Hackers used zerodays to infect Windows, iOS, and Android users
arstechnica.com
arstechnica.com
But unfortunately we don't get exponential security. Normally, one would expect that n variables (Browser, OS, CPU architecture) with three choices each should give you 3^n required exploits to cover all combinations.
But unfortunately, n is rather small nowadays, the number of choices shrinks every year, and -even more worrying- the attack vectors compose extremely well so you actually just need 3n exploits.
So I am a little bit at a loss here how we can make such attacks non-economical again.
Samsung's browser and Chrome share 100% of attack surface; Safari and Chrome share likely near 70%. Windows and Android have Chrome built-in at the OS layer, iOS has Safari built in at the OS layer.
In this case, something like Firefox which shares much less attack surface would in fact solve the problem, because the problem is that other things have Chrome at the OS-level.
How is Chrome built into Windows at the OS layer? Wouldn't that be IE or Edge?
I think that's OP's point. Edge uses chromium.
This is wrong. I'd say it's more like 5%. Blink forked from WebKit 7 years ago and development has been very active on both sides since then. And probably the majority of the attack surface is outside Blink/WebKit proper to start with (e.g. JS engine, font libraries, media decoding, networking, etc).
In my opinion, Web, OSes and CPUs suffer from being overly complicated, closed-source ridden, non-modular systems-within-systems. Basicly, the opposite of what the Unix philosophy advocates.
Protocols and instruction sets etc will need to be not too complicated, in addition to being open source and fully documented.
How does that balance against the thread of each platform/ecosystem having its own variants of security issues?
And how do you get that?
>But unfortunately, n is rather small nowadays, the number of choices shrinks every year, and -even more worrying- the attack vectors compose extremely well so you actually just need 3n exploits.
Let me tell you about early-to-mid 2000s. Now that was a time of very low 'n'. Compared to then, we live in a heterogenous nirvana.
Hmm, anyone else find this interesting? I haven't looked into the actual exploit itself yet, but having it work on Android, which has SELinux and/or other protections by default, but not on (presumably) a generic Linux distro, is weird.
I would have assumed it exploited something present only on mobile builds of Chrome, but it affects Windows as well. Odd.
The Android vs Linux part still stands though.
What they found was a server that served up the correct exploit for the platform making the request, and were able to coax a bunch of iOS and Chrome exploits out of it. This doesn't mean that the attackers didn't have other browser exploits or that Firefox exploits couldn't have been dropped into the same framework.
In fact, if you start trolling around in Tor, you're likely to find a ton of Firefox exploits because Tor Browser is obviously based on Firefox.
Disabling Javascript would have helped. You can even use tools like uMatrix to set exceptions per site so you're not exposing yourself to every single site on the internet by default. Though you won't see online news sites suggest this since their revenue is so tied to Javascript being enabled.
The average user doesn't know anything about how sites are constructed. Telling them to use uMatrix is non sensical.
Though that's not to say there's good advice on these kinds of sites.
I've seen a "Windows 10 tips" list from a very popular site telling users that "they don't like being patronised about their own computer" and recommends turning off UAC (Essentially running their account as root)
Or even saying that updating your OS is frustrating so here's how to disable it.
Absolutely dangerous advice but that's the level of general computer sites.
Regarding Update/UAC Please blame microsoft.
I don't want forced updates when I am working. And many time I have encountered issues like computer not booting. After updates they prompts "Please install our cool new software called edge".
I want security update not the marketing update. So I make a compromise and disable update all together. Why not give linux style update where I can review each and every package.
W10 education and enterprise licenses allows you to manage the updates yourself.
Linux Distros are just bundles of software that make up the operating system.
So if your compromise is that you don't want new Windows 10 updates because they also bundle in new features rather than using an OS like linux, then it'd be your fault if you get hacked via an exploit that was patched in an update.
Microsoft aren't going to care.
Then the obvious solution is to make them care. We penalise corporations for financial negligence and failing to take proper precautions and report correctly. We increasingly penalise them for violations of privacy and data protection rules, where similarly they are expected and required to provide adequate infrastructure to comply with the regulatory obligations. If failing to implement reasonable security practices and provide appropriate security updates to users with no strings attached started costing the hardware manufacturers and software developers and resellers the same kinds of penalty per violation as some of the financial or privacy regulations, we'd soon see those security updates universally available without forcing all the unwanted user-hostile changes at the same time.
