How a simple mistake left Arc Browser wide open to hackers

Поделиться
HTML-код
  • Опубликовано: 14 ноя 2024

Комментарии • 898

  • @mathieu6965
    @mathieu6965 Месяц назад +5108

    I was terrified about this vulnerability because I thought someone was going to use it to push their new JavaScript framework onto my computer.

    • @paxcoder
      @paxcoder Месяц назад +218

      Haha. That's ok, they just stole your data. Business as usual.

    • @Kwazzaaap
      @Kwazzaaap Месяц назад +27

      That's what your boss would do if they knew how to use a computer

    • @abdullahking2418
      @abdullahking2418 Месяц назад +16

      Now that's what I call a funny joke ..

    • @rawallon
      @rawallon Месяц назад +12

      Why wouldnt you want your apps to be blazingly fast?

    • @theobrominator
      @theobrominator Месяц назад +3

      No, that’s what ‘npm’ is for 👍

  • @hi.im.vijayy
    @hi.im.vijayy Месяц назад +2036

    3:41 ayy made it into a fireship video

  • @sadfacekira
    @sadfacekira Месяц назад +668

    luckily i was safe from this exploit by using arc on windows where 95% of the features from the macOS version are literally not implemented 👍

    • @ThisIsLuckyluck
      @ThisIsLuckyluck Месяц назад +30

      I was litteraly thinking the same things lol

    • @gg-gn3re
      @gg-gn3re Месяц назад +68

      luckily I was safe by not using this spyware jank browser and not using either of those oses

    • @TerminalHeatSink
      @TerminalHeatSink Месяц назад +22

      ​@@gg-gn3rebut the real question is, what has more spyware? Those two OSes or the browser

    • @ILoveTinfoilHats
      @ILoveTinfoilHats Месяц назад +120

      ​@@gg-gn3re Linux users taking every single change they can to let people know they use linux

    • @eshnd-1
      @eshnd-1 Месяц назад +20

      i only use arc on school windows computers because it’s so new that the schools haven’t blocked it yet :D

  • @suplays
    @suplays Месяц назад +500

    YES!! First exploit I can actually understand 🎉🎉🎉

    • @oyeezy
      @oyeezy Месяц назад +2

      same o

    • @SuperRedstoneman
      @SuperRedstoneman Месяц назад +5

      Try some ctfs I swear if you find some at your level it's gonna be fun

    • @JesusPlsSaveMe
      @JesusPlsSaveMe Месяц назад

      ​@@oyeezy
      *Revelation 3:20*
      Behold, I stand at the door, and knock: if any man hear my voice, and open the door, I will come in to him, and will sup with him, and he with me.
      HEY THERE 🤗 JESUS IS CALLING YOU TODAY. Turn away from your sins, confess, forsake them and live the victorious life. God bless.
      Revelation 22:12-14
      And, behold, I come quickly; and my reward is with me, to give every man according as his work shall be.
      I am Alpha and Omega, the beginning and the end, the first and the last.
      Blessed are they that do his commandments, that they may have right to the tree of life, and may enter in through the gates into the city.

  • @weird_autumn42
    @weird_autumn42 Месяц назад +1247

    regardless of any security issues, i still don't trust a VC-backed browser

  • @AQDuck
    @AQDuck Месяц назад +3013

    * Proprietary browser made by a for-profit startup
    * Requires an account to use
    * Pinky-promises absolute privacy yet gives the browser away for free and expect to be profitable
    * Already had a vulnerability worthy of a 9.8 CVSS
    * Valued the bounty for said 9.8 CVE a measly $2000
    Yeah, I'm staying as far away from that as possible...

    • @commander3494
      @commander3494 Месяц назад

      This is why I prefer Zen, it looks as good as Arc but is built on Firefox, open source and not made by some suspicious company

    • @Gregorius421
      @Gregorius421 Месяц назад +313

      Well, it was made for apple users first... so what to expect.
      Then it was released for windows, but only 11, initially. Suspiciously baffling.

    • @7heMech
      @7heMech Месяц назад +170

      They upped it to 20k

    • @user-ii7xc1ry3x
      @user-ii7xc1ry3x Месяц назад +107

      @@7heMech And a job offer to Eva ✌

    • @paxcoder
      @paxcoder Месяц назад +33

      I just came here to say "Nearly? I'm not touching that browser with a 10 foot pole".

  • @jordank249
    @jordank249 Месяц назад +894

    "I use Arc, by the way."
    Really, that aged well.

