28 ms·
I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypotheti
by ha470 2y ago
I’m Hursh, cofounder and CTO of The Browser Company (the company that makes Arc). Even though no users were affected and we patched it right away, the hypothetical depth of this vulnerability is unacceptable. We’ve written up some technical details and how we’ll improve in the future (including moving off Firebase and setting up a proper bug bounty program) here: https://arc.net/blog/CVE-2024-45489-incident-response https://arc.net/blog/CVE-2024-45489-incident-response.
I'm really sorry about this, both the vuln itself and the delayed comms around it, and really appreciate all the feedback here – everything from disappointment to outrage to encouragement. It holds us accountable to do better, and makes sure we prioritize this moving forward. Thank you so much.
- ycombinatrix 2y agongl this is pretty pathetic. the massive security hole is one thing but you're just gonna gloss over violating your own privacy policy?
- markandrewj 2y agoI would like to respectfully provide the suggestion of allowing for the use of Arc without being signed into an account. Although I understand browser/device sync is part of most modern browsers, and the value it provides, normally it is a choice to use this feature. Arc still provides a lot of attractive features, even without browser sync on.
- rachofsunshine 2y agoComments further down are concerned that on each page load, you're sending both the URL and a(n identifiable?) user ID to TBC. You may want to comment on that, since I think it's reasonable to say that those of us using not-Chrome (I don't use Arc personally, but I'm definitely in the 1% of browser users) are likely to also be the sort of person concerned with privacy. Vulnerabilities happen, but sending browsing data seems like a deliberate design choice.
- mthoms 2y agoI think that is addressed in the post. Apparently the URL was only sent under certain conditions and has since been addressed: >We’ve fixed the issues with leaking your current website on navigation while you had the Boost editor open. We don’t log these requests anywhere, and if you didn’t have the Boosts editor open these requests were not made. Regardless this is against our privacy policy and should have never been in the product to begin with. Given the context (boosts need to know the URL they apply to after all) this indeed was a "deliberate design choice" but not in the manner you appear to be suggesting. It's still very worrisome, I agree.
- tyho 2y agoThere isn't really anything you can do to convince me that your team has the expertise to maintain a browser after this. It doesn't matter that you have fixed it, your team is clearly not capable of writing a secure browser, now or ever. I think this should be a resigning matter for the CTO.
- avarun 2y agoAnd what, you’re going to find them a new CTO? What kind of magical world do you live in where problems are solved by leaders resigning, instead of stepping up and taking accountability?
- smt88 2y agoTaking accountability can and should include admitting you're the wrong person for the job and resigning.
- radicaldreamer 2y agoCTO is simply a title, the proper response here would be to hire a head of security and build it into the culture from the ground up. I'm looking at all of the Arc Max features which probably need to be architected correctly to be secure/privacy-preserving. They could take a lot of inspiration from iCloud Private Relay and iOS security architectures in addition to really understanding the Chrome security model.
- kiddingright 2y agoIf the devs didn't take security seriously before, why would another node in the communication graph change anything?
- knowitnone 2y agobecause sometimes it's a deadline pushed by management so a change could result in allow more time for design, programming, review, or even full time security personnel. Nobody writes the best most secure software under deadline
- bloopernova 2y agoWill you be increasing the bug bounty payout? $2,000 is a tiny fraction of what this bug is worth, I hope you will pay the discoverer a proper bounty. You've been handed a golden opportunity to set the right course.
- deleted 2y ago[deleted]
- JumpCrisscross 2y ago> $2,000 is a tiny fraction of what this bug is worth The Browser Company raises $50mm at a $550mm post-money valuation in March [1]. They’ve raised $125mm altogether. Unless they’re absolute asshats, they’ll increase the bug payout. But people act truly when they don’t think they’re being watched—a vulnerability of this magnitude was worth $2k to this company. That’s…eyebrow raising. [1] https://techcrunch.com/2024/03/21/the-browser-company-raises-50-million-at-550-million-valuation/?guccounter=1 https://techcrunch.com/2024/03/21/the-browser-company-raises...
- shuckles 2y ago"We will let anyone run arbitrary JavaScript on all your web pages if you send them a referral link" is surely a 6-7 figure vulnerability for a web browser. That this vulnerability was discoverable using about two steps of analysis tools suggests many more issues are in the product.
- rafram 2y agoNot just that - seems like it allowed running privileged JavaScript (full access to your system) on the preferences page as well.
