Slashdot Mirror


Google Releases Chrome 6, Pays $4337 In Bounties

Trailrunner7 writes "Google has released a new version of its Chrome browser and has included more than a dozen security fixes in the update. The new version, 6.0.472.53, was released two years to the day after the company pushed out the first version of Chrome. Google Chrome 6 includes patches for 14 total security vulnerabilities, including six high-priority flaws, and the company paid out a total of $4,337 in bug bounties to researchers who reported the vulnerabilities. A number of the flaws that didn't qualify for bug bounties were discovered by members of Google's internal security team." (Read on for more, below.) Also on the Chrome front, morsch writes "Chrome 7 for Linux is planned to tie in with the Gnome Keyring and the KDE Wallet to securely store saved browser passwords. Users of the stable version of Google's Webkit-based browser might be surprised to find out that, so far, passwords are stored on the hard disk as clear text. On Windows, Chrome has always used a platform-specific crypto API call for encrypted storage. The corresponding Linux function was never implemented — until now. Unstable versions of Chrome 7 still disable the feature by default; it can be enabled using a parameter."

33 of 177 comments (clear)

  1. Yep. My practices are justified. by icannotthinkofaname · · Score: 2

    Users of the stable version of Google's Webkit-based browser might be surprised to find out that, so far, passwords are stored on the hard disk as clear text.

    I see. So that's why I keep my passwords stored in my head. No virus that can live in my head can read my passwords out of there, AFAIK.

    --
    Let q be a radix > 1. I am in ur base-q, killing 10 d00ds.
  2. Crazy Article by bipbop · · Score: 4, Funny

    I just looked at the article briefly, and it states "A second high-priority flaw, a sandbox parameter deserialization error, was discovered by two members of Adobe's Reader Sandbox Team." What the--Adobe has a security team? That's crazy talk!

    1. Re:Crazy Article by TooMuchToDo · · Score: 4, Funny

      Notice that they're too busy working on finding holes in Chrome to be working on Adobe products ;)

      I kid!

    2. Re:Crazy Article by n0-0p · · Score: 2, Interesting

      FWIW, they thanked members of the Chrome team a few months ago when they announced sandboxing support in an upcoming version of Acrobat Reader.

  3. Version bloat by R.Mo_Robert · · Score: 2, Interesting

    Any reasion for the version-number bloat? I mean, I guess it looks a bit cooler next to IE 8, but I don't really think people are that naive.

    --
    R.Mo
    1. Re:Version bloat by ksandom · · Score: 3, Funny

      In 2015.... Chrome 256 released!

      --
      Funnyhacks - Wierd, unusual, and fun hacks
    2. Re:Version bloat by rezonat0r · · Score: 4, Informative

      I'm guessing you missed their highly re-reported blog post regarding the new release schedule.

    3. Re:Version bloat by maccodemonkey · · Score: 2, Insightful

      I was amazed they've already flown past an older browser (Safari) in version numbers, and they're inching toward IE territory.

      Seriously Google. This sounds like a .1, or even a .0.1 release. Don't be afraid of little bumps. It didn't sound like any new significant features were introduced.

    4. Re:Version bloat by Tubal-Cain · · Score: 2, Informative

      Firefox is older than Safari (OK, so it was Phoenix at the time...) and is only at 3.x or 4.0 (beta)

    5. Re:Version bloat by dougisfunny · · Score: 4, Funny

      They figure once they get to 6 they can coast for years.

      --
      This is not the funny you're looking for.
  4. Comment removed by account_deleted · · Score: 2, Interesting

    Comment removed based on user account deletion

  5. Re:Where's the love for the Mac passwords? by Netshroud · · Score: 4, Informative

    Chrome already uses the Keyring... at least it does for me.

  6. Re:Print Preview? by Anonymous Coward · · Score: 5, Informative

    no, no and yes

  7. Re:Wheel of Bug Chasers! by bonch · · Score: 5, Insightful

    Give me a break. You turn a bug bounty into a statement on American values. Your gameshow references are completely baseless and random. What a load of crap!