    • @lilyeatssoup
      @lilyeatssoup Месяц назад +53

      do you mean "i use arch, by the way"?
      totally different thing

    • @alibarznji2000
      @alibarznji2000 Месяц назад

      You're not smart ya know ​@@lilyeatssoup

    • @gg-gn3re
      @gg-gn3re Месяц назад +23

      @@lilyeatssoup I bet jordank was serious too. guy better wear his helmet before going outside, might hurt himself

    • @Kreze202
      @Kreze202 Месяц назад +78

      ​@@lilyeatssoup Typical Arch user not knowing what a joke is (I use Arch btw fr)

    • @jordank249
      @jordank249 Месяц назад +17

      @@Kreze202Someone finally caught the reference. Good God, I thought it was obvious.

  • @HiImKyle
    @HiImKyle Месяц назад +224

    Shouldn't have to have an account to use a browser in the first place. Huge red flag. But w/e

    • @benargee
      @benargee Месяц назад +5

      Yeah, it seems like it could be an opt in feature. Offline users could have an encrypted config file that they could sync between devices if they want so they could use their own sync service of choice like syncthing, etc. even the ease of syncing JavaScript overrides between devices is an oversight.

    • @hastyscorpion
      @hastyscorpion Месяц назад +9

      Firefox has an account system? It’s stunningly useful for syncing your bookmarks and passwords across devices.

    • @osbourn5772
      @osbourn5772 Месяц назад +60

      @@hastyscorpion Yeah, but unlike Arc, Firefox doesn't force you to sign in before using the browser

    • @enderduck4253
      @enderduck4253 Месяц назад +14

      ​@@hastyscorpion the argument isn't against accounts as a feature, it's against forcing it onto everyone.

    • @sujimayne
      @sujimayne Месяц назад +10

      Vivaldi and Firefox also have account systems, but they are not forced. Odd of Arc to force that, but they do.

  • @KETHERCORTEX
    @KETHERCORTEX Месяц назад +110

    Arc FAQ: "Rest assured that your data and security is of utmost importance to us".
    Real life: "Databases hard, access control not understand".

    • @aaaaaa-hh8cq
      @aaaaaa-hh8cq Месяц назад +4

      I installed arc on windows and it was so bad and raw I literally uninstalled in 5 minutes.
      idk why people like this sh*t

    • @PopCapMusicTrending
      @PopCapMusicTrending Месяц назад

      @@aaaaaa-hh8cq only mac users

    • @Sk00200
      @Sk00200 Месяц назад

      ​@@aaaaaa-hh8cqBecause some idiots will try anything except for chrome, it's like they think google is this bad guy and everyone else is an angel, they all get your data, might as well just use chrome and it's really secure and up to date, unlike these 3rd party shitty browsers.

  • @samranda
    @samranda Месяц назад +483

    xyzeva had a good quote in her article that was like “firestore is a database-as-a-backend service that allows for developers to not care about writing a backend”

    • @MarvinPowell1
      @MarvinPowell1 Месяц назад +13

      I peeked at xyzeva's Twitter account. That was a huge mistake.

    • @nothingtoseehere93
      @nothingtoseehere93 Месяц назад +3

      His?

    • @samranda
      @samranda Месяц назад +12

      @@MarvinPowell1 her twitter presence is so normal 😭

    • @gFamWeb
      @gFamWeb Месяц назад +35

      ​@@nothingtoseehere93her*. Fireship misspoke and corrected himself with an onscreen correction.

    • @estivalbloom
      @estivalbloom Месяц назад +10

      @@MarvinPowell1 A mistake as in wasting your time? nothing there was particularly interesting

  • @edwinanciani9532
    @edwinanciani9532 Месяц назад +84

    the way to sneak Diddy in the video was really great

    • @LJdaentertainer
      @LJdaentertainer Месяц назад +4

      And also a Michael Brown "didndu nothin wrong" joke as well, firebase has crossed into menace territory with the jokes 😮

    • @bubtb-yl8lu
      @bubtb-yl8lu 26 дней назад

      But how would you find someone's account id in the first place?

  • @addanametocontinue
    @addanametocontinue Месяц назад +77

    Imagine using Google Maps to visit the near McD's and you end up getting diddled by Diddy.

  • @TRDiscordian
    @TRDiscordian Месяц назад +67

    When I first heard of Arc I said "if it's not open-source, or doesn't have very public audits, not interested", I got a lot of hate. Now here we (predictably) are lol.

