My browser got hacked and it cost me $2,000

Поделиться
HTML-код
  • Опубликовано: 27 сен 2024
  • Thank you BrowserBase for the support, check them out at browserbase.com
    Arc getting hacked is terrifying. Firebase being responsible is even moreso.
    SOURCES
    kibty.town/blo...
    arc.net/blog/C...
    x.com/xyz3va/s...
    Check out my Twitch, Twitter, Discord more at t3.gg
    S/O Ph4seOn3 for the awesome edit 🙏

Комментарии • 186

  • @t3dotgg
    @t3dotgg  16 часов назад +185

    Since recording this video, Browser Company has taken things VERY seriously. Quick list of things since:
    - Browser Company has an official bug bounty board
    - Eva found another exploit that was fixed and paid for
    Wild ride.

    • @sherlockmaverick
      @sherlockmaverick 13 часов назад +7

      I want a guide on how to build the cursor cat, Theo.

    • @atefth
      @atefth 10 часов назад

      @@sherlockmaverick lol

    • @fajllo
      @fajllo 7 часов назад

      😅😅😅😊😅😮

    • @fajllo
      @fajllo 7 часов назад

      😅

  • @shirshak6738
    @shirshak6738 15 часов назад +164

    don't use firebase is my suggestion. You can make browser, but can't make backend for proper authentication & authorization is kinda shame.

    • @BitWizCoder
      @BitWizCoder 10 часов назад +14

      They didn't create the browser from scratch; they used Chromium as their base, so it's more like building on top of an another softwares.

    • @ivan.jeremic
      @ivan.jeremic 7 часов назад +8

      @@BitWizCoderit's more like building just the UI.

    • @rasalas91
      @rasalas91 6 часов назад

      ​@@ivan.jeremic they're doing something Flutter/Kotlin Multiplatform like, but with Swift. I don't know why exactly, because Zen Browser seems close in functionality and seems to rely on React or something?

    • @crugg
      @crugg 4 часа назад

      @@BitWizCoderBuilding a browser on top of Chromium that’s so far off from stock chromium is still a massive thing. If you can do that, you should 100% be able to build a simple backend.

    • @lmnk
      @lmnk 2 часа назад

      I think you don't see an elephant in the room... why the hell THE BROWSER mandates to create account just to use it??
      I mean, I use Firefox and I have an account for sharing tabs across devices... But I only created it in 2022 voluntarily, when moved to mobile Firefox, and before that I just was using it without any account for almost a decade.

  • @zuma206
    @zuma206 14 часов назад +85

    does eva have a youtube or something? as awesome as your videos are, i wish i could get this sorta informative video straight from the source. Paying eva 2k is incredible, though if you continue to cover her stuff i hope you either continue to pay her or work out a revenue split

    • @PatrikTheDev
      @PatrikTheDev 8 часов назад +16

      Actually, Eva ended up getting 20K from The Browser Company, which is much better

    • @schtormm
      @schtormm 7 часов назад +7

      shes got a blog, its in her twitter bio

    • @porterhouse937
      @porterhouse937 2 часа назад

      I don’t know about RUclips, but based on “her” aesthetics and pfp, I’m sure eve has a nice little girl wiener and probably a discord channel with copious amounts of cp.

  • @TopHatProductions115
    @TopHatProductions115 15 часов назад +57

    Just making sure I don't misunderstand...
    Are we saying that Firebase's default config is nightmare fuel for security-conscious devs?

    • @zuma206
      @zuma206 14 часов назад +14

      basically! the default in a custom-made rest api is no data is accessible. in firebase, the default is all data is accessible. in a rest api you write code to give users access to data. in firebase you write (an admittedly smaller amount of) code to disable user access to data

    • @t3dotgg
      @t3dotgg  14 часов назад +21

      Yep.

    • @Fiercesoulking
      @Fiercesoulking 6 часов назад

      yes but its not just this alone the last 10 years were a nightmare . Its really hard to summarize it , you have web dev who do things in browser which weren't meant to while browser stayed on JS and have no security domains, cloud also open some angles for attack . I recently learned about Microsoft Cloud for Infrastructure and what tools and how many custom protocols are used to remote control windows OS systems madness would. Its just not a feeling that the flying forces have increased in the past it was something 2 security alerts peer week on my favorite IT news site now it is on near daily interval often muilply a day.

