Google Releases Chrome 6, Pays $4337 In Bounties
Trailrunner7 writes "Google has released a new version of its Chrome browser and has included more than a dozen security fixes in the update. The new version, 6.0.472.53, was released two years to the day after the company pushed out the first version of Chrome. Google Chrome 6 includes patches for 14 total security vulnerabilities, including six high-priority flaws, and the company paid out a total of $4,337 in bug bounties to researchers who reported the vulnerabilities. A number of the flaws that didn't qualify for bug bounties were discovered by members of Google's internal security team." (Read on for more, below.)
Also on the Chrome front, morsch writes "Chrome 7 for Linux is planned to tie in with the Gnome Keyring and the KDE Wallet to securely store saved browser passwords. Users of the stable version of Google's Webkit-based browser might be surprised to find out that, so far, passwords are stored on the hard disk as clear text. On Windows, Chrome has always used a platform-specific crypto API call for encrypted storage. The corresponding Linux function was never implemented — until now. Unstable versions of Chrome 7 still disable the feature by default; it can be enabled using a parameter."
Google's honoring a password security effort in Linux, and at least calling a cyrpto function in Windows... but why no support for the OSX Keyring?
so, hunt down big companies willing to spend money advertising that they're sponsors of Chrome Bug-hunt.
Otherwise, you won't have that kind of money just waiting to be spent for every little null pointer dereference fix.
Support FSF: Stop thinking with your wallet, and think with your imagination. (cc/non-commercial)
What? Google's not big enough? They need to find sponsors in order to make money? Oh, wait a second...
so, hunt down big companies willing to spend money advertising that they're sponsors of Chrome Bug-hunt.
Otherwise, you won't have that kind of money just waiting to be spent for every little null pointer dereference fix.
Lets get that massive super multi billion dollar every-national company GOOGLE to sponsor the Chrome Bug-Hunt. Wait... what?
Moved to http://soylentnews.org/. You are invited to join us too!
$ 4337 in bounties? So thats one real hard bug $ l337 and $ 3000 worth of bugs that the skript-kiddies could have got.
Does Chrome 6 have print preview? Can you open files with helper applications without having to delete them manually later? Do Flash videos play the audio correctly?
What a fool believes, he sees, no wise man has the power to reason away.
Users of the stable version of Google's Webkit-based browser might be surprised to find out that, so far, passwords are stored on the hard disk as clear text.
I see. So that's why I keep my passwords stored in my head. No virus that can live in my head can read my passwords out of there, AFAIK.
Let q be a radix > 1. I am in ur base-q, killing 10 d00ds.
I just looked at the article briefly, and it states "A second high-priority flaw, a sandbox parameter deserialization error, was discovered by two members of Adobe's Reader Sandbox Team." What the--Adobe has a security team? That's crazy talk!
How does this goggle company plan to stay solvent throwing money around like this? Don't they know we are in a recession?
Any reasion for the version-number bloat? I mean, I guess it looks a bit cooler next to IE 8, but I don't really think people are that naive.
R.Mo
Comment removed based on user account deletion
It's nice that they're paying but if that's $4337/14 = roughly $310 per bug you'll just have to forgive me if I don't quit my day job to focus on debugging Chrome.
These posts express my own personal views, not those of my employer
uh... they did. that total is the sum of multiple payouts.
Maybe they could sell some advertising space on their website. I hear they get a lot of traffic.
Help stamp out iliturcy.
I went from Netscape to Firefox to Opera to Chrome, without ever stopping at Internet Explorer (except at work, where it is the default).
I have to say, though, that I've removed everything but Chrome (and the ubiquitous and hard to remove IE8) from my home computer. It really is an excellent browser.
You could also use Keepass. Not as safe as your head, but can store more than a few passwords.
Give me a break. You turn a bug bounty into a statement on American values. Your gameshow references are completely baseless and random. What a load of crap!
So you removed them all but Google. You're saying to yourself, if google reads my mail, and stores my searches, and takes pictures of where I live, do I feel like I can use their browser? You trust Google knowing this ?? YYu are one fucking idiot !!
That's 0.0.082.78 per day!
No virus that can live in my head can read my passwords out of there, A.F.A.I.K.
(emphasis mine)
Now THAT's an open mind!
*ducks*
First thing I thought when I saw 4337 was "What the fuck is Aeet?"
This is one of the dumbest arguments I've ever seen on slashdot.
