Live data from Hacker News

Google Chrome Hacked?

vupen.com

71–80 of 223 posts

Re: Google Chrome Hacked?

#71
post #7
post #4

Earlier quoted context omitted.

I'm not too sure that's the business VUPEN is in. Sure, it doesn't hurt them much to share their latest Safari exploit given how slow Apple is on the fix, but with Google their window has the potential to be very short.

Citation needed for such a serious accusation. They claim to be ethical. From their about page: "VUPEN follows a private responsible disclosure policy and reports all discovered vulnerabilities to the affected vendor under contract with VUPEN, and works with them to create a timetable pursuant to which the vulnerability information may be publicly disclosed."

Just relying off the quote given: "VUPEN follows a private responsible disclosure policy and reports all discovered vulnerabilities to the affected vendor under contract with VUPEN…"

It makes it sound like if they crack your software, you only get disclosure if you are paying them money. However, I could be wrong.

Re: Google Chrome Hacked?

#72
post #64
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

Funny thing is Google does actually pay for reported security bugs. Up to $3133.70: http://dev.chromium.org/Home/chromium-security/vulnerability...

I'm pretty sure VUPEN asks for an order of magnitude or two more.

Hell, they don't even provide prices on their website, you can request quotes.

Re: Google Chrome Hacked?

#73
post #57

Earlier quoted context omitted.

Looking at VUPEN services it sounds like HBGary twin : http://www.vupen.com/english/services/ "offensive security", yep. The guys are dirty like the Gary. Why a racket and government always means a happy marriage?

One difference is that it appears that these VUPEN folks are not entirely incompetent.

people were telling the same about HBGary before they started to tell the opposite. Though my post isn't about technical brilliance. Being in bed with Power and relaxing one's moral standards to better serve it always leads the same way....

Re: Google Chrome Hacked?

#75
post #44
post #31

Earlier quoted context omitted.

The net result in this case is the government owning a zero-day root exploit for every Chrome/Win citizen’s computer. It’s worse than zero-day because we have no reason to expect a patch, so the window of attack will stay open.

Out of speculation, would this tie in at all to an article I saw on HN a while back about the Government hiring 3rd parties to hack Google for some reason?

[deleted]

Re: Google Chrome Hacked?

#77
post #56

Earlier quoted context omitted.

Do policemen work for free? It's a dirty job, I 'd want to be paid

That's a poor example. Policeman get paid to protect everyone; police protection is not (usually) a subscription service.

Do police protect inner city poverty-stricken people victimized by gangs?

It's pretty easy to argue that police only protect those who pay them.

Re: Google Chrome Hacked?

#78

Earlier quoted context omitted.

Why not? This is highly specialized research that not even well-paid Google employees were able to do. This is actually quite common in recent years for bug hunters and exploit developers. I can think of a dozen or so companies that do the same thing. Immunity is another example. Trying to use a moral argument to get out of compensating someone when you have the resources to do so is shameful. Sorry, but this stuff i…

Publicly announcing a security vulnerability, claiming that you're sharing it with other clients with the intent of using it for "weaponized ... offensive missions", and then demanding a fee to gain the information to protect against said weaponization, sounds an awful lot like extortion. In the offline world, I don't think you can legally run a business with a strategy of: discover a problem in the security at one o…

This is probably why they keep repeating that their customer is the government. You could probably sell Exxon's security vulnerabilities to the government and demand $N dollars from them to show them how to fix the problem. It's advertising the vulnerability with posts like this that seems most questionable (similar to extortion) to me.

Re: Google Chrome Hacked?

#79
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

why do they announce it at all then?

Re: Google Chrome Hacked?

#80

Earlier quoted context omitted.

Why not? This is highly specialized research that not even well-paid Google employees were able to do. This is actually quite common in recent years for bug hunters and exploit developers. I can think of a dozen or so companies that do the same thing. Immunity is another example. Trying to use a moral argument to get out of compensating someone when you have the resources to do so is shameful. Sorry, but this stuff i…

Publicly announcing a security vulnerability, claiming that you're sharing it with other clients with the intent of using it for "weaponized ... offensive missions", and then demanding a fee to gain the information to protect against said weaponization, sounds an awful lot like extortion. In the offline world, I don't think you can legally run a business with a strategy of: discover a problem in the security at one o…

I don't see why not. As long as you don't actually break into Exxon and commit I crime.

The real reason your scenario is unlikely is just that Exxon practically owns the government, so they would change the laws or something to fuck you over.

But I mean what if you discovered a security vulnerability at McDonalds or something, a way to pick their locks. Why are you morally obligated to disclose it without compensation?

On which moral principle are you condemning them?

Post reply on HN