    • @heroe1486
      @heroe1486 Месяц назад +8

      Hate from who ? Reddit kids that have written their first Todo list in React last week ?

    • @TRDiscordian
      @TRDiscordian Месяц назад

      @@heroe1486 usually developer communities I help educate lol. So kinda

    • @Gigusx
      @Gigusx Месяц назад +9

      @@heroe1486 Majority of the "I got hate for saying..." posts on Reddit I've seen are basically prompted by the 1 or 2 people (out of 10s) not agreeing with the OP. Can't take them seriously anymore.

    • @chrishoppner150
      @chrishoppner150 Месяц назад +8

      @@heroe1486 "Got hate for saying" usually means they got 2-3 downvotes on Reddit.

    • @hilmyakatsuki1665
      @hilmyakatsuki1665 Месяц назад +1

      Funnily some reddit users will love to use a new web browser built by a random stranger with privacy in mind lol 😅
      Mostly those are just other browsers themed with fishy behaviors or closed source

  • @qawmkl
    @qawmkl Месяц назад +29

    3:00 intercepting gmaps and redirecting you to diddy's mansion is just pure evil LMAO

    • @SsefahFarouq
      @SsefahFarouq Месяц назад +1

      Really evil😂

    • @bubtb-yl8lu
      @bubtb-yl8lu 26 дней назад

      But how would you get someone's id in the first place though?

  • @MRPtech
    @MRPtech Месяц назад +8

    00:12 so many memories. This was in my primary school. Seeing this poster in Head Teachers office.

  • @vasiovasio
    @vasiovasio Месяц назад +18

    0:47 Ha, Firebase changes their logo!

  • @BeethovenHD
    @BeethovenHD Месяц назад +7

    There is a thing called "Tree Style Tab".
    The horizontal tab bar can be removed with some css.

  • @jmon24ify
    @jmon24ify Месяц назад +25

    whenever I hear someone or company is using Firebase, soon after, I hear there is an exploit on their apps because the developers simply didn't know what they are doing. I wonder how many other multimillion dollar apps were developers that don't know what they are doing

    • @MattPenner
      @MattPenner Месяц назад +8

      Everything old is new again. When people figured out what SQL inject was you came to find out tons of web apps we're vulnerable because the devs never thought someone would put SQL into a text box.

    • @Gigusx
      @Gigusx Месяц назад +7

      I'm not a multimillion dollar app developer and I also don't know what I'm doing.

    • @user-pt1kj5uw3b
      @user-pt1kj5uw3b Месяц назад

      A lot

  • @Obie.
    @Obie. Месяц назад +24

    4:05 love a smooth ad transition 😎

  • @async_7
    @async_7 Месяц назад +55

    Storing executable code is wild

    • @factorfitness3713
      @factorfitness3713 Месяц назад +7

      There will be more exploits because of this. It's inevitable.

    • @rompis.a
      @rompis.a Месяц назад +2

      You know what else stores executable code? Web servers

    • @theherk
      @theherk Месяц назад

      GitHub?

    • @lilium-orchid
      @lilium-orchid Месяц назад

      @@rompis.a The difference here is that the executable code can be written by a user.

    • @rompis.a
      @rompis.a Месяц назад +1

      ​@@lilium-orchid Devs are users. Users of the hosting platform. Devs write bad codes all the time.
      What I'm trying to say is it isn't wild to store executable code. It's wild to make such noob mistake with security rules.

  • @Klayperson
    @Klayperson Месяц назад +81

    4:52 why is the spacebar censored? 👀

    • @untalentedthe
      @untalentedthe Месяц назад +4

      You know why. We can’t say it out loud, but we all know why.

    •  Месяц назад +5

      If he knew why, I wouldn't be writing this sentence.

    • @neociber24
      @neociber24 Месяц назад +1

      We can't say that here

    • @erich_ika
      @erich_ika Месяц назад +1

      because it says ********

    • @WellItsHarsh
      @WellItsHarsh Месяц назад

      Very NSFW.

  • @phead2137
    @phead2137 Месяц назад +14

    And people were mocking me for not wanting to use browser with forced login.

    • @heroe1486
      @heroe1486 Месяц назад +6

      Getting mocked by soydevs is generally a good indicator that you're right

  • @fateriddle14
    @fateriddle14 Месяц назад +2

    Holy shit, this is gold, you fit in a promo for your firebase course & today's sponsor all within the flow of the video, legend!

