[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y ] [Home]
4chanarchives logo
Pwn2Own: Chrome wins
Images are sometimes not shown due to bandwidth/network limitations. Refreshing the page usually helps.

You are currently reading a thread in /g/ - Technology

Thread replies: 107
Thread images: 11
File: pwn2own_logo-930x488.png (569 KB, 930x488) Image search: [Google]
pwn2own_logo-930x488.png
569 KB, 930x488
http://venturebeat.com/2016/03/18/pwn2own-2016-chrome-edge-and-safari-hacked-460k-awarded-in-total/

BTW Firefox was considered so far behind in regards to security that it wasn't even tested.


>Of the trio, Chrome fared the best. Two attempts were made to hack Google’s browser: One failed and one was deemed a partial success. The successfully exploited vulnerability in Chrome had already been independently reported to Google, so it wasn’t given full points.

Edge and Safari meanwhile didn’t survive any attacks. Two attempts were made to hack Microsoft’s browser and three attempts were made to hack Apple’s browser. All attempts were successful (2/2 for Edge and 3/3 for Safari). The biggest cash prize for a single attempt was $85,000 for pwning Microsoft Edge.
>>
>>53590044
firefox is unhackable so it wasn't tested
>>
>>53590119
https://it.slashdot.org/story/16/02/12/034206/pwn2own-2016-wont-attack-firefox-because-its-too-easy

keep dreaming, faggot.
>>
>>53590044
>Firefox was considered so far behind in regards to security that it wasn't even tested.

AHAHAHAHAHAHHA BTFO
>>
>>53590044
>BTW Firefox was considered so far behind in regards to security that it wasn't even tested
felt of chair when i read that. but hey guys it is okey because it is free.
i'm surprised that EDGE wasn't cracked more times since is quite new and still somehow buggy.
>>
>>53590144
>The contest, which is sponsored by HPE and TrendMicro this year, is offering over half a million dollars in prize money, but for the first time, not a penny of that will directed to Mozilla Firefox. While Microsoft Edge, Google Chrome and Apple Safari are targets, Firefox isn't because it's apparently too easy and not keeping up with modern security: "'We wanted to focus on the browsers that have made serious security improvements in the last year,'

Holy shit.
I'm sure it wont be long for the mozilla shills to show up defending this behaviour.

Mozilla should spend less time on gay rights and buying Paris offices with gold leaf ceilings so they might actually be able to spend time to make a web browser that is safe to be used on a machine with an internet connection.
>>
>>53590359
>I'm sure it wont be long for the mozilla shills to show up defending this behaviour.
hehe
>Mozilla should spend less time on gay rights and buying Paris offices with gold leaf ceilings

Doubtful. They seem to have chosen the path of steady self-demolition.
>>
>Mozilla should spend less time on gay rights and buying Paris offices with gold leaf ceilings so they might actually be able to spend time to make a web browser that is safe to be used on a machine with an internet connection.
Shit I wish I could say it's not true.
>>
>>53590359
>it wont be long for the mozilla shills to show up defending this behaviour.

Still nothing. Looks like they can't spin this.
>>
File: Screenshot (35).png (14 KB, 876x322) Image search: [Google]
Screenshot (35).png
14 KB, 876x322
Firefox needs to be put down humanely out of it's misery.

FF with never have 50% market share it did back in 2009. I suspect unless Mozilla focus on getting real shit done rather than social justice Mozilla and Firefox could be bankrupt in 5-10 years and no amount of FOSS volunteers will be able to pick up the mess.
>>
What's the best firefox based browser? Palemoon is ded and waterfox is just as slow and bloated.
>>
>>53590296
>new
It's just trident with a new window border.
>>
How about you try that contest with noscripts, which Chrome doesn't support?
>>
>>53590654
I'll try:
Who gives a shit about some stupid hacking competition. Firefox is free as in freedom, and works to fix the gender disparity in the software world. Don't you realize that women are being subjugated even more so than men, since women are being actively excluded from the software world and thus the merits of free software? Seriously, you should take some time to reflect on your obvious misogynistic subconscious and your tendency to attack anyone who isn't hetero white male, you cis scum.

