are valuable. Links is still vulnerable to * application-layer attacks (it is still an HTTP client and HTML parser, and the protocols themselves are complicated to implement soundly, even if the newest features aren't included) * protocol attacks (is links immune to buffer-overruns triggered by intentionally-malformed q…

> .. source code isn't open-source ..

Not sure what you mean, but then what is this: http://links.twibright.com/download/

> In this thought experiment, any successful attack has massive value so we can expect bad actors to be hammering on the system and finding most such exploits available on the application.

Precisely, and because of that, with 50% people using it, an orders of magnitude smaller attack surface and a mostly fixed feature set (you could at least have a LTS version), just how many vulnerabilities are there to find? How many man-years of work until there is nothing¹ left to find? Do you think that just any code has exploitable vulnerabilities, you just need to look hard enough? And with each fix, you can repeat that ad nauseam?

With the current browser development efforts, would we end up with a 100% formally verified browser, including its dependencies, networking, and maybe even relevant parts of a linux kernel?

Judging by the change log[2], links is currently developed by 1 developer and occasional contributions.

¹ Nothing of sufficient importance, frequency and lack of reasonable mitigations like not clicking on browser look-alikes, server-side CSRF protections, etc.

[2] http://links.twibright.com/download/ChangeLog

Re: Google tracks individual users per Chrome installation ID

#642

Earlier quoted context omitted.

Why do people still dredge up Google's historical "don't be evil"? It's not been applicable for half a decade now, and even in 2015 when it was officially removed from the last company documents, it was already a dead phrase. Google had already cornered the market back in 2012, when it surpassed every other browser, with an absolute majority dominance (>50% market share) achieved way back in 2015. Google has been in…

> Why do people still dredge up Google's historical "don't be evil"? Historical? It's not like it was 50 years ago.

In a world where broadband internet hasn't even been available for 2 decades, 5 years is a bloody long time.
Post reply on HN