14 ms·
I discovered a browser bug
- obl 8y agoIt's quite incredible how the web managed to get along with such a janky sandbox model. It's a very important thing that users trust their browser and won't hesitate a second to enter an unknown URL. They see "going to a webpage" as the equivalent to looking at a poster in the street, not eating candy provided by a random stranger. Eroding this trust would ruin it for everyone, even well behaved static websites without javascript. Maybe it's time to reconsider giving the same execution rights to gmail and unknown web pages ?
- pjc50 8y agoThe key thing is differentiating one set of pages from another set of pages - putting security boundaries into a hypertext system that was originally designed to allow mixing resources from different sources.
- simion314 8y agoI use a private window for banking/paypal , I don't trust the extensions or the other tabs so for this cases I get more security.
- felix_nagaand 8y agoThat hardly helps. For true security devote a device purely to banking. Preferably a diskless device running an updated live CD on a security oriented distro with no rewritable storage attached connecting out over a VPN through an equally dedicated firewalled router. Then you're just left to worry about your bioses getting infected off an unpatched or 0d exploit.
- r3bl 8y agoHe identified his threat model (other tabs + addons doing something shady) and made a security assessment based off of it. You're here bullshitting that he needs "true security" like he's dealing with APTs trying to access his bank account. He's not. He's concerned about other tabs + addons, and private browsing mode is a solution with the slightest friction for his threat model. Please, in the future, try making security assessments based on the actual threat model. EDIT: "threat" instead of "thread".
- seba_dos1 8y agoThis was pretty confusing to read until it came to my mind that "threat model" exists :)
- simion314 8y agoIf there were a big target on my back I would do that, but since I am running Linux, I am not a rich person or have an important job I assume that I will be attacked by regular malware and not skilled hackers.
- tzahola 8y agoSorry, but we need a Turing-complete language for ads and tracking. Preferably with JITting, and unfettered access to the GPU and other misc. peripherals like GPS, webcam, etc. In return you get free cat videos. You’re welcome.
- kevin_thibedeau 8y agoNo. The server just needs to send over an image and log the IP of the requestor for reconciliation at the end of the month.
- workinthehead 8y agoThe really ironic thing is trying to decide (before the internet was ever a thing, say 50 years ago) which of the 2 scenarios is more dystopian.
- datenwolf 8y ago…and with unfettered access to USB devices. WebUSB my ass.
- philipwhiuk 8y agoHow else are we going to tailor our adverts based on the music on your iPod Shuffle?
- WorkLifeBalance 8y agoDo you want to reinforce established monopolies? Because I can't think of a better way of doing that than having a technical difference between "trusted" and "untrusted" sites.
- yoz-y 8y agoWhat about differentiating applications and web sites? The line between the two is blurry, I know, but I would be happy if the document metaphor were divorced from the application one.
- dec0dedab0de 8y agoAbsolutely, there should be a different port for web pages than applications. Even if we started by disabling js on port 80
- krapp 8y agoBut what about applications that link to web pages or web pages that link to applications? What valid reason is there to have an "application" and any documentation or related HTML material from the same site on different ports? Or, as some have pointed out elsewhere when this has come up, to have "applications" and "documents" use completely different protocols, languages and native clients, when both are often used together?
- Retric 8y ago'Application' can be backward compatible with documents just fine. That does not mean a new category 'Document' that has reduced capability is useless. Banking websites for example don't need to be Applications and added protection for cross-site scripting etc. would be beneficial. Restrict things further and you default to supporting screen readers etc.
- krapp 8y agoWhat definitions of "application" and "document" are being used here? Banking websites are applications in terms of their functionality - they're certainly not documents. At least not the parts where I can access and modify my account.
- makmanalp 8y agoThe web didn't used to be able to do much, and we're using browsers that depended on tons of multi-decade old code, so I see how it happened. Agreed on the main point though.
- Endy 8y agoNo. The burden needs to be on the user to understand their own security. If we stopped taking the burden out of user's hands and tried to ensure that everyone on the Internet understood that anything they access becomes data on their computer/device, we'd have a smarter Internet. Frankly, I think if we made people understand that they have a responsibility to choose what they download, there might be more vocal group demanding the ability to do whatever they want with data transmitted to their computer, save for directly malicious acts against other users. The browser should be only two things: a client between a user and a server, passing information; and a parser which displays that information on the client-side. The moment a browser alone begins controlling what the user sees, or does not see, without the user having the ability to control it, we have a major problem. That becomes a security problem, a privacy problem, and a functionality problem. All data on the Internet should be treated the same by all browsers' client functions. The display may vary (e.g. the difference between Lynx and Firefox), but all data should be treated equally and the user should have both the authority and the responsibility for their own computer.
