Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I never think twice about clicking links.

I hope you don't work for any sensitive position.



It's a valid comment, but if you're in a position where you are worried about 0-days from random web browsing then you should be using the internet on a fully segregated machine.

If Firefox or Chrome has an RCE + privilege escalation in it that can be triggered just from browsing to a page then, congrats, you got me.


The recent CPU-level vulnerabilities have exploits that can run in the browser. See https://www.zdnet.com/article/intel-cpus-impacted-by-new-zom... for pointers to video evidence. They're not zero-day attacks once they're made public, just the same as Meltdown and Spectre. Go download the PoC code, switch calc.exe to something useful, and phish away.

https://news.ycombinator.com/item?id=20028108 from earlier this week shows that just loading a page can lead to network information disclosure or other compromise / attack vectors. It's not a zero-day, it's a feature.


That's not very fair. Browser exploits are a lot rarer than phishing.


I don't think background noise of broad, low-effort phishing emails can be directly compared to a more focused attack. If you work somewhere with interesting data the odds of a good phishing attack leading to an exploit could be much higher because you're being specifically targeted and they're not going to send the message until they have a current exploit ready (probably hoping to get it in before your IT department's change window, too).


If someone had a working browser exploit, wouldn't they just deliver it to their targets via an ad network?

AFAIK most enterprises don't mandate ad blocking or noscript.


> If someone had a working browser exploit, wouldn't they just deliver it to their targets via an ad network?

I've heard more people at enterprises using ad blockers for security so I wouldn't rule that out but in general this is hitting that the broad vs. targeted distinction I mentioned: each time you use an exploit you're risking discovery, which will lead to it being patched & AV signatures going out. Using an ad network increases the number of people who are not your target getting the payload, not to mention any scanning the network does, and since ad networks require payment there's another trail pointing back to you which might not otherwise be the case if you are hosting things on compromised servers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: