3 ms·
The proof-of-concept is really just painting 10,000 rectangles the size of the window. It's that stupid. It has nothing to do with shaders or anything fancy. As
by bjacob 15y ago
The proof-of-concept is really just painting 10,000 rectangles the size of the window. It's that stupid. It has nothing to do with shaders or anything fancy. As long as you allow painting many large triangles as a single GPU command, you have the vulnerability. If you don't allow that, then you're not fast.
Everybody has known forever about that vulnerability in 3D APIs. So there was not much of a point using a private reporting mechanism. However, Microsoft took this well-known universal vulnerability and presented it as something specific to WebGL. There was no point in replying privately to that.
- tptacek 15y agoSure. Plenty of people also deliberately don't use "official" channels. Look at the Metasploit people, who I respect a lot. I'm not saying it has to be done that way. I'm saying that the guy who says "it got posted to the public bug tracker because there's no other place for an individual to send security flaws" is wrong. Doesn't know what he's talking about. There's also nothing wrong with that. Why should everyone need to know the ins and outs of vulnerability research? But probably he should dial back the stridency.