  • @damonguzman
    @damonguzman Месяц назад +228

    Eva is an absolute legend at this point. She’s exposed security flaws in over 100,000 websites using Firebase and now even Arc Browser. Holy!!

    • @andiuptown1711
      @andiuptown1711 Месяц назад

      @@anon_148Nah

    • @rishabhgupta655
      @rishabhgupta655 Месяц назад

      Who is eva

    • @Zumama2
      @Zumama2 Месяц назад +67

      @@rishabhgupta655 eva deez nuts

    • @divinecomedian2
      @divinecomedian2 Месяц назад

      ​@@rishabhgupta655 Probably a dude

    • @retrocatalog
      @retrocatalog Месяц назад

      ​@@rishabhgupta655zx3eva, the hacker who found the exploit.

  • @Riuyilmistico
    @Riuyilmistico Месяц назад +3

    Feels so good to see a fireship video that is not an ad

  • @0xGRIDRUNR
    @0xGRIDRUNR Месяц назад +3

    ngl the one day turnaround on the patch is actually pretty impressive

  • @gargantuan4696
    @gargantuan4696 Месяц назад +72

    Like an arc of lightning, my private browser info can go anywhere

  • @badralz
    @badralz Месяц назад +7

    even sponsership ad looks interesting when @Fireship talks about it xD

  • @Metruzanca
    @Metruzanca Месяц назад +436

    I really wish the firebase rules were reversed. Everything locked down by default and you have to explicitly allow read/write for things. Would make life so much easier.

    • @lanye2708
      @lanye2708 Месяц назад +15

      yeah, like postgres' row level security! it makes services like supabase feel so nice to use

    • @deidyomega
      @deidyomega Месяц назад +83

      It is! Default rules are deny all. But most devs will change it to allow all by default while building. However if you created a firebase firestore instance right now, it gives you a few weeks of allow all (allow if date less than x date). but after that, you have to config the security rules.

    • @TFE6979
      @TFE6979 Месяц назад +11

      What I like to do is to basically only allow READ operations if you're connecting to firebase from the client-side, and writes/updates are only done through Cloud Functions with all the authorization logic in there. Feels easier to manage and doesn't require writing weird firestore rules for authorization, schema validation and etc.

    • @BTCSEDivyanshAsthana
      @BTCSEDivyanshAsthana Месяц назад

      Damn thats smart ​@@TFE6979

    • @deidyomega
      @deidyomega Месяц назад

      @@TFE6979 You are losing a lot of efficiency doing that. The whole point of firestore is the ability to read/write directly from the client. Spending the 2 hours to get good at the rules isn't that hard.
      We use CloudFunctions for when creating the rule would be challenging. Like sharing content. But most of the time, everything is done client side.

  • @danser_theplayer01
    @danser_theplayer01 Месяц назад +146

    "We're not like Chrome, we're private and secure". Private and secure my donkey. What a circus.

  • @Akosiyawin
    @Akosiyawin Месяц назад +2

    I dont even know Arc Browser existed, this video made me use it today.

  • @tacticalassaultanteater9678
    @tacticalassaultanteater9678 Месяц назад +5

    Ordinarily I would blame BAAS for accidentally permitting types of updates that don't make sense, but this particular mistake actually sometimes happens in APIs that use ORMs too , because all it requires is for the set of updated fields to be specified as a dictionary

  • @chibuikeclement2912
    @chibuikeclement2912 Месяц назад +8

    Watching this on Arc Browser.....

  • @trueberryless
    @trueberryless Месяц назад +9

    Fireship basically shipping based news about Firebase which ships Databases as a basement. ❤️

  • @Sameer.Trivedi
    @Sameer.Trivedi Месяц назад +72

    That's why I never jump on hype trains. The first time I hear it needs an account to use, I was like nah....

    • @HeyMr.OO7
      @HeyMr.OO7 Месяц назад +1

      🧑🏻‍🦰🧑🏻‍🦰Me too but in the end the geek inside me surrendered with my email ✉️

    • @npc-drew
      @npc-drew Месяц назад +3

      Theo was pushing Arc lmao Like the saying, better the devil you know...

    • @Johnny91832
      @Johnny91832 Месяц назад +12

      Don't forget the bazillion chromium and Firefox forks like zen, floorp, min etc that could all potentially face this. Trust the first party (chrome and Firefox) because they likely have actual security.