    • @rasalas91
      @rasalas91 6 часов назад

      @@zuma206 isn't the default for like 30 or 90 days to open everything and then it automatically closes everything (if you didn't set your own stuff)? Or is that new?
      (I "recently" did that the first time and when I heard the news about Arc I was confused, because you can set all that up and ~isAuthorized and ~isSameID didn't seem so far fetched)

    • @ticler
      @ticler 6 часов назад +2

      Just for people who do not understand how browser and http protocol works

  • @AtiqSamtia
    @AtiqSamtia 12 часов назад +19

    They collecting each website visit when they clearly say in their policy they don't. And no accountability on this major privacy issue? Just glance over?

  • @sean_reyes
    @sean_reyes 16 часов назад +31

    That cat is a nice touch I’ll add that to my website.

    • @t3lls
      @t3lls 10 часов назад +5

      Make an option to disable it, I like to read while marking the text with my cursor. That cat would really annoy me…

    • @leofaizan8886
      @leofaizan8886 10 часов назад +15

      @@t3lls thats what cats do.

    • @Manmanolo115
      @Manmanolo115 7 часов назад +4

      Make it so when you click on it you give it food and leaves

    • @brod515
      @brod515 7 часов назад +1

      I think people should be more interested in creating their own content. you don't have to have a cat like the one on her website just come up with your own creative things.
      go find out how they did it and just learn from that.

    • @sean_reyes
      @sean_reyes 6 часов назад +2

      @@brod515 I like cats 😊

  • @jonaskohl13
    @jonaskohl13 5 часов назад +13

    15:48 "They're new to this, they have no idea what they're doing" Maybe they shouldn't just build a browser with half-assed features like this and put all of their users' data on the line. This is just plain amateur grade software development. If you'd push such an half-baked, insecure feature like this in a "normal", non-startup corporation, you'd immediately get fired for this. This level of unprofessionalism developing features with somewhat trivial exploits is just unacceptable for a product like this. There should be QA, there should be internal security testing before a feature like this even reaches its alpha stage.

  • @NicolasSilvaVasault
    @NicolasSilvaVasault 16 часов назад +111

    i really want to jump to zen browser after this

    • @mob_builds
      @mob_builds 14 часов назад +6

      Yoo, It's slowly becoming my daily driver

    • @Seven-ez5ux
      @Seven-ez5ux 14 часов назад

      Highly recommend. Been daily-ing it for a month+ now. No complaints.

    • @RomanAvdeevX
      @RomanAvdeevX 13 часов назад +9

      I use it daily, it's amazing

    • @googleisevil4115
      @googleisevil4115 12 часов назад +6

      I love it, few issues that need to be ironed out still

    • @lokuo5523
      @lokuo5523 10 часов назад +2

      Zen is amazing especially on windows, Arc on windows is just not ready yet

  • @sutharjay1
    @sutharjay1 10 часов назад +22

    Zen >>> Arc

    • @wvovaw3052
      @wvovaw3052 7 часов назад

      No, bro. I've been using Zen for a while an it's not even close to Arc. It lack some Arc's killer features like "Peak". Also I ran Zen on a pretty old machine and it seemed to leak some memory. I returned to chromium after 3 weeks of using Zen and have no regrets. Hope Zen become a real thing eventually!

    • @firestormjupiter
      @firestormjupiter 6 часов назад +3

      Zen is in alpha and mostly developed by a solo dev, give it some time and it will be more stable and could quite possibly surpass arc in many aspects

  • @GameOn0827
    @GameOn0827 12 часов назад +7

    Turns out the 10x dev was right, they didn't need those investors.

  • @JakobRossner-qj1wo
    @JakobRossner-qj1wo 8 часов назад +5

    The thing that is really shocking to me is that they dont follow their own privacy policy by logging the websites you visit. This is a no go for me and I dont want to have this piece of spyware on my PC.