How was that?
>>
File: 1458435734268.png (617 KB, 1280x720) Image search: [Google]
1458435734268.png
617 KB, 1280x720
>>53590044
>BTW Firefox was considered so far behind in regards to security that it wasn't even tested.
>>
File: sip.jpg (67 KB, 379x351) Image search: [Google]
sip.jpg
67 KB, 379x351
>>53590901
0/8 not gr8 b8 m8

Sounds too formal to be either Mozilla shill or sjw.
>>
>>53590901
I liked it :)
>>
>>53590853
Chrome has uMatrix you retarded neckbeard.
>>
>>53590745
There is no good FF based browser
>>
>>53590996
Crap, it was a little formal wasn't it.

I've been writing architecture and api docs for the past few weeks since my customer is a dipshit. I'll try better next time :^)
>>
>>53591065

It's cool, you'll be back to shitpost level of literacy in no time!

Good luck with that customer anon, godspeed.
>>
>>53590044
>can't hack firefox
>claim it's too easy so you didn't even try
>get google shill bucks
>>
Is firefox ok for mobile? Im currently using it, primariky because ublock just werks
>>
>>53591186
On Android Lightning browser is better

On iOS Firefox is pretty good yeah
>>
>the Chrome target is with EMET enabled.
>TrendMicro sponsored event

lol what a joke. Poor FUD.
>>
>>53591179
Firefox shill detected.
>>
>>53590791
and zou know that how? If they are the same underneath why is there so much difference in rendering and speed?
>>
So what browser should I be using on Windows?
>>
>>53590901
I don't know why are you so surprised when the mozarella foundation has always been a non-profit first and foremost and a tech company second. Same goes for the FSF or the EFF. Suddenly they issue a statement that rings with socially-conscious sentiment and you go nuts, because fuck, why would an NGO care about society at large.
>>
Firefox is under bad management and is dead until it falls into the hands of apolitical or politically unsavory neckbeards once again.

Typical firefox changelog:
>Removed a feature some users liked
>Added or improved a bullshit social feature we like but nobody else uses
>Changed the UI again
>Facebook integration
>Broke addon compatibility
>Mobile shit but nobody uses our browser on mobile so who gives a fuck
>Fixed known security bugs but didn't fix insecure design
>Didn't improve performance, actually made it worse. Cache more UI animations! Who uses older computers? Not firefox users! Go use dillo, neeeeeerds!
>>
>>53591357
Non-profit is not that same as anti-profit. M'zilla is literally burning money on anything but the browser right now.
>>
>>53591391
>Non-profit is not that same as anti-profit
D'oh
>>
>>53591300
Because it's just trident? Because Microsoft is not the kind of company to throw away decades of compatibility to appease a few neckbeards?

But beyond that, they likely decoupled the window interaction from the page drawing like they should have 5 years ago, and probably tossed a sandbox in for good measure. You can do a lot with a new window border without touching the underlying data engine
>>
File: 19078588_BG1.jpg (47 KB, 720x480) Image search: [Google]
19078588_BG1.jpg
47 KB, 720x480
>Adobe Flash was included because it was unsurprisingly often used to circumvent browser security.
>Flash was used
>Flash
and the other entry point was Java?
so the weakness isnt the browser but the exploitfests called flash and java?
not to mention unverifiable results because muh undisclosed hacks.
wow its fucking nothing except a PR wank fest.
>>
>>53591435
It was mostly windows with EMET enabled browsers.
As I said, poor FUD.
>>
>>53591435
Browsers are supposed to sandbox their extensions. It's a valid test. If this was as easy as "just hack flash", chromium would have fallen too. It didn't.
>>
>>53590745
Firefox
>>
>article doesn't even mention firefox
>OP lies about firefox
>thread believes him
ARE YOU ALL THIS MENTALLY RETARDED
>>
>>53591510
see
>>53590144

Nice try Rajesh but only 0.7 gold leaves will be deposited in your MozShilla account for that poor quality post.
>>
>>53591179
>>53591246
>>53591435
>>53591452

Finally, the FF are coming. Took 'em a while.
Counter args so far:
-sponsored competition
-only jave and flash as entry points
- PR fud

Yep, FF shills getting desperate
>>
>>53591510
It was mentioned countless times before by the organizers and in different articles that firefox will not be tested because it did nothing to improve it's security since last time. Maybe it's not in this article but we all know about this. Get informed.
>>
>>53590144
>slashdot
/. is as bad as a random dumbfuck OP here. The article it linked to only said it was focusing on certain browsers because they advanced security features, not that Firefox WASN'T SECURE.