"Discover flaws in Google's Chrome... and you get paid. But the entire panel of winners gets less than $5,000 for their trouble... Something's not right in the equity here."
Well, you could always find flaws in Firefox, Windows, IE, etc and get paid nothing if you like.
$4,337 > 0
I say good for Google. What do you want from them, $43,370? $433,700? They're already paying more than anyone else.
my karma will be here long after I'm gone
Give ME a break. I can't believe the "bug bounty hunters" would really sell a Google vulnerability for a thousand dollars - I used to mindlessly wipe asses and roll people over for two weeks for that. It's an insult to their intelligence considering the amount of work they put into the penetration-testing/logic analysis involved. An average-sized college internet-portal exploit would be worth $1,000... let alone one of the largest web services company in the world. I think $10,000 is much more appropriate.
Mozilla also pays bug bounties.
That butt-face dude makes 5 grand an appearance, just for showing up. He looks stupid. Must be to only get 5 grand.
Paris
Because I am the whore you always wanted
We've never paid based on the actual value of services. In a free economy, prices should be set by the supply and demand. Even if the demand for a service is great, the price may stil be incredibly low due to high supply. Like water. Can't quite live with out it. What kind of value does that bring to you? More or less than a huge flat screen tv. Less?? But isn't water more valuable to you??!!!
Explaining the economics of game shows, is a bit too much for me at this hour. Safe to say, they contestants aren't paid a bunch because they are rare. Its not a free market.
And I'll just end by pointing out you presenting a false choice. Most people would decide to pay many regular workers significantly more, rather than pay a few game show contestants more. Its not their choice, and its not anyone's choice.
Well.. maybe. Or Maybe not. But Definitely not sort of.
FYI your linux logins on Ubuntu are stored in this file: /home/username/.config/google-chrome/Default/Login\ Data
just do "strings Login\ Data"
and you have those passwords. :(
Once it works with Murrine-ARGB and the Ubuntu appmenu bar, i don't see anything to pull me back to Epiphany again. It'll be just as native, and three orders of magnitude more performant on JS.
I've just confirmed the above, and it's the same on other Linux distros, not only on Ubuntu.
I hope this is some dreadful oversight! An application of Chrome's stature cannot be storing passwords in the clear by design, surely ...
What're you expecting here? Google to pay out bigger? I imagine that people would submit these flaws with or without the bounties. Nobody's forcing them to search them out. I'm amazed by the fact they're willing to pay anything at all.
If you aren't suspicious of your government's actions, you aren't doing your job as a responsible citizen.
As a Linux application developer who has used keyring/kwallet for saving secure passwords in the past. I'd recommend not to use them.
Various different distributions have different versions of the these utilities and their libraries. There are so many variations that it becomes hard to support all versions. Most desktop linux end users have never used them and when they see a warning window popping up (which these utilities tend to show). They cancel the window rather than going through the authentication process.
Just my 2 cents.
GNAA is a giant pain in the ass.
You're on Linux, the most trusted, secured and freshest OS in the universe !!
Why do you care if Google leaves your creds in the clear? If someone can read them, you are already OWNED !!
Yours,
Shirley, the one and only Summer's Eve girl
What's your point?
If you ask browser to remember passwords, they will be stored somewhere in plain text or in some form that can be decrypted. Browser has no way to remember passwords without saving them somewhere. If passwords were stored on Google servers, then it would be an issue.
like a mirror,
only not really,
unless you shine it up,
you can see yourself in it.
You could also use Keepass.
Really bad name for a program meant to keep something.
You're just mad because you didn't think to join while it was still cool.
> Do Flash videos play the audio correctly?
// ==UserScript==
// @name YouTubeWMP
// @version 1.0
// @description Replaces Flash player with WMP in YouTube.
// @run-at document-start
// @include http://www.youtube.com/*
// ==/UserScript==
Yes. The video on the other hand, as in all browsers, is a different story. We're still waiting for the fix from Adobe. In the meantime, you can use the following user script:
----(start of file)----
flp=document.getElementById("movie_player");
flp.outerHTML = "<EMBED type='application/x-mplayer2' width='" + flp.width + "' height='" + flp.height + "' src='" + unescape(flp.getAttribute("flashvars").match(/&fmt_url_map=[^&]*%7C([^&]*)/)[1]) + "' autostart='true' autosize='-1'></EMBED>";
----(end of file)----
This script is for YouTube, you can make similar ones for other sites easily. Just use the resources panel in the developer tools to figure out where to get the link to the flv stream.