What if they rewrote a component to have new features and it also fixed a security issue?
What's the difference between a security patch and a bug fix?
At the end of the day if someone gets so angry that Microsoft added Paint 3D in an update that they disabled updates.
What's the obligation here? They chose not to update their computer.
I'm suggesting that perhaps there should be.
In what other area of consumer protection law does a manufacturer or reseller get to provide a seriously defective product and then refuse to deal with the problem unless the buyer also accepts other changes that might make the product significantly different and possibly in their view significantly worse than the one they chose to buy?
The principle is important here. Your example about Paint 3D is cute, but in reality, there are plenty of other examples where user-hostile software changes have been pushed out after purchase, including those that disabled previously available functionality, reduced privacy, introduced advertising, or dramatically changed the look and feel of the product. People shouldn't be forced to accept these kinds of unwanted retrospective changes to the product they originally chose to buy just to maintain an adequate level of security.
For the record I hate this, but history has shown that if you don't try your absolute hardest to get security updates installed onto users' machines, they're going to constantly get owned by malicious third parties. Chrome and Firefox aggressively auto-update for the same reason (if you try to manually install old Chrome for testing it'll obliterate itself on next launch!) The vast majority of users simply do not pay attention to security and will not make the right decisions if you offer them choices about updates and security, because they don't have enough knowledge or context to make the right choices.
Thank you for saying that. I'm one of first in 2005/2006 advocating JS rendering in the browser. JS in the browser has really gotten out of hand. I no longer advocate to do everything on the client/browser side. A web site should just work without JS.
For sure, audio, video do not need JS to function.
Yes you need JS for 3d webGL, but it also opened another can of worm that allows company to fingerprint GPU pretty much anyone who is not using Safari regardless if you are in incognito mode.
What most web developer don't realize browser was build to be a sandbox to protect you from the world wide web. Seems like the current trend is tear down that sandbox for usability and functions. Which is fine, then advertise that browser with JS enabled pretty much open you all that risk. It should be in the educational to the public as well as the first page of any browser that doesn't sandbox GPU finger printing.
Even in the few cases where it is needed, it should be designed to work OK without. I did see once where if JavaScript was disabled, it displayed a link to documentation instead; that is a good idea. (Unfortunately, the documentation didn't work without JavaScript enabled; they should fix that.) If it is accessing data, you can link to the documentation and/or to the data directly, in order to deal with it by yourself, with your own software, if the user wishes to do so. Sometimes the script is used to perform calculations, or automatically convert or render something; you can still add a <noscript> block to just mention what it is, links to source codes, or in some cases (e.g. automatic time zone conversion) just omit that part entirely will do. Simply writing "This page requires JavaScript enabled to work" is worthless; don't do that.
android and ios are indeed a wasteland in terms of browser security.
https://news.ycombinator.com/item?id=24532973 https://github.com/gorhill/uMatrix
I'm not sure what is supposed to replace it though.
https://github.com/gorhill/uBlock/wiki/Blocking-mode:-medium...
There has to be a better way. This isn't working...
If Firefox & Chrome had support for something lightweight like Gemini (https://gemini.circumlunar.space/) then most sites could just use that.
With that sort of setup, restrictions on the web like uMatrix would be a lot less painful because most sites wouldn't ever need to be whitelisted.
But they wouldn't, because they couldn't track people.
They wouldn't use it (or the VAST majority wouldn't) because it means losing tracking.
If implementing your site as an app rather than using something like Gemini came at the price of making people think twice, in theory there might be an incentive to only do web apps when it's actually needed.
But of course not that many people would use that kind of discretion, not to mention "ooh, shiny!"
And it's hard to put the genie back in the bottle anyway.
A better web browser is really needed; one of things it can have is support for the Gemini protocol and file format. (It can also omit many things, as well as adding things.)
It might be nice to have a prompt like "This page wants to use a web font" like how you get for location. I realize that may be a lot of work to add in though.