God fucking damn, Google, are you this insecure about your browser that you will pay people to lie?
>>
File: game over u died.jpg (65 KB, 500x498) Image search: [Google]
game over u died.jpg
65 KB, 500x498
It really is sad how far Mozilla has fallen. Firefox was the knight in shining armor coming to save us from IE back in the day.
>>
>>53591589
>only said it was focusing on certain browsers because they advanced security features, not that Firefox WASN'T SECURE.

I hope you don't do IT for a living.
Not doing security improvements constantly is being insecure.
>>
>>53591406
sad that ive never anything about edge and i know your post is true
>>
>>53591328
If you don't want feature surprises every month use Firefox ESR. Honestly my patience is nearly up with Mozilla.
>>
what if i used Opera? that had such low market share, people wouldn't bother exploiting it. right?
>>
>>53591684
I hope you dont have flash and java installed in your IT and rely on the browser to safe your sorry ass.
>>
>>53590359
I'm confused, so they slandered Firefox?

if anything this shows how sponsored and dumb this whole thing was.
>>
>>53591774
>I'm confused, so they slandered Firefox?

Not slander at all, it's facts and reality. it's understandable it would seem like slander to Firefox cucks since they haven't grasped that facts don't care about their feelings.
>>
File: 33750642392586.gif (84 KB, 403x392) Image search: [Google]
33750642392586.gif
84 KB, 403x392
whats the point of updating firefox now? every new version removes a feature, doesnt bring anything new, they dont even improve security, theres no fucking reason at all im staying at 44, fuck them removing tab groups, fuck you mozilla
>>
>>53591793
what facts?

no hacks were awarded, documented or presented for prize money.

why is /g/ so childish and bandwagony?
>>
>>53591684
I hope you don't plan on doing anything that requires intelligence for a living, because ADVANCING SECURITY doesn't clash with HAVING SECURITY.

But of course, anyone with intelligence knows that. Too bad you're a dumb 4chan luser that doesn't.
>>
ITT: /g/ bitching at mozilla for supporting addons
>>
>>53591406
well i agree it is not 100% new code. Why would you throw away all of it. Trident had it strong parts like power efficiency and it definitely got harden over the years from all the patching. But still some significant modifications had to be made. New standards included support for chrome extensions and so on.
>>
>>53591840
>because ADVANCING SECURITY doesn't clash with HAVING SECURITY
As I said, those two are the same thing. And yet you fail to understand.
>>
this test seems too good to be true.

like. is it what this guy said? >>53591547
>-only jave and flash as entry points

because if so, this test is dumb as shit
>>
File: 1450083851857.jpg (47 KB, 600x664) Image search: [Google]
1450083851857.jpg
47 KB, 600x664
This is the final straw for me. Always thought Firefox was better at security.

Which browser to use now?
>>
>>53592423
Who would ever think Firefox natively is better at security? Serious question. The only thing that makes it secure are certain addons, without that it is Swiss cheese.
>>
>>53592684
It USED to be the more secure browser, back when Microsoft was still pushing ActiveX and super user as default user account.
>>
>>53591644
There will be servo.
>>
Firefox is a pile of shit. I'm not even surprised.

All they have been doing over the past years is remove features and bloat it. I'm ditching it for Chrome soon.
>>
>>53590044
Google buy this event every year it's meaningless.
>>
>>53591644
It caused MS and Google to jumpstart the development of secure browsers.
So it succeeded, in some way.
>>
>The bounty for valid potentially exploitable critical and high security rated client security vulnerabilities will be between $3000 and $7500 (USD) cash reward.
https://www.mozilla.org/en-US/security/client-bug-bounty/

>Sandbox Escape [5] $15,000
https://www.google.com/about/appsecurity/chrome-rewards/
>>
File: 1138961386702.png (21 KB, 176x232) Image search: [Google]
1138961386702.png
21 KB, 176x232
im switching to chrome probably, i have already used it at work on a weaker pc and it ran much better than firefox on my home rig, theres really nothing left from old firefox, its shit, only thing that disturbs me is botnet, but you cant fight something as big as google forever, you cant win
>>
>>53594438
also im going to keep ff44 on my linux pc forever, never updating this shit again
>>
I want to use chromium so bad, but because of their affiliation with google I just can't bring myself to install it.
>>
>>53594438
>>53595052
use opera, it's really the best browser out there.
>>
>>53595942
>proprietary
>>
>>53595052

Same. Fuck google.
>>
>>53594537

BOTNET VERSION 44

No 2.6.28
???
Dude....................................................................................................................................
>>
>>53591547
Hey Homo, My Noscript kills your shilling.

