Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> It's a self correcting problem. You go to a site, it freezes your machine, you never visit the site again.

What do regular users do about a malicious ad that runs on thousands of different sites?

> Turning off WebGL = no more Figma, no more Canva, no more Google Maps

Which is why you should probably rather turn off the actual vulnerable API, i.e. WebGPU, not WebGL.



It really ought to be something you can enable or disable per site. I was surprised to find its not.


Maybe a browser extension could inject JS in a tab to redefine all the WebGPU API into a noop.


I just remembered and checked. Noscript does allow blocking webgl on a per site basis.


I just don’t think people are doing malicious ads like that. Like I’m sure it exists but like what’s the point? If you are the malicious person you pay money for ads to freeze someone’s computer and that’s it? It’s not even like you would gain anything from it


Failure to imagine an incentive doesn't mean there isn't one. You can't rely on this type of thinking to reason about security. The thing you would have never thought of is what gets you.

For example, an ad provider itself can be hacked by a malicious party, so the "pay money for" part no longer applies.

Or an attack by a state actor or other large entity, where paying for a coordinated disruption of some region or company makes financial or military sense.

Those are just two things that came to my mind, and are likely a fraction of plausible incentives someone might have now or in the future. People are creative and unpredictable. Weird shit happens. Fact is stranger than fiction...

Instead, just ask: should visiting a website ever have the power to freeze your computer without your consent? If you think the answer is no, this is a security bug and it should be fixed.


That’s why I said I’m sure it does exist but based on it only freezing the computer until you reboot it that’s not useful for hackers doing it to make money and doesn’t seem that useful for disruption unless of course you do hack a bigger ad network then I could see it legitimately being disruptive rather than a slight nuisance. It definitely should be fixed though, it’s crazy it’s gone so long with no fix




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: