The least enjoyable thing about web browsing in the 00-s was javascript. Pop-up windows, window resizing, stealing focus. Now javascript is still the reason web sucks. And security has not improved much.
The least enjoyable thing about web browsing in the 00-s was javascript. Pop-up windows, window resizing, stealing focus. Now javascript is still the reason web sucks. And security has not improved much.
What?!
Modern browser security has gotten orders of magnitude better since Shockwave Flash was removed from web browsers. The sheer unending volume of security vulnerabilities flash introduced into browsers was staggering. Flash (until very near the end of its life) had no sandboxing, and had its own update mechanism. It was the norm for people to be running old versions of flash with unpatched security holes. And flash had so many vulnerabilities - if memory serves, flash generally fielded more CVEs in any given year than the entire rest of the browser!
Remember how revolutionary pwn2own was? "Wow, find a vulnerability and win $1000!". These days vulnerabilities of that magnitude are worth way more money, because of how secure the browser environment has become. ($100k-$1M on the black market as I understand it.)
The only reason it feels like security hasn't improved much is because crypto ransomware has made hacking so much more profitable. But even then, most randomware doesn't usually take advantage of security vulnerabilities in web browsers. Its really quite remarkable how secure the modern web has become; and that wouldn't have been possible if flash were still around.
Theses amounts were low because there was no interest in rewarding white hat hackers sadly. Bug bounties at the time were extremely rare. It wasn't lower because it was easier (though it may have been easier, not arguing it wasn't, just that the amounts are not evidence of it).
> ($100k-$1M on the black market as I understand it.)
On the "white" market you means. Zerodium is paying theses amounts. I don't feel like it would be higher in the black market than what they are offering, but could be.
Speaking of which, in 2020 Zerodium stopped accepting "Apple iOS LPE, Safari RCE, or sandbox escapes" for a few months because there was too many of them... still no "Thought on iOS" yet... It's not like it's even a new thing, I remember a long time ago when you could jailbreak your iPhone using a website directly.
Didn't even need to go far either... check CVE-2022-22620, only a month ago.