Live data from Hacker News

Escaping the Chrome Sandbox Through DevTools

ading.dev

81–85 of 85 posts

Re: Escaping the Chrome Sandbox Through DevTools

#82

Earlier quoted context omitted.

Run calc.exe actually means steal money of everybody in their entire organization or blackmail the entire organization by encypting all the data they need to function.

If compromising a single machine of a user already compromises your entire orgs IT, you’re doing something wrong, right? Shouldn’t a normal user lack privileges to do this much damage to the network?

Everybody is doing something wrong.

Re: Escaping the Chrome Sandbox Through DevTools

#83
post #66

Earlier quoted context omitted.

> Is it bad for Chrome to have vulnerabilities? Yes, obviously it is. Is it bad for others/the public? Probably, but not as bad as it is for Chrome. > because it really is only Chrome here holding the power I'm not sure this is true. Apple pretty much forces usage of their browser engine on iOS, and heavily try to get people to use Safari on macOS. Windows push Edge pretty hard on their OS, and their browser engine i…

> and heavily try to get people to use Safari on macOS how so? on any new macOS install, I use Safari to download Firefox. After that, I never think about Safari until I'm trying to use its DevTools to look at iDevices. I never get a nag screen about Safari. I have never had default browser changed after any updates. so where exactly is this heavy handed attempt at forcing Safari down anyone's throat?

I'm not on a macOS machine right now, so can't show you any specific examples, but scattered links/actions across Apple applications still open Safari from time to time (I think Xcode was especially gnarly for a long time), as it seems at one point Apple hardwired the links/actions to open Safari rather than the user set browser. Search for `site:discussions.apple.com wrong browser` in your favorite search engine and you'll get some actual examples.

Re: Escaping the Chrome Sandbox Through DevTools

#84
post #83

Earlier quoted context omitted.

> and heavily try to get people to use Safari on macOS how so? on any new macOS install, I use Safari to download Firefox. After that, I never think about Safari until I'm trying to use its DevTools to look at iDevices. I never get a nag screen about Safari. I have never had default browser changed after any updates. so where exactly is this heavy handed attempt at forcing Safari down anyone's throat?

I'm not on a macOS machine right now, so can't show you any specific examples, but scattered links/actions across Apple applications still open Safari from time to time (I think Xcode was especially gnarly for a long time), as it seems at one point Apple hardwired the links/actions to open Safari rather than the user set browser. Search for `site:discussions.apple.com wrong browser` in your favorite search engine and…

Back when I used to run Chrome, I noticed one case that would do this (it was buried in Spotlight), but it didn't seem intentional (especially because web search results in Spotlight always respected the default browser setting, and showed the correct browser icon as well). I use Safari now though, so I won't be finding any more cases like that anytime soon.

Re: Escaping the Chrome Sandbox Through DevTools

#85
post #61

Earlier quoted context omitted.

If they make excuses, sit on it, or dont pay out, release those bugs into the public domain, thats how this system works!

While I would love to do that, I still enjoy making a living in security.

Im genuinely interested here. If you made some security bugs public due to the company not cooperating properly, would that damage your reputation in the community to the point it would jeopardise your career opportunities?

From the outside looking in, it seems that the community would applaud that behavoir, but I am not familier.

Post reply on HN