  • @mohitkumar-jv2bx
    @mohitkumar-jv2bx 15 часов назад +66

    I just can’t understand how can someone use a closed source browser. And the one which needs to be logged in.
    Man if thats not a confirmation for “they are f***ing taking your all data” i just don’t know what can be 😂

    • @anonymousalexander6005
      @anonymousalexander6005 12 часов назад +1

      It’s easy to check what telemetry they collect, but I definitely won’t do that, I’m good enough with Edge and Tor/Mullvad on the side when I need it

    • @realivanjx
      @realivanjx 5 часов назад

      wait you cant use arc without logging in? i use linux so i cant test it

    • @DavidHust
      @DavidHust 59 минут назад

      Is there another way to sync data between devices? What data do you think they are about enough to "take"?

  • @7heMech
    @7heMech 8 часов назад +5

    This is an example of an extremely poor use of firebase, since it doesn't even follow first thing in firebase docs (check if user is writing and reading for their id)

    • @pokefreak2112
      @pokefreak2112 8 часов назад

      SaaS should be idiot proof, that's the whole reason to use it. If you get these security vulnerabilities by default and need to manually hunt all of them down that's just bad product design.

  • @liam-dimpr
    @liam-dimpr 16 часов назад +53

    2:05 "firebase was the cause".
    No. This is not true. It's not a firebase specific issue. It's an arc developers skill issue - they did authn by user id, instead of authn by signed/verified token, in firebase security rules.
    Firebase and cloud is generally a little unbased, but it's not the root cause.
    It's literally arc devs made code which does authn by user id instead of a signed/verified token.
    EDIT: Exchanged with theo on x, and actually it's probably not fair to say this isn't somewhat firebase specific issue, since the firebase docs do have unacceptable security rule examples where it includes rules which fail to include request.auth none checks which would even bypass request.auth.uid checks and that's a bit crazy and definitely going to increase the rate of security issues where skill or lapse in judgement occurs.

    • @t3dotgg
      @t3dotgg  16 часов назад +42

      The official example in the Firebase docs is vulnerable to this exploit.
      Three other websites have been found with the same exploit since. Eva has a long post about how common this particular config is.

    • @zuma206
      @zuma206 14 часов назад +15

      If you don't see how firebase enables this specific type of issue you shouldn't be using firebase. And if you do see how firebase enables this specific type of issue then you also shouldn't be using firebase.

    • @cobrasys
      @cobrasys 13 часов назад +3

      @@t3dotgg Then that's a Firebase _docs_ issue, not a Firebase _functionality_ issue. Postgres also has row-level security, but it's not on by default.
      If what you're saying is that having row-level security be the *only* security mode is a bad feature, then I would agree with you, but the fact of the matter is that a properly configured Firebase store would not be subject to this exploit. The "cause" was the Arc devs' use of Firebase's less-than-ideal defaults, due to either ignorance or carelessness.

    • @benargee
      @benargee 12 часов назад +3

      ​@@cobrasys ok but it's still a Firebase issue. Theo didn't specy what part of Firebase had an issue. They should teach users to use security features securely. Don't downplay it.

    • @cobrasys
      @cobrasys 12 часов назад +3

      @@benargee They absolutely should teach their users how to use their product securely, no doubt about that, but saying it's _purely_ a Firebase issue is misleading. The product itself doesn't have a vuln or a flaw.
      Let me put it another way: if a stapler manufacturing company doesn't put "don't staple your buttcheeks together" in the manual, when someone invariably does it, you wouldn't say it was a _stapler_ problem, would you?

  • @luvmakin9342
    @luvmakin9342 6 часов назад +5

    I am ever so stunned with RUclipsrs talent to come up with the most clickbaity title! Thoroughly impressed! 🎉

    • @luvmakin9342
      @luvmakin9342 6 часов назад +1

      I think I know the process now - it's basically half truth. The most unhinged sh*t that you can say - take it out of context and voila there you have it!

    • @DavidHust
      @DavidHust 54 минуты назад

      Loses credibility from the jump.