- lucideer 8y ago> The moment a browser alone begins controlling what the user sees, or does not see, without the user having the ability to control it, we have a major problem. What you're describing would be inordinately taxing for even the most experienced developer, not to mention the average internet user. The only way this could possibly be viable would be if we used gopher:// instead of http(s):// Currently, there are tools such as Privoxy Actions & Filters, which allow you to do 100% of what you're describing, Greasemonkey which allows you to do ~80% of what you describe, or uMatrix which allow you to do quite a lot. The prerequisites for using those range from full-blown programming skill (for the former 2) to managing a relatively advanced in-browser UI (for uMatrix), and having a lot of spare time. For every single webpage you visit on the web. This isn't viable for 99% of people.
- Endy 8y ago>The prerequisites for using [Privoxy & Greasemonkey] range from full-blown programming skill... Neither Privoxy nor GreaseMonkey require actual programming knowledge. I do not program, and I use Greasemonkey with some regularity - I use a combination of userscripts.org scripts and my own. They require a basic knowledge of specific scripting language implementations. Besides, Greasemonkey & uBlock/uMatrix both have a right-click menu entry that amounts to "hide anything like this". You're saying that 99% of the Internet's users can't handle being required to interact with the most basic front-end technologies which power the network they use every day, and which they willingly give up their private information to - thus having no ability to provide evidence for their trust or any expectation of their privacy. Frankly speaking, my mindset is that if it's not viable for them to understand it, it shouldn't be viable for them to use it. Uneducated users lead to nothing but trouble; and sure, I'll grant that I'm suggesting educating them the hard way, but I think the Web as a whole would be better off in the long run from smarter users and dumber clients. Heck, I think the whole world would be better off with smarter users and dumber clients/terminals/systems. Also, please, don't even begin to suggest that uneducated users should be directed to Gopher holes. You know as well as I do that if there's enough people going back to it, some yutz is gonna start trying to figure out how to add streaming this and scripted that to Gopher, and then Gopherspace will be ruined. And sure, on a technical level it would be a neat project to look at. But to reference Jurassic Park, a lot of very smart people have been so amazed at what they could do with the Web and the Internet as a whole, that they never really stopped to ask if they should do it.
- z3t4 8y agoSome browsers allow you to have many profiles. So you can use one profile for banking and e-mail, and another profile when browsing dubious sites.
- dannyw 8y agoThis was such a nasty bug for Edge. Visiting any page means I could now read your private Messenger messages, or your email. You could even automate resetting the password to an account, and then automatically exfiltrating the URL!
- Avamander 8y agosuperlogout.com v2.0
- acdha 8y agoThe Microsoft experience reminded me of the time when security@apple.com went to the building security office, who just quietly deleted bug reports. Poor processes amd communication is one of the worst classes of security problem.
- munin 8y agoMicrosoft used to have a group, Trustworthy Computing (TWC), that was where all the security expertise lived. TWC was destroyed in 2014. From the outside, it seemed like that was the point where the reporter/outside security engagement story stopped, because the people that held responsibility for it Microsoft wide were either fired or re-orged into a role where they didn't have broad authority any more. Now, you get stuff like this, where people on the "security" group (which is squirreled away in a totally different part of Microsoft) don't have visibility into the Edge bug tracker any more. Internally, Microsoft is organized a lot like the Federal government, only worse.
- pbhjpbhj 8y agoOne can see a rationale in not having a security group - every team should have security focus (eg by having expertise & champions within each group). You can't tack on security, you have to build it in.
- munin 8y agoI disagree - the motivations of the security group and the product group are different. If the security team is under the product team leadership, the security team is disincentivized to interrupt a product launch due to a security issue, because they're rewarded by shipping a product, not making it secure. Really, you should have both: you should have a security team that sits with the product team and works with them through the lifecycle of the product, and has continuity (i.e. it's the same security people with your product team through the life of the product, mostly), but that security team reports to different management and has their promotions, bonuses, etc. handled by a different leadership chain than the product team.
- 8y ago
- Promarged 8y ago> Oh, I guess the vulnerability needs an extremely tenuous name and logo right? Here goes I admire the extra touch here :)
- kawsper 8y agoI enjoyed the WhatsApp-looking box that explained the server/client conversation.
- _trampeltier 8y agoThe PDF was great too ;-)
- forgot-my-pw 8y agolol no
- jjcm 8y agoFor people downvoting forgot-my-pw, "lol no" was the complete content of the pdf.
- _bxg1 8y agoFor example, the request may have the following header: Range: bytes=50-100 …which is requesting bytes 50-100 (inclusive) of the resource. I haven't finished the article, but I've seen how this movie ends...
- usermac 8y agoFirst paragraph made me chuckle.
- ariehkovler 8y agoThat's a really well-explained and clearly presented writeup of the bug and how it can be exploited as a vulnerability.