  8. Re:$4,337 from a multi-billion dollar company? by LingNoi · · Score: 4, Informative

    Since you're not going to RTFA or even the summary i'll repost it here..

    includes patches for 14 total security vulnerabilities, including six high-priority flaws, and the company paid out a total of $4,337 in bug bounties to researchers who reported the vulnerabilities. A number of the flaws that didn't qualify for bug bounties were discovered by members of Google's internal security team.

    The new release of Chrome also fixes an older bug, a Windows kernel flaw, that Google had thought it fixed in a previous version.The highest bug bounty, $1337, was paid for an integer error in WebSockets found by Keith Campbell. A second high-priority flaw, a sandbox parameter deserialization error, was discovered by two members of Adobe's Reader Sandbox Team.

  9. Re:$4,337 from a multi-billion dollar company? by blai · · Score: 2, Informative

    tl;dr

    --
    In soviet Russia, God creates you!
  10. Aeet? by Anonymous Coward · · Score: 5, Funny

    First thing I thought when I saw 4337 was "What the fuck is Aeet?"

    1. Re:Aeet? by Anynomous+Coward · · Score: 2, Insightful

      Actually, $4337 is 'Saeet', a phonetic transcription of the middle eastern name 'Saïd'.

      --
      I'm not a coward by any name.
  11. Re:Wheel of Bug Chasers! by kdub432 · · Score: 3, Insightful

    This is one of the dumbest arguments I've ever seen on slashdot.

  12. Re:Wheel of Bug Chasers! by iamhassi · · Score: 2, Insightful

    "Discover flaws in Google's Chrome... and you get paid. But the entire panel of winners gets less than $5,000 for their trouble... Something's not right in the equity here."

    Well, you could always find flaws in Firefox, Windows, IE, etc and get paid nothing if you like.

    $4,337 > 0

    I say good for Google. What do you want from them, $43,370? $433,700? They're already paying more than anyone else.

    --
    my karma will be here long after I'm gone
  13. Re:Print Preview? by Urza9814 · · Score: 3, Interesting

    Uhh...my Chromium 5 for Linux has print preview and proper flash support. And the same file download behavior as browsers like Firefox - I open a file the browser doesn't handle, it downloads to the folder I've specified for downloads. How is that a problem? As I said, it's the same thing Mozilla does. I don't _want_ a browser to just start deleting my downloads on it's own. If I tell it 'yes, download this file', that file should stay where it is until I decide to delete it.

  14. Re:Wheel of Bug Chasers! by Tubal-Cain · · Score: 3, Informative

    Mozilla also pays bug bounties.

  15. Linux Logins by idcard_1 · · Score: 5, Interesting

    FYI your linux logins on Ubuntu are stored in this file: /home/username/.config/google-chrome/Default/Login\ Data just do "strings Login\ Data" and you have those passwords. :(

    1. Re:Linux Logins by Zixaphir · · Score: 2, Informative

      wtf is /home/username? In my days, we communicated home as "~/". You can read it as tilde slash or even tilde slash dot, but it doesn't matter. ~ sweet ~.

      --
      "Now I am become Death, the destroyer of worlds"
  16. Implement your own secure storage strategy by nick1000 · · Score: 2, Interesting

    As a Linux application developer who has used keyring/kwallet for saving secure passwords in the past. I'd recommend not to use them.

    Various different distributions have different versions of the these utilities and their libraries. There are so many variations that it becomes hard to support all versions. Most desktop linux end users have never used them and when they see a warning window popping up (which these utilities tend to show). They cancel the window rather than going through the authentication process.

    Just my 2 cents.

  17. Feel Save AND Fresh by Anonymous Coward · · Score: 2, Funny

    You're on Linux, the most trusted, secured and freshest OS in the universe !!

    Why do you care if Google leaves your creds in the clear? If someone can read them, you are already OWNED !!

