3 ms·
I can confirm this! Back in 2017, I was 17 and found a flaw that affected the privacy of all browsers and required a web standards change. Google/Chromium (Andr
by rydre 6y ago
I can confirm this! Back in 2017, I was 17 and found a flaw that affected the privacy of all browsers and required a web standards change. Google/Chromium (Andrew R. Whalley) paid me a good bounty for that, but Apple (mac, ios, iphone, watch) didn't pay. I didn't expect Mozilla to pay obviously since they were non profit.
- 3pt14159 6y agoWhat was the exploit? I've been sitting on one that's essentially as old as the web but I figured it was pointless to try to alert browers about it because too much functionality rests on it.
- XCabbage 6y agoDon't tease us - what was your exploit? Just from the description, I'm happy taking a guess that this is going to involve somehow exploiting the browser cache (e.g. via timing how long it takes to request an image from another domain that may or may not have previously been cached) to determine whether the user has visited a page. That was first written up by academics decades ago, and has since been independently invented by several people (me included), but wasn't fixed as of whenever I last checked a couple of years ago. Is my wild guess right? :)
- 3pt14159 6y agoNo, though that is a good one.
- rydre 6y ago> What was the exploit? Just file a security issue on bugs.chromium.org with demo/instructions. If it's a good one, they'll pay good. I don't wanna give it out since it's publicly linked to my twitter and I've bad mouthed Apple here... (I don't publicly speak against them for obvious reasons)
- miles 6y ago> I didn't expect Mozilla to pay obviously since they were non profit. Despite being a nonprofit organization, Mozilla's annual revenue is around half a billion dollars[1] and they do offer a client bug bounty of up to $10,000[2]. [1] https://en.wikipedia.org/wiki/Mozilla_Corporation https://en.wikipedia.org/wiki/Mozilla_Corporation [2] https://www.mozilla.org/en-US/security/client-bug-bounty/ https://www.mozilla.org/en-US/security/client-bug-bounty/
- fishywang 6y agoWhen the December 2014 git vulnerability was disclosed to git maintainers (I can't find the CVE number now, but this was the github blog about it: https://github.blog/2014-12-18-vulnerability-announced-update-your-git-clients/ https://github.blog/2014-12-18-vulnerability-announced-updat..., and this was the hn discuss then: https://news.ycombinator.com/item?id=8769667 https://news.ycombinator.com/item?id=8769667, tl;dr is git only checked and protected all lower-case .git directory from overwritten by clone/checkouts, which will becomes tricky when it's used on case-insensitive fs), they contacted both Microsoft and Apple to make sure that they fixed all the corner cases of their case-insensitive file systems. Microsoft was very cooperative at the time, pulled in someone from NT kernel team to make sure that the fix covered all the corner cases; Apple, on the other hand, didn't response. Even after the patched version of git is released, Apple didn't do a hot release of Xcode tool (which is how they distribute git officially on Apple's systems). They only included the fix on their next scheduled beta release of Xcode.