- chrisfinazzo 8y ago> Lol no. That hurts, Jake :(
- jaffathecake 8y agobwhahahaha
- MatthewPhillips 8y agoI can echo his experience reporting browser bugs and provide my own reviews: Firefox - By far the best. Quick response, usually from engineers. If it's important the fix will be quick. Edge - No reply for months / years. When I've gotten replies back it's been to ask me to try with the current version. When I do and the bug still exists it goes back at the bottom of the queue it seems. Chrome - Somewhat of a mixed bag. Some times responses are quick, some times they are from engineers. But most often I get replies that convey the person I'm speaking too is a very green QA type. I've gotten replies that the test case I provided them doesn't reproduce the bug, because they had attempted loading it with the file:// protocol (of course hardly anything works with the file protocol). I'm not sure, do they expect me to include a web server for them? Safari - Only tried a couple of times, never gotten a whisper back. I would rate my experiences as: Firefox - A+ Chrome - C Edge - D Safari - F
- jaffathecake 8y agoYeah that Chrome experience doesn't sound great. Fwiw I tend to put my test cases on jsbin or Glitch, but yeah, a Chrome engineer should know to put the page on a basic web server. If anyone runs into problems like this, feel free to bug one of the Chrome dev rel folks, such as me.
- MatthewPhillips 8y agoLike I said, my impression is that often the people replying are not engineers. Here's one with that problem: https://bugs.chromium.org/p/chromium/issues/detail?id=674096#c8 https://bugs.chromium.org/p/chromium/issues/detail?id=674096...
- jaffathecake 8y agoYeah, that's not great, but the commenter in #12 is a senior engineer on devtools, so at least the right person saw it in the end.
- bjornstar 8y ago
- deleted 8y ago[deleted]
- shiftoutbox 8y ago=========== FUCK THE STUPID NAMES =========== I found a bug in the SecOps posts . It revolves around proving how clever you are at marketing your finds.
- zegl 8y agoMicrosoft claims to be developer friendly these days, but they are clearly not white-hat friendly.
- evfanknitram 8y agoMy entirely anecdotal experience is that they are white-hat friendly some time. My last experience was super good.
- zamalek 8y agoI think it depends on the team.
- notveryrational 8y agoThis is really nice research! Simple, effective, and brutal. This reminds me of the research that went into finding issues in the media plugin models. Essentially, once the security community discovered that Java and Flash, etc, plugins didn't follow the same rules as the browser at all times - it became a free bug hunting exercise until the media plugin model just died. I expect there are some "side channel" type ways to create high resolution timers in browsers which have removed built in support for them, for instance: WebAssembly? WebGL subroutines? Anyway, congratulations.
- frandroid 8y agoIs it Tuesday?
- con22 8y agohn bet big money on firefox/mozilla? all news for other web browser is bad except firefox. HN now is mozilla's Microphone
- dang 8y agoHN doesn't bet any money on anything. Please don't post unsubstantive comments here.
- andrewmcwatters 8y agoI, too, discovered a browser bug. Specifically with mutation observers in Safari (but not Chrome, or other WebKit-likes) in a particular DOM event scenario. Fully replicable. Not a word from any team at Apple, no acknowledgement of the bug, no acknowledgment of the issue. The situation is a common one wrt SPAs, routing, and changing a tree based on history state. I'm sure other frameworks have run into it. My brief experience documenting the issue solidified the position that I will never do it again.
- jlg23 8y agoThis just happened to be two anecdotes with 2 browser dev teams that should not be generalized. Everyone who has to deal with n-th layer tech support regularly (where n > 2) knows that even there it's hit or miss. Sometimes you file a bug report and get a "thanks, fixed!" an hour later. Sometimes you spend an hour to gather all the data upfront only to be painstakingly taken through the exact same data gathering process step by step. By email. Over days. On a "4h response" SLA (and they always just barely make it, not considering the value of the "response"). Randall Munroe has the best description: https://www.xkcd.com/806/ https://www.xkcd.com/806/
- klexin1 8y agoDo you get a cash reward for doing the right thing these days?
- 0x86DD_ 8y agocool, good for you
- dang 8y agoCould you please not post unsubstantive comments to Hacker News? that's not what this site is for. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- djhworld 8y agoI'm not familiar with the Web Audio APIs, was the Edge bug effectively interpreting the stream of bytes from the cross origin request as an 'audio stream', and then the OP just wrote a thing to convert it back so it could be converted into a string?
- masklinn 8y agoA stream of bytes is valid PCM (that's the point). The issue is that Edge would first allow a redirect to a cross-origin then would leak the entirety of the cross-origin data by allowing it through the Web Audio API — an API for low-level audio processing and synthesizing — ultimately allowing the attacker to retrieve the cross-origin resource.
- westmeal 8y agoNice one!
- hnruss 8y agoI've found a couple of browser bugs in different browsers (but nothing security-related). Nothing I've reported to browser teams has ever been fixed, even with simple standalone test cases. It's definitely easier just to write a workaround and call it good.
- amelius 8y agoAnother symptom of browser specs getting too complicated.
- jaffathecake 8y agoIn this case it was a symptom of them being too simple. The use of range requests wasn't specified.
- mito88 8y agotip of the iceberg?