- voiceblue 2y agoIt is very strange to me that their attitude is "no one was impacted" and this is "hypothetical". Any serious company would immediately consider this to be a case where everyone was impacted! This is like coming home to the worst neighborhood on the planet to find your door wide open, and immediately putting on a blindfold so you can continue to pretend nothing's changed.
- bobmcnamara 2y ago[flagged]
- ayhanfuat 2y agoWas the post written for HN users only? I cannot see it on your blog page (https://arc.net/blog https://arc.net/blog). It’s not posted on your twitter either. Your whole handling seems to be responding only if there is enough noise about it.
- deleted 2y ago[deleted]
- titaniumtown 2y agoNot a good look it not being on the main page! I personally use [zen browser](https://github.com/zen-browser/desktop); https://github.com/zen-browser/desktop); I like the ideas of Arc, but it always seemed sketchy to me, especially it being Chromium-based and closed-source.
- zamadatix 2y agoHeads up: HN doesn't support link naming markdown and some of the extra characters broke the hyperlink. In case the parent can't fix it in time for the edit window: https://github.com/zen-browser/desktop https://github.com/zen-browser/desktop
- tanx16 2y ago> We’re also bolstering our security team, and have hired a new senior security engineer. Is there a reason why you don’t have any security-specific positions open on your careers site?
- ha470 2y agoWe did but we closed the roles by hiring folks. They just haven’t joined yet.
- _kidlike 2y agono mention of the pitiful bounty reward (2000 usd). only sorry and thanks. Please award this person a proper bounty.
- exdsq 2y ago$2000 is an absurdly small bounty here - you should up that
- radicaldreamer 2y ago50k or 100k would be far more appropriate given the severity of this issue. But overall, this makes me think there's probably a lot more vulnerabilities in Arc that are undiscovered/unpatched. Also, there's the whole notion of every URL you visit being sent to Firebase -- were these logged? Awful for a browser.
- deleted 2y ago[deleted]
- ha470 2y agoYa this is fair! Honestly this was our first bounty ever awarded and we could have been more thoughtful. We’re currently setting up a proper program and based on that rubric will adjust accordingly.
- karlzt 2y ago$200k for this big bug.
- karlzt 2y agoMy comment has been downvoted twice, but I don't see it grayed out, I wonder why.
- ARandomerDude 2y ago> Honestly this was our first bounty ever awarded and we could have been more thoughtful That’s corporate speak for “no, we won’t pay the researcher any more money.”
- ibash 2y agoThanks for the response. While people might nitpick on how things were handled, the fact that you checked if anyone was affected and fixed it promptly is a good thing.
- ziddoap 2y agoIt is not really nitpicking, given the severity. Being prompt on a vulnerability of this magnitude should be considered "meeting the standard" at best.
- metadat 2y agoThe CTO and co-founder didn't check in on any of the concerns, completely disappeared after leaving a heartfelt comment. This comes off as incredibly disingenuous.
- NegativeLatency 2y agoOnly $2k for an exploit like this?
- mirzap 2y agoPay the guy properly. $2000 is an insult. It should be $50k. This kind of bug could be sold for 100-200k easily.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- JumpCrisscross 2y ago> This kind of bug could be sold for 100-200k easily Maybe not. If the browser is that buggy, there may be plenty of these lying around. The company itself is pricing the vulnerability at $2k. That should speak volumes to their internal view of their product.
- shuckles 2y agoI think OP mean to say "this bug could let an attacker gain $200k of value easily", though you are right the market clearing price for such a vulnerability is probably low due to huge supply.
- radicaldreamer 2y agoMany engineers at SV startups use Arc on a daily basis. This bug could've resulted in the compromise of multiple companies, probably including crypto exchanges. A browser bug of this severity is extremely valuable, even for a niche browser like Arc.
- JumpCrisscross 2y ago> Many engineers at SV startups use Arc on a daily basis Do we have adoption statistics? It would seem prudent for the browser to be banned in professional environments. (I use Kagi's Orion browser as a personal browser on MacOS. My work is done in Firefox.) > browser bug of this severity is extremely valuable, even for a niche browser like Arc Absolutely. (Even if it were in beta.) What I'm trying to say is the $2k payout sends a message. One, that The Browser Company doesn't take security seriously. And/or two, that they don't think they could pay out a larger number given the state of their codebase. Side note: my favourite content on crisis management is this 2-minute video by Scott Galloway [1]. (Ignore the political colour.) [1] https://www.youtube.com/watch?v=PB-AyvgE8Ns https://www.youtube.com/watch?v=PB-AyvgE8Ns
- zo1 2y agoUntil this individual comes back and responds to at least a few of the questions/comments, I don't think we should even pay attention to this marketing-dept-written post. They basically want this to go away, and answering any questions would raise more issues most likely, so they just seemed to have done the bare minimum and left it at that. It's 3 hours later now, they might as well have not even posted anything here.
