Live data from Hacker News

Exploiting IndexedDB API information leaks in Safari 15

fingerprintjs.com

71–80 of 99 posts

Re: Exploiting IndexedDB API information leaks in Safari 15

#71
post #58
post #37

Earlier quoted context omitted.

Edge is just Chromium now https://finance.yahoo.com/news/microsoft-edge-chrome-chromiu...

Chromium is "just" a logical, security first base OSS project, that (theoretically) any org can adopt and strap additional modules onto.

Edge adopted chromium because microsoft could not compete with their monopoly power to enforce web standards as “however it is implemented in chrome”. If chrome ships a feature, there 80-90% market share means that every other chromium browser has to ship it or they’re “broken” and people switch to chrome.

if the other chromium wrappers have a seat at the table, that isn’t the table that makes the decisions.

Re: Exploiting IndexedDB API information leaks in Safari 15

#72
post #64
post #29

Earlier quoted context omitted.

Well, only if the alternatives are, overall, more secure and private than Safari. I tend to doubt that's true, mainly because, by far, the most likely alternative is Chrome, and Chrome is specifically designed to leak its users' personal information to Google's customers (the ones that generate the bulk of their revenue, that is).

Security ≠ privacy. This is well-tread, mistaken path. Chromium > all, for security. But for privacy, sacrificed by all of them out of the box (yes, Firefox is a noisy SOB too, no I won't dig up the articles people have written on the traffic captured for you). Your settings are very, very important to your browser privacy, regardless of which.

Well, don’t get caught up in unimportant distinctions. Security vs. privacy depends on the relationships between the subject of data, the holder of data and those seeking to use the data. Consider the relationships between browser end users, Google, and the parties who provide Google’s revenue. If we want to distinguish privacy from security here, we have to argue about how to characterize these relationships and hash through the details of the flow of data. It’s pointless and unhelpful.

Re: Exploiting IndexedDB API information leaks in Safari 15

#73

Earlier quoted context omitted.

What we need are companies working on browsers that actually care about the web. Apple have demonstrated time and time again that they don't, because they favor native applications on iOS and macOS over anything web, so we end up with subpar browsers who ship with the OSes. In some cases (iOS), we even end up with a browser-monopoly where no other browser is even welcome.

iOS sure but native mac applications are dead , D-E-A-D, muerto, morte, morto etc on macOS and have been almost entirely ejected in favor of web based SAAS and electron apps over the past 4 years. I genuinely can’t name a native application released for macOS built with AppKit or SwiftUI or whatever that didn’t come from Apple.

Off the top of my head: Nova (Panic's new code editor) and Craft are both pretty new such apps. Acorn and Pixelmator Pro are both image editors that aren't brand new, but aren't quarter-century old incumbents by any stretch. There's the whole Affinity suite of Adobe competitors. And while BBEdit is a quarter-century old incumbent, of sorts, it's pretty far from being in maintenance mode -- and it certainly has company.

It's certainly true that the center of gravity is tilting toward web apps, but not every kind of app makes a good web app, at least yet.

Re: Exploiting IndexedDB API information leaks in Safari 15

#74

Is it usual to disclose (what appears to me to be) a vulnerability with massive potential for exploitation towards disastrous ends, before the developers of the software have shipped a fix? I guess I'm curious as to what the norms are around disclosure of such discovered vulnerabilities are in general.

The bug was filed in November. More than enough time for a fix. Eventually you have to go public to force Apple’s hand.

Re: Exploiting IndexedDB API information leaks in Safari 15

#75
post #29

Earlier quoted context omitted.

Well, only if the alternatives are, overall, more secure and private than Safari. I tend to doubt that's true, mainly because, by far, the most likely alternative is Chrome, and Chrome is specifically designed to leak its users' personal information to Google's customers (the ones that generate the bulk of their revenue, that is).

The problem is when a zero day is found on safari engine there's no alternative one can use till it gets patched.

Do you think there is a browser available with no zero-days on any platform?

Re: Exploiting IndexedDB API information leaks in Safari 15

#77

Earlier quoted context omitted.

Adobe Creative Cloud, Microsoft Office, Sketch, Paw, TablePlus Just named five I use daily...

TablePlus looks cool! Also the only one started in the last decade. Inertia is the most powerful force in the universe, and gravity is up there as well. Adobe & Microsoft dynastyware dating back to 1990, and two also rans devoured by the web (Figma/Postman). And TablePlus which genuinely looks cool and gives just enough hope to mourn again.

I think Paw and Sketch are better than Postman and Figma, respectively. But I see your point.

You're basically right, but at least we have much more cross-compatibility now. Not something we could say about Macs of yore. Pros and cons.

Re: Exploiting IndexedDB API information leaks in Safari 15

#78
post #48
post #46

Earlier quoted context omitted.

Why does (near) silence equate to incompetence?

My perception of Apple’s (software) engineering capabilities comes from being their customer and using their products daily. This might be different if I had some perception of what was happening internally or how problems are approached. But from what I see nobody at Apple cares. So the silence contributes to the perception of incompetence by not counter-acting it.

> But from what I see nobody at Apple cares. So the silence contributes to the perception of incompetence by not counter-acting it.

There isn’t silence though. The world doesn’t begin and end at Hacker News. Head over to Twitter, for instance, and you’ll see plenty of Apple developers talking about their work. Or join the WebKit mailing lists or Slack. Or join the Swift forums.

Re: Exploiting IndexedDB API information leaks in Safari 15

#79
post #72
post #64

Earlier quoted context omitted.

Security ≠ privacy. This is well-tread, mistaken path. Chromium > all, for security. But for privacy, sacrificed by all of them out of the box (yes, Firefox is a noisy SOB too, no I won't dig up the articles people have written on the traffic captured for you). Your settings are very, very important to your browser privacy, regardless of which.

Well, don’t get caught up in unimportant distinctions. Security vs. privacy depends on the relationships between the subject of data, the holder of data and those seeking to use the data. Consider the relationships between browser end users, Google, and the parties who provide Google’s revenue. If we want to distinguish privacy from security here, we have to argue about how to characterize these relationships and has…

I would trust Chrome to flash GrapheneOS to my Pixel — that's security.

I do not trust it not to report back that I use GrapheneOS, or which internet communities I visit, back to Google for use in who knows what data correlation research — that's privacy.

Re: Exploiting IndexedDB API information leaks in Safari 15

#80

How is this not a P1 thing in the iOS/iPadOS/macOS/security teams at Apple? Seriously? Bare minimum, why didn't they let people know about this? We know the whole "we care about privacy" thing is marketing fluff now but holy F this is just unacceptable. And this kind of an issue is exactly why Apple needs to stop screwing around and do the following things ASAP: 1. Decouple Safari from the OS so that it can be update…

Number 1 is number one on my list. I am literally (right now) just installed an old MBP from an empty disk. Literally could not use Safari to download another browser because it’s “updating.” So I’m literally watching a 10 minute progress bar just to download a browser.

curl is pre-installed :)
Post reply on HN