  • @unknowntotherestoftheworld
    @unknowntotherestoftheworld 8 часов назад +5

    zen >>> plus its firefox so doesnt have to deal with the chrome manifest changes and runs on linux

    • @NabekenProG87
      @NabekenProG87 6 часов назад

      My boy Linux is always left behind 😢. Automatically makes Zen better

    • @unknowntotherestoftheworld
      @unknowntotherestoftheworld 6 часов назад

      @@NabekenProG87 there's even nix flakes for it while they're working on getting a proper nixpkg for it

  • @rackyboi
    @rackyboi 4 часа назад +3

    A browser that can inject remotely JS and CSS in any website is a security nightmare even without the bug

  • @JonGretarB
    @JonGretarB 6 часов назад +2

    I loved Arc. I loved the workflow of it. However… there are a few problems. Big one is the problems mentioned in the video. The second problem is the user login requirement. The third problem, and the reason I stopped using it before I watched this video, is the chromium backend. Chromium is just not compatable with things that run of batteries. The energy use is just crazy. There is a noticeable difference in battery life when you use a chromium based browser. We are talking about hours in a day.

  • @Philipp..
    @Philipp.. 6 часов назад +2

    There is no way I will give Arc another try especially because you can't use it without an account and they clearly don't care about user privacy at all. Maybe now they start to care about security but that shouldn't be an afterthought...

  • @iLiran
    @iLiran 6 часов назад +2

    But is it really Firebase to blame for? To me, it seems like the developer fault (at least in this case).

  • @gearboxworks
    @gearboxworks 3 часа назад +2

    Can you create a Boost to get rid of that damn cat?!? 😒

  • @doubletroublemcmuffin
    @doubletroublemcmuffin 9 часов назад +2

    These ads are so much better than the skits

  • @ramtennae
    @ramtennae 14 часов назад +2

    patiently waiting for Theo to zap the cat

  • @tato-chip7612
    @tato-chip7612 8 часов назад +19

    >bro uses meme browser and gets meme results
    And this shit is why i never use anything other than firefox.

  • @sanjaux
    @sanjaux 6 часов назад +1

    You’re telling me boosts are just user friendly, unsafe local overrides?

  • @Strammeiche
    @Strammeiche 5 часов назад +1

    I tried arc a week ago and really liked it. I'm somehow not sure anymore but the zen browser looks quite good too.
    But as the browser is the most important software after the OS itself I may stick with the big ones as they are probably more secure.

  • @dipereira0123
    @dipereira0123 15 часов назад +1

    Man see cat following the mouse, man laughs, man like!
    Im sold already, where can i get it?

  • @wlockuz4467
    @wlockuz4467 5 часов назад +1

    Screw the exploit, I wanna see their Firebase bill.

  • @sidewaysdesign
    @sidewaysdesign 14 часов назад +1

    Nice to see the return of Neko the Cat after all these years...

  • @wlockuz4467
    @wlockuz4467 6 часов назад +1

    I can't with the kitty running around 😭

  • @animanaut
    @animanaut 6 часов назад +1

    ...we checked the logs... yeeeaaaahhhh, riiiiiiiight

    • @DavidHust
      @DavidHust 53 минуты назад

      What could they say instead if it were true to get people to believe them?

  • @artemisfowl127
    @artemisfowl127 16 часов назад +4

    oh no, arc no more! Hopefully you get through it!

  • @letruxux
    @letruxux 5 часов назад +1

    change the title to 20k!

    • @oSpam
      @oSpam Час назад

      Theo didn't pay 20k though, he paid 2k... Don't make it more clickbaity then it already is

  • @JournalRahmen
    @JournalRahmen 16 часов назад +1

    How did u add the kitty

    • @wyndmill
      @wyndmill 16 часов назад

      eva's blog has that

  • @AKABeestYT
    @AKABeestYT 3 часа назад

    That moment when not open source.
    I'll stick to Zen thanks

  • @hqcart1
    @hqcart1 10 часов назад

    that what happens when you try to reinvent the wheel..

  • @aiamfree
    @aiamfree 15 часов назад +1

    hmm isnt this how Supabase works as well?

