4 ms·
From the email thread: > I happened to notice that the /api/showSB endpoint will spawn an ancient build of Chromium (version 41) with --disable-sandbox. To add
by Chris911 11y ago
From the email thread:
> I happened to notice that the /api/showSB endpoint will spawn an ancient build of Chromium (version 41) with --disable-sandbox. To add insult to injury, they append "(Secure Browser)" to the UserAgent.
> I sent a mail saying "That is the most ridiculous thing I've ever seen".
This is indeed unbelievably ridiculous.
- cenal 11y agoMore ridiculous than that time Microsoft shipped an operating system with no firewall enabled by default and a feature designed to allow for remote commands to be executed? I think the Blaster Worm and other variants that took advantage of that excellent decision were far worse. https://en.wikipedia.org/wiki/Blaster_(computer_worm) https://en.wikipedia.org/wiki/Blaster_(computer_worm) https://books.google.com/books?id=_TgEAAAAMBAJ&pg=PA60&lpg=PA60&dq=steve+gibson+windows+xp+firewall&source=bl&ots=-INXwLArT3&sig=rAt1aZ9PrKdl4ZeJhrfi1KqVMEU&hl=en&sa=X&ved=0ahUKEwiKvNrr06LKAhWBSCYKHS6sBmEQ6AEIPzAF#v=onepage&q=steve%20gibson%20windows%20xp%20firewall&f=false https://books.google.com/books?id=_TgEAAAAMBAJ&pg=PA60&lpg=P...
- WatchDog 11y agoOr that time the Trojans let the greeks send in a horse full of soldiers.
- tptacek 11y agoYou can make a lot of things sounds comically insecure, very much including virtually all open source software, if you use 2003 as the benchmark.
- rsync 11y agoNot really. A FreeBSD 4.x system with a (modestly) stripped down kernel and running sshd was not only rock solid in 2003, but would probably be rock solid today. Just to pick one random example.
- hueving 11y agoDoesn't sound like a random example to me. It sounds like one of the most secure examples you could think of.
- 9935c101ab17a66 11y agoHahaha, glad someone else noticed.
- tptacek 11y agoNo, FreeBSD 4.x from 2003 would not be "rock solid" today; it had kernel RCEs. Not to mention the ones in OpenSSH. Nothing was secure in 2003.
- rsync 11y agoHmm... I would have to look to be sure, but having lived through it all, I seem to remember that all of the 2-3 OpenSSH security advisories that came out for FreeBSD in the last 10-12 years were either: a) incredibly far fetched theoretical attacks that didn't work in almost 99% of live deployments b) local privilege escalation that required a real unix login on the system to exploit I think if you had left a FreeBSD 4.x system running on the public Internet all of these years you would have been untouched.
- tptacek 11y agoI've been doing FreeBSD security in particular since 1996, when I got the commit bit for discovering the crt0 environment overflow flaw, and all I can say is that this just isn't true. You don't even have to be a security specialist to know that there's something wrong with your argument, because you're talking about exactly the time period where OpenBSD --- which is more secure than FreeBSD --- comically started having to change its tagline from "no remote vulnerabilities in the default install" to "just one vulnerability in the default install" to "only two remote vulnerabilities in the default install for a heck of a long time". Even OpenBSD concedes it wasn't secure in 2003!
- euyyn 11y agoYeah, it's more ridiculous because of they specifically naming it the "secure browser" API.
- ygjb 11y agoYour example is ridiculous; in this case Trend Micro took a a year old product missing several patches, turned off the single most important exploit mitigation in a modern browser, and slapped a sticker that said "Secure Browser" on it and shipped it. Versus you know, shipping an OS that doesn't contain features, more than a decade ago.