Live data from Hacker News

Exploiting IndexedDB API information leaks in Safari 15

fingerprintjs.com

1–10 of 99 posts

Re: Exploiting IndexedDB API information leaks in Safari 15

#5
post #3

What the web needs is fewer APIs.

What we need are companies working on browsers that actually care about the web. Apple have demonstrated time and time again that they don't, because they favor native applications on iOS and macOS over anything web, so we end up with subpar browsers who ship with the OSes. In some cases (iOS), we even end up with a browser-monopoly where no other browser is even welcome.

Re: Exploiting IndexedDB API information leaks in Safari 15

#7
It's very interesting seeing exploits like this from this organization. On one hand their service fingerprints users and offers extended metadata like whether the user is in incognito via sketchy web apis.

On the other hand they report (and help close) some gnarly exploits like this via sketchy web apis.

What do you all make of this? It's hard to not see it as some weird "were not doing a bad thing" gaslighting (perhaps even internally to their team).

Re: Exploiting IndexedDB API information leaks in Safari 15

#8
The way they describe the behaviour when the dev tools are used with undeletable database copies being created, this just looks like the whole area is buggy. Which is of course not an excuse for this, but might also indicate that there could be even more attack surface there.

Re: Exploiting IndexedDB API information leaks in Safari 15

#9
post #3

What the web needs is fewer APIs.

What we need are companies working on browsers that actually care about the web. Apple have demonstrated time and time again that they don't, because they favor native applications on iOS and macOS over anything web, so we end up with subpar browsers who ship with the OSes. In some cases (iOS), we even end up with a browser-monopoly where no other browser is even welcome.

It's good that Apple doesn't care about the web, because that means that developers can't rely on the APIs that Apple refuses to implement, meaning that in the end the web ends up with fewer APIs that can be used in practical terms.

Re: Exploiting IndexedDB API information leaks in Safari 15

#10
post #4

> and in all browsers on iOS and iPadOS 15 Wow. I wonder what Brave thinks of this?

All browser vendors are very unhappy that Apple only allows their browser engine on iOS. For security and many other reasons.

Security in this case is broken by actually forcing the browser engine monopoly on ios.
Post reply on HN