    • @zuma206
      @zuma206 14 часов назад

      yep, though at least supabase provides more than just a firebase clone, whereas firebase only provides firebase

    • @aiamfree
      @aiamfree 14 часов назад

      @@zuma206 lol good one… well time to check the policies just in case I guess !

    • @doc8527
      @doc8527 14 часов назад

      Nope, in case if other "inexperience" devs were wondering the same thing.
      Supabase at the end is PostgreSQL. Hence, the part you feel familiar with is a combination of "row level security (RLS)" + "anonymous user right".
      Afaik, RLS by default is on with empty. That means unless you make an exception rule, anonymous has no right to do anything.
      You can still go the traditional route to have your own server and api with private key to handle all the user request, that will bypass the RLS.
      The anonymous key thing is just something allows you to skip the server, directly access the DB from client, but you move all the "heavy lifting (auth check, etc)" to database level. If you are doing something simple like read-only, maybe it's fine. And it could be insanely fast as you skip the server layer. But whenever thing becomes complex, it's likely a trap and can cause security issue, because it's just more hard to handle all the thing via sql statement and DB level privilege controls, comparing to programming languages and server.
      Where the Firebase default seems like opposite to RLS, you have all rights to do anything unless you make rule to against it. That's a security nightmare to handle.
      Hence the problem here for Arc team is that their engineers is naïve enough to decide offload all the things into DB privilege controls rather than having a server in front and do the heavy lifting. Ideally, they should have both! Server as one layer of protection and DB level (which they currently using) as the final level of protection.

  • @SanyaZol
    @SanyaZol 2 часа назад

    5:27 Ublock origin is good not only for hiding annoying elements, but also for applying ustom CSS rules (using it's selector:style(color:red) syntax)

  • @aiamfree
    @aiamfree 15 часов назад

    I imagine they’re not using IndexedDB because of a cloud sync or something?

  • @rfigueiredo
    @rfigueiredo 2 часа назад

    They were more responsible than CrowdStrike hahaha.

  • @wrux
    @wrux 8 часов назад +1

    I'm bored of Arc's sidebar tabs taking up 15% of the screen realestate on my 13 inch display. Paitently watring for Zen browser to become stable enough to use

    • @opposite342
      @opposite342 8 часов назад

      it is technically already fine and less jank than using firefox's vertical bar css (which is what im kind of doing on my laptop, while on my main machine I use zen)

    • @eduardofernandez2697
      @eduardofernandez2697 7 часов назад

      You can get the same experience in base Firefox with extensions. Zen it's just a pretty coat of paint that might cost you 2k one day 😉

    • @wrux
      @wrux 6 часов назад

      @@opposite342 Yeah nice. Maybe I should update and try it out again

    • @zakajus
      @zakajus 5 часов назад

      I've been using it on my Linux laptop and Windows desktop since Theo dropped the video about it. The only real issues I've encountered has been 1 crash and the theme store going offline for a bit, so all things considered it's very usable. Also, the compact mode is a fucking blessing for smaller displays once you learn the shortcuts.

  • @arcanernz
    @arcanernz 33 минуты назад

    Seems like a bad default on firebase side. They should have security by default not opt in security. But then it would be difficult to adopt for beginners since you have to do all these configurations just to use it which I think is worth it in the long run but is still a barrier to entry.
    It’s like a classic tug of war between engineering and marketing. You need both to be successful but it is most definitely a wrong call for this situation.
    If enough ppl stop using firebase they’ll be forced to change.

  • @kellymoses8566
    @kellymoses8566 39 минут назад

    The Browser Company has no business model at all. I don't get it. And a bug this bad should get a company just plain shut down.

  • @InfiniteQuest86
    @InfiniteQuest86 53 минуты назад

    ARC is probably way too small for state actors to care. But after this, lol, who knows....

  • @theDanielJLewis
    @theDanielJLewis 15 минут назад

    Dang good Browserbase ad! I love that you just _showed_ what it does and that was the best sales pitch!