    • @npc-drew
      @npc-drew Месяц назад

      @@Johnny91832 same thing happening with vscode clones lol 😅

    • @HolyAvgr
      @HolyAvgr Месяц назад

      @@Johnny91832the fact you trust chrome of all things in this universe while taking about privacy is wild to me.

  • @Strammeiche
    @Strammeiche Месяц назад +74

    This vulnerability made me discover the zen browser. So, I'd say a win for me.

    • @prorenicsultd
      @prorenicsultd Месяц назад +19

      I tried it. For the same configuration it uses twice or more ram (scales up massively) than Firefox. So no, I use my custom css and sidebery in og Firefox and life's good. Your mileage may vary.

    • @solvek2196
      @solvek2196 Месяц назад +5

      I tried zen but much prefer arc. This isn't a very good look for arc though.

    • @Strammeiche
      @Strammeiche Месяц назад

      @@solvek2196 comparing the 2 I'd prefer arc too, but at least the coming years I'd be too afraid to get bank details or similar stuff leaked.
      But I'm probably a bit paranoid there.

    • @sujimayne
      @sujimayne Месяц назад +8

      Vivaldi is just the best

    • @vspianist
      @vspianist Месяц назад +8

      I tried switching, but Arc just nails so much stuff. The control+tab tab switcher, the split screen windows, the spaces and profiles, the keyboard shortcuts
      They make it so hard to switch (i can't even transfer data over)

  • @Dyras.
    @Dyras. Месяц назад +15

    firefox + ublock keep winning no matter what

    • @EquaTechnologies
      @EquaTechnologies Месяц назад

      i was using that a few days ago but then i switched to ungoogled chromium for the right click emoji and the homepage extension i like. currently trying brave to see what it's like.

    • @ultron_gr6668
      @ultron_gr6668 Месяц назад +7

      this aged well

  • @covle9180
    @covle9180 Месяц назад +134

    If you need to create an account for something that's private and secure, it's not private and secure.

    • @ego4
      @ego4 Месяц назад +2

      teeeny tiiinnyy mayybe secure but definitely not private

    • @c49f65
      @c49f65 Месяц назад +5

      Password Managers?

    • @covle9180
      @covle9180 Месяц назад

      @@c49f65 Good point. Don't use online password managers. KeePass is a great solution. Don't put your entire password db in the hands of some for-profit company and their promise it's totally secure.
      Seriously. If you need to create an account, it's not private. Either you and only you own it, or you're getting fucked at the next data breach.

    • @valiantviktor
      @valiantviktor Месяц назад

      @@c49f65 Ever heard of KeepassXC?

    • @theherk
      @theherk Месяц назад +3

      Your bank?

  • @dziugazz
    @dziugazz Месяц назад

    This was recommended to me the whole day, now that you changed the title, I will finally watch the video, thank you.

  • @gtleshow
    @gtleshow 26 дней назад

    Talk about a ‘whoops’ moment! 😬 It's crazy how one small oversight can lead to such a huge security hole.

  • @ticler
    @ticler Месяц назад +21

    I liked how Theo took his time to shift the blame on Firebase. The truth is, these people should not be anywhere near a team implementing a browser.

    • @heroe1486
      @heroe1486 Месяц назад

      And people like Theo shouldn't be anywhere teaching anything related to programming, he's just as those guy, a soydev with weak and shallow CS/programming knowledge that misguides beginners.

    • @pu239
      @pu239 Месяц назад +4

      i really hate that guy for being such a "nice jerk", if you know what i mean
      always acting as if it's understood that he's morally correct and whatever he does cant be wrong. i watched 4 videos and was out by the half of the 5th.

    • @muizzsiddique
      @muizzsiddique Месяц назад +1

      ​​@@pu239 Have you seen the DarkViperAU videos on Theo? I was already uncomfortable with watching some of Theo's videos (reading articles verbatim, "react" content, etc.), and then DVAU sold me on unsubbing for good.

    • @pu239
      @pu239 Месяц назад +1

      @@muizzsiddique i will, thanks

    • @corvacopia
      @corvacopia Месяц назад

      Or they should just invest more in hiring people in charge of security.
      They have people who worked on Chrome and Safari, they have part of the browser know-how on board, but it would seem not all

  • @tortoiseshell_cat
    @tortoiseshell_cat Месяц назад +129

    We don't need the patch, because we already left Firebase after that pricing change

  • @sreejikm
    @sreejikm Месяц назад +1

    Great find ... good to know firebase rules do handle this vulnerability.