Now get the fuck out!
>>
>>53590119

hacking firefox is homophobic
>>
>>53590044
>BTW Firefox was considered so far behind in regards to security that it wasn't even tested.
Citation needed
>>
>>53595052
>>53596626
>uses google search
>>
>>53590119
>>53590359
you're both fucking retarded..

firefox is so much more secure, there's no need for it to "get more secure" vs other browsers
FILLDISK STILL WORKS ON EVERY BROWSER, IT NEVER HAS WORKED ON FIREFOX

why are they so fucking bad.
>>
So, seriously,
Real talk, I don't want firefox anymore. I heard Opera is like IE with a new shell, and... We all know ie/edge was trash.
So what the fuck alternative do I have guys? I'm sick of the stock browsers.
And no, I don't really want waterfox/Pale moon either.
>>
>>53597196
Use Iridium.
It's chromium with all the shit taken out of it.
Only thing that sucks ass is the non-stacked tabs which chrome doesn't have.
>>
>>53597328
Thanks anon.
I'll be porting my shit to that soon.
>>
>>53590044
>all this macbooks
>one token surface
>>
>>53590044
>no palemoon
As expected, real browsers are too hard for script kiddies.
>>
>>53590119
I think they're using stock browser configs. NoScript + ad blocker + HTTPS Everywhere = unhackable.
>>
Last week in class I saw someone use UcBrowser on windows, I didn't even know of the existence of that browser for computers.
>>
>>53596773
There are no valid alternatives. Finding otaku goods is hard.
>>
>>53590745
Icecat
>>
>>53597032
Denial in full effect
>>
Firefox is a bad, SJW, Brow's
>>
>>53596751
read the thread, faggot. it's in the 3rd post.
>>
>>53597874
>palemoon
>real browser
wow
>>
>>53590044
I want a secure browser but I do not want to sign up for the botnet, what do I do?
>>
>>53604337
Use Firefox
>>
Considering the Tor browser uses Firefox, they must be tracking that shit byte by byte i think it's a fairly safe browser.
>>
Chrome is so secure because of the botnet
>>
>>53591823
They probably didn't publish the hacks so they won't create a security panic among their users. With Chrome, they only found one vulnerability which had already been reported.
>>
>>53590144
keep being an imbecile.
>>
>>53591547
ye ye keep suckin googles p e n i s
>>
File: 1404163586550.jpg (73 KB, 459x395) Image search: [Google]
1404163586550.jpg
73 KB, 459x395
>>53591370
>>
>>53604337
>botnet
Seriously what are you people so scared of? Do you really think a human is going to read through all the billions of searches and web history google receives every day?
>>
>>53591370
>Mobile shit but nobody uses our browser on mobile so who gives a fuck
but I do. Because there are actually addons like stylish and ublock
>>
>>53592788
According to Mozilla, Servo in itself won't replace Gecko in Firefox.
They might port some Servo parts over, though.
Why? No fucking idea.
>>
>>53606844
>what is xkeyscore
>>
>>53606844
>human
That's not how data mining works
>>
>>53607641
Why would you give a single fuck about data stored in a database that nobody ever looks at?
>>
>>53606962
Because making an entire browser from scratch takes forever, especially one that has as much flexibility as Firefox. Integrating it bits at time allows them to actually get improvements live rather than having vaporware / forever beta software
>>
>>53607728
Sure, but forever building on top of legacy software does nothing but create unnecessary cruft and problems in the long run.
I'd rather them do everything from scratch, and take their time for it, to build a great and long-living browser for the Web3.0(tm)

Also, they built a fucking mobile operating system from scratch that they knew nobody would ever use.
How hard could building a fucking browser be in comparison?
Thread replies: 107
Thread images: 11

banner
banner
[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y] [Home]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
If a post contains personal/copyrighted/illegal content you can contact me at [email protected] with that post and thread number and it will be removed as soon as possible.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com, send takedown notices to them.
This is a 4chan archive - all of the content originated from them. If you need IP information for a Poster - you need to contact them. This website shows only archived content.