  • @user-pt1kj5uw3b
    @user-pt1kj5uw3b 33 минуты назад

    Yeah, I'm not gonna use this shit. The fact this could happen in the first place makes me lose faith in the project.

  • @brownpaperbagyea
    @brownpaperbagyea Минуту назад

    Am I crazy or does it seem kinda foolish to use these obscure browsers?

  • @frankymaca
    @frankymaca Час назад

    It's always nice to see fellow programmers help each other when companies don't make it right! Love your videos btw

  • @DevUser-bh9if
    @DevUser-bh9if 4 часа назад

    Theo not talking about browsers challenge (IMPOSSIBLE)!

  • @Younex
    @Younex 7 часов назад

    The cat following the cursor is so cute damn 🔥🔥🔥🔥

  • @gkiokan
    @gkiokan 6 часов назад

    The cat is awesome!

  • @user-pt1kj5uw3b
    @user-pt1kj5uw3b 29 минут назад

    Clown browser. Cool UI though.

  • @bryangichuru9
    @bryangichuru9 Час назад

    If it isn’t my arch nemesis Firebase. Too easy to make a security flaw and it’s never your fault

  • @davidb.6271
    @davidb.6271 7 часов назад

    So you've been Arced and you've been Clerked

  • @PhilipAlexanderHassialis
    @PhilipAlexanderHassialis 15 часов назад

    But it all boils down to having access to someone else's creator/user/whatever Id. Now, arguably, this could be accessed by a mitm or something else that can listen to a machine's calls. It is impressive but I was kinda expecting something a bit more explosive.
    Edit: I just reached the point of the video where you practically advertise your own user Id to the public. Amazing security concept, great success! Whoever thought of that should be awarded engineer of the year!
    That being said, good job on researching the browser and even better job to keep the white hat on.
    P.S. so people *really* use firebase huh? TIL.

  • @Mallowigi
    @Mallowigi 7 часов назад

    Very interesting video, but was the clickbait really necessary?

  • @AnonYmous-yu6hv
    @AnonYmous-yu6hv 3 часа назад

    they should remove that account option

  • @thijskoerselman
    @thijskoerselman 10 часов назад

    I have been developing on Firebase for many years, but I always disable direct writes from clients, and only allow them to read. All mutations flow through API endpoints instead. It takes away the out-of-the-box optimistic updates, but retaining this kind of control makes me sleep better.

  • @tea_otomo
    @tea_otomo 7 часов назад

    That's why I don't touch hyped browser with "flashy" new features

  • @wlockuz4467
    @wlockuz4467 5 часов назад

    This would not have been a problem with Ladybird.

  • @nikilk
    @nikilk 8 часов назад

    Well it’s cool that these things are being caught. No software is perfect when it comes out. Arcs focus was purely around the UX and I bet they’ll improve their internal implementation with champions like Eva

  • @trad4097
    @trad4097 9 часов назад

    A like for you, for matching the initial payout

  • @ValipPowa
    @ValipPowa 4 часа назад

    arc is fucking horrible lol i just could never translate to it

  • @rns10
    @rns10 8 часов назад

    If they could just stop asking for emails to use a browser. Its such a issue.
    You want to increase your browser user count, but then block them for an email?

  • @joschkazimdars
    @joschkazimdars 14 часов назад

    I'm actually binging all your videos to get insights into the tech industry that I many years desired.

  • @ItsError430
    @ItsError430 16 часов назад

    Thats amazing im happy they handled it well afterwards. Congrats on eva and just wow 😂

  • @BrentMalice
    @BrentMalice 11 часов назад

    WHERES THE SKIT THEO IM ONLY HERE FOR YOUR ACTING SKILLS

  • @voidmammal
    @voidmammal 9 часов назад

    hmm yeah i think im going to stick to firefox XD

  • @sumitpurohit8849
    @sumitpurohit8849 12 часов назад

    Torvalds: My kernel got hacked

  • @audrey_santoso
    @audrey_santoso 15 часов назад

    wow maybe i should change my browser

  • @eduardofernandez2697
    @eduardofernandez2697 7 часов назад

    This seems like a `${whatEver}base` issue.