  • @mx338
    @mx338 Месяц назад +6

    Not surprising that Firebase users don't know what they are doing, just hire a backend developer.

  • @thecryptouniversity
    @thecryptouniversity Месяц назад +34

    no diddy hackers

  • @Serizon_
    @Serizon_ Месяц назад +19

    First , also I think that we should rather use zen browser or firefox instead of arc browser or chrome properitory

    • @Mike-Zz
      @Mike-Zz Месяц назад +1

      thanks for sharing, loved zen

    • @willi1978
      @willi1978 Месяц назад

      I like zen. Only necessary bars and most of the window to show the website. All other browser features I don't need

    • @Gigusx
      @Gigusx Месяц назад

      @@willi1978 I've started used it recently and like it for the vertical tabs. The native ones (in Nightly) are ugly af and so are the extensions. Zen does them better but I still hope something Firefox-based comes close to the Vertical Tabs chrome extension.

    • @corvacopia
      @corvacopia Месяц назад

      I like Zen, but I miss the new tab UI with arc, it just feels much nicer to use for me

    • @Mike-Zz
      @Mike-Zz Месяц назад

      @@corvacopia yeah, the overall experience is pretty awesome and solid

  • @itsfedor
    @itsfedor Месяц назад +1

    I have never clicked "Restart and Update" so fast in my life.

  • @AbhiroopSantra
    @AbhiroopSantra Месяц назад +13

    0:15 how is that news fake?

  • @Christian-op1ss
    @Christian-op1ss Месяц назад +4

    Even if this mistake was clearly Arc's, directly exposing your database to the browser makes these kinds of vulnerabilities much more likely. It's why we're moved away from Supabase as well.

  • @mardix
    @mardix Месяц назад

    That Diddy joke was smooth :)

  • @danheidel
    @danheidel Месяц назад +1

    1:38 - Why would you want to remix this? That would be like painting over the Sistine Chapel.

  • @SHUIHE-xyz
    @SHUIHE-xyz Месяц назад +2

    To fellow users:
    I’ve encountered several frustrating issues with this browser, such as crashes and login failures. It seems that feedback isn’t being properly addressed by the developers either. If you’re facing similar problems, I encourage you to speak up and share your experience so that these issues get the attention they deserve. Let’s hope the developers take action and improve this browser for everyone!

    • @SHUIHE-xyz
      @SHUIHE-xyz Месяц назад +1

      AND screw you ARC Developers

    • @FacelessBillions
      @FacelessBillions Месяц назад

      I also experienced relatively poor performance, even compared to Chrome

    • @lilium-orchid
      @lilium-orchid Месяц назад

      give up and leave that browser

  • @FC-BS
    @FC-BS Месяц назад +1

    I'm glade that none of my data got stolen

  • @harshraisaxena6724
    @harshraisaxena6724 Месяц назад

    I've never seen bugs and glitches that much in any application. but arc is still cool

  • @ducodarling
    @ducodarling Месяц назад +2

    I love how BaaS doesn't fit the acronym, no matter how hard you try.
    It's like, as hard as people try and shove SaaS into their project, that's how hard you had to go to make that acronym.

  • @poolkrooni
    @poolkrooni Месяц назад

    The simple fix is instead to set specific fields to Locked in Firebase, not checking whether they match etc... the built-in created field is also of "locked" type already

  • @voidmind
    @voidmind Месяц назад +29

    3:38 Is the $500M valuation another joke? Surely that can't be real. This thing is not even visible on the Statcounter browser market share chart

    • @kevinosborn3258
      @kevinosborn3258 Месяц назад +12

      Probably it shows up as chromium

    • @bmanpura
      @bmanpura Месяц назад

      "There was an attempt"

  • @zeroxinfinity5816
    @zeroxinfinity5816 Месяц назад

    Honestly I would still give them some time, they are a relatively new company and has responded appropriately to the situation

  • @Theo_m64
    @Theo_m64 19 дней назад

    congrats to arc on trying to be a new browser in today's market

  • @JamNaweb
    @JamNaweb Месяц назад

    I asked Arc's AI if it was safe to use the browser after this information and it said no. That it is better to wait for the developers to announce the fix of the flaw.

  • @ethos8863
    @ethos8863 Месяц назад

    "how arc narrowly avoided an iceberg" is perhaps one of the funniest tech jokes in history.

  • @devvie_hu
    @devvie_hu Месяц назад +1

    Exactly why I stick to custom firefox with tree style tabs instead of all these new wannabe browsers..