Really, I'd just like to re-enable webfonts on Netflix so the subtitles don't look like garbage, but keep the fonts off on almost all websites. If anyone at Netflix is reading this, please fallback to something like sans-serif and not serif.
I wish servo was in a better place to fork
Prompts do help, but the prompt should allow the user to allow or block once or always, and to override settings too (e.g. for location, the user can optionally specify a location to use, or specify a command-line of a program that provides the location; for camera, the user can specify the path to the device or to a picture or video file, or a command-line of a program that will produce the picture). The user can then specify whether or not to always make this selection in the future, and in what scope. If the site uses TLS, or is a local file which has been digitally signed, then the user can optionally specify certificate pinning too, in which case the automatic selection will be ignored if the certificate does not match.
I also have other ideas, about meta-CSS, presentation mode, table of contents window, animation skipping, capability of loading animated GIF and PNG files as videos (so that you can rewind and pause it), better keyboard controls, save form data to local files, regular expression search, full cookie editor, SQL access to HTML tables, Xaw-style scrollbars, relative location bar, ARIA view, etc. Most of this is configured and/or activated only by the end user, not by the document. Although, some are capable in the document too, such as, a HTML document with a <video> referencing a GIF or PNG will work; such a file can be loaded with <img> or <video> and either way would work.
No "do not track" setting is needed. My idea is the user could set up request headers arbitrarily, as well as overriding response headers (including some "protected" ones, which are stripped if received from a remote site, so are only effective if set up by the user). For example, to enable "do not track", you can add the rule which adds the request header "DNT:1" with the criteria specified as "always".
I would also ensure that all timing APIs can be spoofed (including the JavaScript core Date object; in my opinion this is an I/O function so it shouldn't belong in the core). This is probably useful for testing, as well as for the end user to get rid of annoyances too.
In normal view and ARIA view, the viewport height would always be reported as Infinity. In print preview and in presentation view (which is a paged/screen media type), the viewport height is reported correctly.
Was it ever robust? Or just that there weren't yet so many exploits?
Qubes OS v4+ does not use typical software virtualization methods. VT-d hardware virtualization it uses was broken only once, and it was done by the Qubes founder: https://en.wikipedia.org/wiki/Blue_Pill_(software)
EDIT: not just zerodays. Many organizations have patch schedules that are too slow.
If they did, there would be more effort and knowledge about the subject
It's like being in the arms trade: what matters is who you decide to trade with.
Honestly, I'd rather see myself as anti-cyber-war at this point, like anti-war protests, meaning telling people to use computers for less critical tasks, and disengaging from certain areas.
The best way to stop future attacks is to make current attacks unsuccessful.
So the whole point of security, digital or physical, is power.
For now, I really don't see the point of working in security for a single reason: there is NO REGULATION on measures of security when writing software. You can find millions of regulations for making physical products, but very few for software when it comes to security.
Of course, governments have higher standards, but law should mandate that insurance companies be able to evaluate cyber risks, so there should be regulations regarding computer security.
I think I a bit can understand how you think. Looking at some health care related apps, I was surprised to see how buggy they were (the user interface) and silly built, wrt security.
On the other hand, without computers, the alternative seems to be that the health care staff picks up the phone and just assumes you are the one you say you are
(I guess you're in the US?)
Related: can community recommend some forums, periodic publications or other sources that aggregate information security news?
Keep an eye on r/sysadmin in Reddit.
r/netsec
What do you do on an iOS device? Does a full device reset reinstall the OS, or does it simply remove all user settings?
I feel like the locked down nature of iOS makes it harder to attack, but if an attack goes thru it would also make it harder to clean up the attack?
Given the price of iOS devices vs good security consultant hourlies, the easiest and most effective clean-up for a few devices is likely just starting over.
Of course you can try to be diligent and skip everything that is potentially a problem, but it is even harder than reinstalling and the data you are dropping is usually more valuable than the OS installation.
Not on iOS.
I'd pay real money for a browser with a slow, safe JS interpreter.
Yeah, there are newer ROP mitigations coming down the pipeline, I agree verifiable execution flow remains a major problem.
We need slow and safe before we can have fast and safe. Either is better than the fast and unsafe we have now.