  • @jasonc6241992
    @jasonc6241992 13 часов назад +7

    Firebase is real infra 🗣️

  • @ram_chopade_cr
    @ram_chopade_cr 3 часа назад

    Just use chrome👍

  • @termorey
    @termorey 8 часов назад

    And we ❤️ Eva

  • @farzadmf
    @farzadmf 14 часов назад

    OMG, that cat!

  • @realtitedog
    @realtitedog 15 часов назад

    Common Arc L

  • @samoart
    @samoart 16 часов назад

    🎉 first

  • @2u841r
    @2u841r 12 часов назад

    好き eva 😍

  • @kronjobkronicles
    @kronjobkronicles 16 часов назад

    nice

  • @mopifyz
    @mopifyz 16 часов назад

    hi

  • @ChumbleIsChill
    @ChumbleIsChill 16 часов назад

    e

  • @cognominal
    @cognominal 5 часов назад

    the Browser Company blog entry on the subject is date September 20, that is before the incident. WTF.

    • @TheRealCornPop
      @TheRealCornPop 3 часа назад

      They were made aware of it on Aug 25th

  • @truthalwaysprevails662
    @truthalwaysprevails662 16 часов назад

    Kind of expected it sooner rather than later, Arc had just too much hype around it and when they initially launched the browser exclusively for Apple and deferred the Windows launch for later, that was kind of a red flag for me. Just my opinion.

    • @firestormjupiter
      @firestormjupiter 6 часов назад

      It’s like they built their business model around both the good and the bad of apple. From what I hear closed ecosystem (in a browser!) is a thing in Arc and there are people using various complicated scripts just to export passwords and data

  • @sorrynotsorry8224
    @sorrynotsorry8224 16 часов назад +2

    Vivaldi > everything.
    Just my opinion of course, but I'm yet to see a feature in a browser I want or think is cool that Vivaldi cannot do.

    • @zuma206
      @zuma206 14 часов назад

      Vivaldi is closed source though, firefox ftw. open source and big-tech free

    • @secretzpt176
      @secretzpt176 10 часов назад

      Vivaldi was too slow for me, Zen so far is a great alternative

  • @gro967
    @gro967 14 часов назад +4

    Nice blog post, but it would be much easier to read, if eva would learn to use uppercase characters...

  • @Kendoujo
    @Kendoujo Час назад

    I'm a bit thick so can someone confirm I understood correctly. It went like this right?
    1. Create your own Boost (like a tampermonkey script), to do whatever you want.
    2. Update the creator ID field to that of a different user.
    3. That boost has now been 'transferred' to that other user and will run whatever you set it up to do
    is that it? If so that seems like a major dumb dumb like how do you miss something like that haha

  • @kisaragi-hiu
    @kisaragi-hiu 11 часов назад +1

    10:43 You'll notice you just wrote an SQL injection. The appeal of letting your database service handle it for you is that I can just configure the service correctly, hopefully more easily than code, and automatically eliminate chances of my own errors breaking security. …This of course becomes a moot point when the configuration becomes just as complex as the code would've been and there's broken defaults and footguns everywhere.

    • @teejaded
      @teejaded 11 часов назад +1

      Query parameters aren't that hard to use.

    • @djbremsespor
      @djbremsespor 5 часов назад +1

      No, he did not write an SQL injection.
      It is worth to go back and watch the video again from 9:15 to 9:55 and see how careful and security aware he is.
      You will then notice that he specifically wrote a super pseudo / non-SQL example and clearly stated that you would want to validate / sanitize the new username also.

  • @koz
    @koz 14 часов назад

    In my world, the cloud is not allowed.

  • @CripsyFries
    @CripsyFries 16 часов назад +11

    1 view in 31 seconds?? bro fell off

  • @whoman0385
    @whoman0385 6 часов назад

    a browser shouldnt even need an account

  • @JonathanRose24
    @JonathanRose24 15 часов назад

    Love Arc and the Browser Company and they way they ultimately handled this, makes me love them even more

  • @akam9919
    @akam9919 10 часов назад

    Yeah, yeah, terrifying browser exploit, who cares? Look at the little kitty!