> AFAIK
What about rootkits?
Some kind of encryption as obfuscation, DRM-style, is still better than just plain text. One of the tricks used by people who steal hard drives is to try every possible chain of subsequent bits as a password. It's only at most a few trillion tries (less than brute-forcing an 8-char alphanumeric password, and quite feasible with a botnet or a few days of time), and often as few as a few billion, but it gets passwords right quite often. Encryption would defeat this attack.
At least the Linux version for x86_64.
Try it
Maybe Computers will never be as intelligent as Humans.
For sure they won't ever become so stupid. [VR-1988]
You question the American value system, and you invoke game shows. And you use the word "Discover" twice, which is awfully close to "Discovery", as in "Discovery Channel". You haven't posted a manifesto on your web site recently, have you?!
(ducks)
There is no universal ISO IEEE Regulatory standard for software version numbers, it's meaningless to compare them. Personally I mostly ignore them and look at the release or file date.
If you don't risk failure you don't risk success.
It does not defeat anything. Decryption password is stored in same location as encrypted data.
So that when someone steals your laptop they don't get access to your passwords/CC numbers? The only security that Firefox's master password provides that Chrome doesn't is if you happen to leave your computer logged in, unlocked and unattended but just happen not to have entered your master password into Firefox yet.
Firefox, on the other hand uses a password that protects them either when you try to view the passwords through the dialog box, OR when the passwords have to get loaded in order to be used by a site.
Not by default it doesn't - "Use a master password" is unchecked by default, meaning very few people are actually protected by it.
I see. So that's why I keep my passwords stored in my head. No virus that can live in my head can read my passwords out of there, AFAIK.
No, dude! That's what they want you to think!!! Quick, forget all your passwords and go stand next to somebody that's thinking about windows xp...
>I see. So that's why I keep my passwords stored in my head. No virus that can live in my head can read my passwords out of there, AFAIK.
In other news Hacker Geneticists start breeding Meningitus that can talk...
Unicode killed the ASCII-art *
I have been using 6 Beta for two months because of the instabilities of version 5.x. Typing something in the location bar was often enough to crash the browser. Chrome is not complete or flexible as the the other browsers on the market but for sure is the faster. This only thing makes me to prefer chrome over the others.
"I used to mindlessly wipe asses and roll people over for two weeks for that." Whats up, fellow Nursing Assistant? :(
No portion of this post may be rebroadcast without the express, written consent of Major League Baseball.
It's a pretty big showstopper for me, since it makes using it at work extremely difficult to do. I do wish it had its own proxy engine like Firefox does.
A password that only lives in your head is of little use. Sooner or later you'll have to use it somewhere, and a virus can easily read it from the keyboard buffer / form field. Maybe it's even more likely it reads the password from a form than from where it's stored at the disk. While there are A LOT of ways to store passwords on disk, it's pretty limited in the ways you can use them.
It's The Golden Rule: "He who has the gold makes the rules."
You might want to do some research before you start casually using the term "bug chasers". Hint: it already has a meaning, and it's almost certainly not what you think it is.
And yet they did. That must really shake your world view.
Believe it or not, when normal people discover a vulnerability and their options are "run a bonet" and "tell the manufacturer," most of them tell the manufacturer. Getting $1000 for it is an added bonus, not the incentive to action.
True, it's not going to create a whole new generation of professional bug bounty hunters living off their bounties, but that was never the intent. If they wanted to hire an army of extra bug hunters they'd put you on the payroll. If you're looking to get rich, do something else. If you're into it for the challenge or to be helpful or you happen to be mucking about with their browser as part of your day job, make a little extra money as Google's way of saying "thank you" for doing the right thing and helping them to make their free product--one you evidently use, if you're finding bugs in it--a better one.
If that's not good enough for you, well, fine. Don't look for bugs. Don't pass Go, don't collect $1,000. Your time is apparently better spent trying to get yourself a spot on Wheel of Fortune.
This is one of the dumbest arguments I've ever seen on slashdot.
You must be new here.
Firefox can optionally use a master password to encrypt the other stored passwords. You have to enter the master password once per session (or, if you prefer, every time you access the store). This doesn't prevent a determined attacker who has root from getting those passwords (he could use a keylogger to get the master password, etc.). But it does mean that sheer physical access is not enough, so if someone copies your Firefox profile, or restores it from an old HD, the passwords still would need to be decrypted. If I understand correctly, using the Gnome login keychain is just as safe as the Firefox master password, it's stored in an encrypted fashion and decrypted at login (using the user's password, I guess?).