    • @karersio7062
      @karersio7062 29 дней назад

      watch his new video lol

    • @devvie_hu
      @devvie_hu 29 дней назад

      @@karersio7062 💀💀

  • @cranberrymoscowmule
    @cranberrymoscowmule Месяц назад +1

    more aesthetic a program is... more exploits it has

  • @trieulieuf9
    @trieulieuf9 Месяц назад

    Looking at the thumbnail, I thought this video is about Freemason. The Arc Browser logo is really similar to Freemason logo.

  • @sacredgeometry
    @sacredgeometry Месяц назад

    Good job I don't use the feature that incurred the vulnerability because it reeked of "why the fuck would I want that"

  • @inzaghiposumaalkahfi9650
    @inzaghiposumaalkahfi9650 Месяц назад +33

    1:13 I just found out! It turns out Arc Browser is written in Swift.

    • @Ozzy_Axil
      @Ozzy_Axil Месяц назад +2

      same😂

    • @IStMl
      @IStMl Месяц назад +2

      yeah wtf

    • @MarvinPowell1
      @MarvinPowell1 Месяц назад +5

      Taylor Swift?

    • @szymex22
      @szymex22 Месяц назад +6

      @@MarvinPowell1Apple’s Swift.

    • @IStMl
      @IStMl Месяц назад

      @@szymex22 Tim Swift

  • @asergb
    @asergb Месяц назад

    Are we pivoting to clerkship?

  • @SuperSrDan
    @SuperSrDan Месяц назад

    My favorite part is the "bad things with the power of Javascript"

  • @howar31
    @howar31 15 дней назад

    And it has announced that it will stop all updates except for security updates going forward.

  • @MrSamu309
    @MrSamu309 Месяц назад

    Question- does Boost only work with JS executable script? Seems like a big risk. Can it not be some data values that stores HEX values for colors? Is there additional functionality that boost provides?
    Also, anybody who logs in to their browser to be synced across devices need to be aware of the risk that your browsing data has been stored in a location outside your local machine which is always susceptible to data breach.

  • @guard13007
    @guard13007 Месяц назад +4

    Claiming Firebase did nothing wrong when they allow you to bypass authentication that easily is a bit of a miss.
    If a system's fundamental design encourages bugs with this level of potential impact, the fundamental design IS WRONG.

    • @BruceNJeffAreMyFlies
      @BruceNJeffAreMyFlies Месяц назад

      Allow me to introduce you to C/C++....
      Horrible languages, allowing unsafe code!!!

  • @gblargg
    @gblargg Месяц назад +2

    3:54 Riskiest part of the video.

    • @9hoot789
      @9hoot789 Месяц назад +1

      He'll go there but not 1:18, lol.

    • @gblargg
      @gblargg Месяц назад +1

      @@9hoot789 Nice catch, hah.

  • @josephbarasa
    @josephbarasa Месяц назад

    😂😂 Diddy's mansion was just chilling the boom 💥. Alice has arrived

  • @landmimes
    @landmimes Месяц назад

    Always had mixxed feelings about using Arc but figured it was so much better than everything else - time for zen browser

  • @aaaaaaaaaaaaaaaaaaaaaaaaaaaab1
    @aaaaaaaaaaaaaaaaaaaaaaaaaaaab1 Месяц назад

    Now a hacker will only need to find someone else’s user id. It’s the same difficulty as finding a signature of a signed url. This is not really a serious vulnerability

  • @fernandogalindo767
    @fernandogalindo767 Месяц назад +3

    May be a silly question but how would a malicious user get another user/“target” user id? I get the ability to change and force someone else to execute is bad……but how would they know who they were attacking and if the userId is even valid or not?

    • @alhypo
      @alhypo Месяц назад +3

      Probably just brute force. They can randomly try IDs until they get a hit. Hackers are often not looking for a specific target but rather any target.

    • @harshshah2549
      @harshshah2549 Месяц назад

      Brute forcing is one

    • @alexholker1309
      @alexholker1309 Месяц назад +7

      According to the hacker's article about the exploit the referral system shares your user ID in both directions, and publishing customisations or "easels" also exposes your user ID. So you'd be able to find people to attack even if you can't guarantee that a specific user will be vulnerable.

    • @zakxyz2813
      @zakxyz2813 Месяц назад

      @alhypo @harshshah2549 How are you geniuses planning to "bruteforce" ~30 character alphanumeric case sensitive firebase uuids?

