4 ms·
That's a very good point. Sorry if I was unclear earlier -- I don't think we should give up on trying to find/fix these bugs. I was thinking more along the line
by randomwalker 16y ago
That's a very good point. Sorry if I was unclear earlier -- I don't think we should give up on trying to find/fix these bugs. I was thinking more along the lines of (1) improving user education (2) improving private browsing mode to deal with these attacks even at the expense of compromising some functionality. Mozilla has already been thinking along these lines: https://wiki.mozilla.org/Security/Anonymous_Browsing#Anonymous_Browsing_Mode https://wiki.mozilla.org/Security/Anonymous_Browsing#Anonymo...
As for whether it will become the new normal, that remains to be seen, but I think there are a couple of differences compared to regular privilege-escalation exploits: (1) everyone agrees that taking over your computer is malicious, whereas the perception of identity leaks is malleable (2) identity leaks are harder to deal with: even after the relevant bug is fixed, the attacker still has the mapping of your identity to your IP/browser fingerprint.
But thanks for the comparison and I will keep an open mind about this :-)