Switch back to Slashdot's D1 system.
The decryption password isn't stored anywhere. You have to remember it. But remembering one password beats remembering 10, 20 or 100.
Switch back to Slashdot's D1 system.
The password-required feature is logging in to your user account. Chrome uses the Windows encryption facility that piggybacks off of Windows user logins.
Not really, it's not. It gives a false sense of security when in reality the password is going to be easily retrieved from disk by a hacker. The only way to properly secure passwords is with another password, and proper encryption that uses this password somehow to derive its key. See: http://developer.pidgin.im/wiki/PlainTextPasswords
Yup. If the browser can decrypt them, so can a virus.* But it is well-known that most people suck at remembering passwords and the security risk of choosing bad passwords is worse in most cases than that of the browser remembering them. And if the browser doesn't remember them, people *will* use easy to guess passwords, and are economically justified in doing so.
* Note: you can make the area where passwords are stored privileged so that the kernel can decide to only let the browser in. For this to work reasonably well, you'd also have to make sure that viruses can't infect the browser. It's possible, but neither Windows nor Linux do this, although I gather that the Mac does. But it doesn't run the software I want to use on the computer I want to use, so yeah.
It uses Keychain on OS X AFAIK, and there's a 1Password plugin for it so you can use that as well.
Try using http://lastpass.com/ for Chrome passwords - it encrypts the passwords on disk (of course), has a lot more features, and is a cross-browser plugin for Firefox, IE, Safari as well as Chrome, on Windows/Mac/Linux etc. It also has paid-for versions for iPhone, Android, etc, and syncs the passwords to the cloud.
You could also use Keepass. Not as safe as your head, but can store more than a few passwords.
this
I use keepass and dropbox to sync the keepass database between my most used computers. The downside is that I can't access stuff i don't remember when i'm not at one of those computers. Before keepass i just used 3 or 4 different passwords for every site.
$4,337 > 0 I say good for Google.
I say it's too much. Should have been $1337
If you ask browser to remember passwords, they will be stored somewhere in plain text or in some form that can be decrypted.
It's called a password-protected, encrypted keychain, and it's hardly new technology.
It's nice to see the broader technical community getting recognition from Google as.... ...bringin' the HEET
It uses the Keyring on OSX which is secure AFAICT
Exactly - it's a way of the company saying thanks and that they appreciate the efforts of the bug hunters, which is a refreshing change to the attitudes of most companies who just want to pretend bugs don't exist because fixes cost money. They could probably get plenty more goodwill than those other companies just by sending out a hamper of beer and gaming snacks, or a few free pizzas, so the fact that they're paying out a grand is a very nice thank you. It's a reward for regular people, not an incentive for criminals to change their ways.
It was inspired by Pulp Fiction.
The "bounty" is mostly a marketing instrument, and not so much a reward (just a nice gesture). The rationale is: "our software is so good that we can afford to give out bounties for the few bugs that you will find". A message to the majority of users, not to potential bug hunters. :-)
To see the passwords you need to enter the master password again, else the passwords can be used, but not revealed, so as soon as firefox is closed/crashes the passwords will be useless..
You dummorz can't even R33d???
The incentive of money destroys nearly any type of creative work (e.g., bug finding, vulnerability testing, etc). The lower Google keeps the $$ reward for the bug, the more likely they are to get people who are in it for the experience, professionalism, notoriety, or satisfaction of bug finding ... not the money itself. I bet Google would prefer to have the former type of people on their 'payroll' as they will likely be more loyal, find bugs deeper in the code, and overall contribute more to the project than someone who sees it as a paycheck.
-ryry
be posting a bug bounty for bugs of other browsers?
Last time I've checked IE and Mozilla does not require any password to be set to remember passwords. Mozilla does have master password, but the only time I was confronted with it was when I didn't use it and lost all my IceDove passwords during upgrade. Konqueror can use Kwallet, but it is most annoying thing in KDE.
Not sure what your point is. The master password function in Firefox is optional. If you don't use it, you don't have to remember a password. If you do use it, you do have to remember a password, since obviously Firefox doesn't store it anywhere.
Switch back to Slashdot's D1 system.