3 ms·
I think the point of the original comment was that it's extremely feasible for attackers this sophisticated to have access to browser 0 day which would allow fs
by viknesh 4y ago
I think the point of the original comment was that it's extremely feasible for attackers this sophisticated to have access to browser 0 day which would allow fs access, "insecure" browser or not
- ActorNightly 4y agoZero day exploit =/= people automagically get infected. One would have to first craft the shellcode insertion into the exploit, which is not exactly trivial, then hope that enough users visit a particular website to get infection (which is a negative feedback loop as the more users visit a website, the more likely it is to get scanned and reported as containing malware), then drop a crafted executable to presumably steal something that is worth money, which is a whole separate problem. Possible? Definitely. So is you getting held up, your car stolen, and chopped up for parts, with no available recourse. Both are rather unlikely.