    Yours,
    Shirley, the one and only Summer's Eve girl

  18. Video on the other hand... by Anonymous Coward · · Score: 2, Informative

    > Do Flash videos play the audio correctly?
    Yes. The video on the other hand, as in all browsers, is a different story. We're still waiting for the fix from Adobe. In the meantime, you can use the following user script:
    ----(start of file)----
    // ==UserScript==
    // @name YouTubeWMP
    // @version 1.0
    // @description Replaces Flash player with WMP in YouTube.
    // @run-at document-start
    // @include http://www.youtube.com/*
    // ==/UserScript==

    flp=document.getElementById("movie_player");
    flp.outerHTML = "<EMBED type='application/x-mplayer2' width='" + flp.width + "' height='" + flp.height + "' src='" + unescape(flp.getAttribute("flashvars").match(/&fmt_url_map=[^&]*%7C([^&]*)/)[1]) + "' autostart='true' autosize='-1'></EMBED>";
    ----(end of file)----
    This script is for YouTube, you can make similar ones for other sites easily. Just use the resources panel in the developer tools to figure out where to get the link to the flv stream.

  19. Re:Print Preview? by dakameleon · · Score: 2, Informative

    I think the behaviour being asked for above is the "open with" behaviour common on other browsers, where the file is download to a temporary folder (e.g. $WINUSER$\Local Settings\Temp for Windows) for use by an application selected right from the download dialog. The temp folder can be cleaned up by the browser at a random date in future, or more often than not just sits there until someone decides to clean it out.

    This just means the file is out-of-sight out-of-mind for a one-time-use scenario and the user doesn't need to concern themselves with file management post-use.

    (Some might say this goes hand-in-hand with private browsing modes. You wait til you're cleaning out a Temp folder for a friend of a friend and notice the number of 30 second video clips...)

    --
    Man who leaps off cliff jumps to conclusion.
  20. Re:Yep. My practices are justified. by selven · · Score: 2, Informative

    Some kind of encryption as obfuscation, DRM-style, is still better than just plain text. One of the tricks used by people who steal hard drives is to try every possible chain of subsequent bits as a password. It's only at most a few trillion tries (less than brute-forcing an 8-char alphanumeric password, and quite feasible with a botnet or a few days of time), and often as few as a few billion, but it gets passwords right quite often. Encryption would defeat this attack.

  21. And it's ACID3 compliant! by VincenzoRomano · · Score: 3, Informative

    At least the Linux version for x86_64.
    Try it

    --
    Maybe Computers will never be as intelligent as Humans.
    For sure they won't ever become so stupid. [VR-1988]
  22. Re:$4,337 from a multi-billion dollar company? by sco08y · · Score: 4, Funny

    The highest bug bounty, $1337

    $1337? Oh come on!

    Well, $5318008 was a bit much.

  23. Re:Wheel of Bug Chasers! by Dhalka226 · · Score: 4, Insightful

    Give ME a break. I can't believe the "bug bounty hunters" would really sell a Google vulnerability for a thousand dollars

    And yet they did. That must really shake your world view.

    Believe it or not, when normal people discover a vulnerability and their options are "run a bonet" and "tell the manufacturer," most of them tell the manufacturer. Getting $1000 for it is an added bonus, not the incentive to action.

    True, it's not going to create a whole new generation of professional bug bounty hunters living off their bounties, but that was never the intent. If they wanted to hire an army of extra bug hunters they'd put you on the payroll. If you're looking to get rich, do something else. If you're into it for the challenge or to be helpful or you happen to be mucking about with their browser as part of your day job, make a little extra money as Google's way of saying "thank you" for doing the right thing and helping them to make their free product--one you evidently use, if you're finding bugs in it--a better one.

    If that's not good enough for you, well, fine. Don't look for bugs. Don't pass Go, don't collect $1,000. Your time is apparently better spent trying to get yourself a spot on Wheel of Fortune.

  24. Re:Print Preview? by delinear · · Score: 2, Funny

    Maybe his time is important and he's planning on paying out a bounty to anyone who can deliver the information to him.