- msephton 2y agoI misread your name as Hush which is kind of fitting considering how you're trying to make this go away
- FactKnower69 2y agoremember when reading this that this guy's company is valued at a billion dollars and his comp is 10x yours if not more. we live in a meritocracy
- kernal 2y ago>Arc brought order to the chaos that was my online life. There’s no going back. Bringing the chaos back like it's 1999.
- metadat 2y agoHursh / ha470, where did you go? There are lots of good questions in the replies to your thread, yet you went dark immediately after posting more than 8 hours ago. It's hard to imagine what could be more pressing than addressing people's concerns after a major security incident such as this. To be honest, I'm a bit disappointed. For future reference, this doesn't seem like a good strategy to contain reputational damage.
- tomjakubowski 2y agoHi Hursh, I'm Tom. A couple friends use Arc and they like it, so I had considered switching to it myself. Now, I won't, not really because of this vulnerability itself (startups make mistakes), but because you paid a measly $2k bounty for a bug that owns, in a dangerous way, all of your users. I won't use a browser made by a vendor who takes the security of their users this unseriously. By the way, I don't know for sure, but given the severity I suspect on the black market this bug would have gone for a _lot_ more than $2k.
- keepamovin 2y agoShould have at least paid €1 per user. Eh, maybe that’s what they did?
- ljm 2y agoYou have no idea but you suspect someone could have made more?
- 7sidedmarble 2y agoThat is generally how suspicions work
- xelamonster 2y agoAfter thinking about it for a good long ten seconds, yeah. It would be very easy to steal users' banking information with this. If you crack into one single bank account you have a decent shot at making over $2k right there, a skilled hacker could do a lot more.
- poincaredisk 2y agoSelling vulnerability on the black market is immoral and may be illegal. The goal of bug bounty programs was initially to signal "we won't sue white hat researchers who disclose their findings to us", when did it evolve into "pay me more than criminals would, or else"?
- tolmasky 2y ago
- qwertox 2y ago> including moving off Firebase Firebase is not to blame here. It's a solid technology which just has to be used properly. Google highlights the fact that setting up ACLs is critical and provides examples on how to set them up correctly. If none of the developers who were integrating the product into Arc bothered about dealing with the ACLs, then they are either noobs or simply didn't care about security.
- com2kid 2y agoSaying Google provides examples of being rather nice about it. Firebase ACLs are a constant source of vulnerabilities largely because they are confusing and don't have enough documentation around them.
- liendolucas 2y ago> "...the hypothetical depth of this vulnerability is unacceptable." What is also unacceptable is to pay 2000 dollars for something like this AND have to create user accounts to use your browser. Will definitely stay away from it.
- benreesman 2y agoI like Arc, and I don’t want to pile on: God knows I’ve written vulnerable code. To explore a constructive angle both for the industry generally and the Browser Company specifically: hire this clever hacker who pwned your shit in a well-remunerated and high-profile way. The Browser Company is trying to break tradition with a lot of obsolete Web norms, how about paying bullshit bounties under pressure rather than posting the underground experts to guard the henhouse. If the Browser Company started a small but aggressive internal red team on the biohazard that is the modern web? I’ll learn some new keyboard shortcuts and I bet a lot of people will.
- exabrial 2y agoBro you should be requiring accounts to download HTML. Come on man.
- __turbobrew__ 2y agoAre you going to address the part where you send visited websites to Firebase which goes against your privacy policy of not tracking visited URLs?
- FleetAdmiralJa 2y agoI think the bigger question is: Why are you violating your own security policy by keeping track on what we browse. I though my browsing is private and hidden away from you but if you store my browsing data in your firebase this is not acceptable at all.
- nixosbestos 2y agoSo when there are near weekly reports of websites being compromised due to horrid Firebase configuration, did absolutely no one on your teams raise a red flag? Is there some super low-pri ticket that says "actually make sure we use ACLs on Firebase"?