We should probably unfuck the dangerous morass that is turing-complete font file formats at some point, too.
https://hacks.mozilla.org/2020/02/securing-firefox-with-weba...
Same with Ogg container parsing.
Slow & safe javascript will simply not be adopted by the market because there is zero incentive to do so. Change the incentives and you will get the change you want.
chrome --js-flags="--jitless"It seems to me that "automatic exploit generation" is improving quite a bit where the infrastructure for analysis is a little tricky to set up, but then you can direct that infrastructure to analyze the code for you. The bad guys and good guys are in a race to find new exploits faster (they always have been) but I've been pretty amazed by the direction I see things going with automation.
I might just go back to pen and paper at this point.
Maybe you kid, but... I've been using a physical calendar on the wall this year. I also replaced my Apple Watch with a Casio F-91W some time ago.
You know what's really great? My calendar or watch never gets hacked and it's never unavailable because some overnight software update broke it! Sure, the F-91W technically runs software, but it has no connectivity. That's the important part.
Now if I could just figure out what to do with my phone... I don't think dumb phones are particularly secure, so maybe it makes sense to keep using Android? Or eventually switch to Linux on my phone?
Here's some possible scenarios though:
* If I need to remember when something is going to happen, such as "I'm leaving my house to meet a friend at 4 PM", I can just commit to memory what time it was suppose to be.
* If there's a lot of stuff happening, then I'd make a note on my phone. If the times of events change while I'm out, it doesn't really matter if my calendar at home is out of sync. I'm just going to cross the day off when I get back.
* If I find out a later date will change ("the user group has been moved to Thursdays"), then I'll leave myself a reminder on my phone. Most of the things on my calendar are actually little post-it notes, so I can move things around. I only write things in ink when they will never change, like national holidays that are already scheduled/set in stone.
So far, I haven't really run into any pain points. The drawbacks of paper calendars just aren't enough to overcome the drawbacks of electronic calendars.
b) Google Maps could advice direction to some smaller not so well maintained roads, that could increase travel time a lot, or lead to some road where it's hard to turn back. So maybe planning ahead and writing driving instructions at home before driving would be better. Or just trying to follow main street signs for major roads.
c) There are some DIY projects like Raspberry Pi navigator: https://www.raspberrypi.org/forums/viewtopic.php?t=70517
The raspberry pi project looks interesting, though.
I hear you, but I see where they're going with it and what is possible with automation will improve each year. It's certainly not a dead end.
And then there is also the irony punctuation which looks like this: ⸮
https://en.wikipedia.org/wiki/Irony_punctuation
But I have never seen anyone actually ever use it. In fact I only ever heard about it so rarely that I almost miswrote and was about to say that interrobang is sometimes used for indicating sarcasm. But when I looked it up I read that interrobang is for showing surprise of course!
As for your :> there was a guy that used to use it on an IRC channel that I was on. But I never understood quite what he meant by that kind of smiley. And later I looked it up and in his case I think the description I saw on Urban Dictionary fit pretty well, which said it was like a mischievous or devious smile. And I guess that also fits good for when you are sarcastic. Ever since I read that definition of :> it makes me think of this cartoon grinch smile https://meme.fandom.com/wiki/The_Grinch_Smile
I'd call whoever is responsible for such a valuable amount of 0days expert/nation state level for sure.
> Expert (!) hackers used...
I hope then it's clear they are not experts really and when I say "experts" it's clear that I'm just quoting.
On the other hand, using quotation marks to indicate sarcasm or irony is normal use and is in style guides.
You just have to rely on context to differentiate. The headline of the linked article is pretty ambiguous and like GP I read them as sarcasm. I think it was a poor choice to include them at all in this case—they don't add anything to the headline.
I don't know why started using it but it's in wiktionary so "everyone should" understand it: https://en.wiktionary.org/wiki/(!)
I guess, as you also mentioned, without enough context around it, both are hard to understand.
X is dangerous VS X is "dangerous"
The implication is true vs not true.
Wasn’t clear to me from the article, although I may just have missed it being the idiot that I am.
The Volexity blog covers some of the earlier watering hole attacks in more detail.