  • @GuruEvi
    @GuruEvi Месяц назад

    The biggest problem is that Firebase allows you to send data to unsuspecting users and they don't even have to accept/review it. It also stores what should be in local WebStorage with Google in unencrypted format, big problem if you're claiming to be all about security and privacy.

    • @MattPenner
      @MattPenner Месяц назад

      That's not a firebase issue. Literally any Javascript script can do the same thing no matter what backend you use, or even without a backend. If the dev stored unencrypted data to your local storage that's on them. What sucks is Arc loaded this code as part of its base functionality. Ugh.

  • @justafreak15able
    @justafreak15able Месяц назад +1

    Stopped using arc a long time ago.

  • @foobars3816
    @foobars3816 Месяц назад

    This sounds like a bad security default on Firebase. I don't blame Arc based on what you said. Things should be secure by default.

    • @foobars3816
      @foobars3816 Месяц назад

      the fact that it defaults to off after 30 days means Firebase expected this issue, but didn't want to risk making things too hard for people because they might lose a customer. So they chose lax security for 30 days.

  • @APPLP1E
    @APPLP1E Месяц назад

    InteresteingInteresteing that there's no one talking about Arc browser glazers here

  • @basit147
    @basit147 Месяц назад +2

    i installed acr and the minute i saw creating user account it mandatory it uninstalled it

  • @Dash359
    @Dash359 Месяц назад

    Arc makes the impression of a product made by UI/UX experts, but having so many security holes is just not acceptable for a browser.
    I stopped using Arc when I installed it on the new machine. After logging in, it merged all my workspaces, mixing all the credentials and passwords of my personal and work environments.
    I would consider using it again, but only once will the rest of the world beta-test it.
    I really loved using it but had to switch to Edge because I could kinda configure it similarly to Arc.

  • @notoriouslycuriouswombat
    @notoriouslycuriouswombat Месяц назад +1

    If they claim to be private and secure they can't point fingers at other people

  • @moritz_p
    @moritz_p Месяц назад

    This is unacceptable. You have to keep in mind that Arc is already used as the default browser at many companies. Both those and consumers could've gotten impacted to a degree I don't even want to imagine. In an ideal world I would've expected VCs to pull funding but they probably got even more money because of the publicity.

  • @RaaynML
    @RaaynML Месяц назад

    I don't know why people keep assuming that primarily-macOS devs are well-verse in security, when macOS handles so much for you that you obviously are going to get used to not covering your own bases, IMHO

  • @emilproducing
    @emilproducing Месяц назад

    Man I love Arc. I hope they fix it well.

  • @noahfunnyguy
    @noahfunnyguy Месяц назад

    wooooow i’m so shocked it’s almost as if people were joking about it and then it happened 😭

  • @buddhaburrito
    @buddhaburrito Месяц назад +1

    2:06 you can't handle the truth

  • @avwie132
    @avwie132 Месяц назад

    How are they so sure it wasn’t exploited?

  • @Beastly477
    @Beastly477 Месяц назад +1

    I prefer Zen rn. We'll see how it goes

  • @Planeta1951
    @Planeta1951 Месяц назад

    The lesson learned is as usual in recent times "don't store your shit on the cloud you have 0 insight into"

  • @gokukakarot6323
    @gokukakarot6323 Месяц назад

    The amount of shit that people do with firebase is astounding. I think we can add Firebase to the list of 3 hard things in software development.

  • @bitwisedevs469
    @bitwisedevs469 Месяц назад

    I've been using Firebase in the beginning of my career and seeing this mistake such as security misconfiguration or prolly never configured at all from the beginning is funny.

  • @AmineOnline
    @AmineOnline Месяц назад

    next video : how clerk exposer millions of data by mistake

  • @commandstring
    @commandstring Месяц назад +27

    3:00 is wild bro

  • @josecassola
    @josecassola Месяц назад +3

    Nothing about the Wordpress drama?

  • @ankk98
    @ankk98 Месяц назад

    Critical infrastructure software should be designed with restrictions applied by default and developers should be forced to specify exact restrictions to ease while implementing it.

  • @Fiilis1
    @Fiilis1 Месяц назад

    I've not even heard of this browser.

  • @Minerafter9
    @Minerafter9 Месяц назад +1

    I use arc on windows. Luckily for me arc on windows does not have boosts so I wouldn't have been hacked.

  • @nequefus
    @nequefus Месяц назад

    But why is user configuration stored in cloud and not locally? Staying away from that.