Home
3 comments
SebFender11 months ago
With all do respect - I laugh every time a researcher thinks THEY found something... Sometimes they really do, but many times others have long before and just don't share the results...
评论 #40799235 未加载
1vuio0pswjnm711 months ago
"Let's now skip ahead a few years to the first research paper I ever worked on. With (who would later become) my PhD advisor, we found that most of the most popular Chrome extensions were vulnerable to a variety of attacks that could let us do very bad things. Over half of the extensions we studied were vulnerable to attack, impacting millions of users."<p>Lots of HN commenters are fans of popular browsers and "browser extensions". Maybe they just like the ones that are not vulnerable to a variety of attacks. Yeah, right.
The idea that I never see in these published papers is that (a) the software being examined should henceforth not be distributed to the public. Or even that people should stop using this software. Instead I almost always see the idea that (b) the software should be "fixed".<p>The power of idea "(a)" is that it stops the problems for end users. It leaves nothing for "attackers". Ideally it stops bad programmers from distributing software to the public for commercial purposes.<p>Whereas idea "(b)" generally keeps these bad programmers doing what they do: writing bad software and profiting from it. It might temporarily embarass them but they will continue to distribute their bad sofware to the public, for profit. (And creating more "puzzles" for people like the author of the blog post. Arguably giving these "attackers" an interest in seeing more bad software distributed. Keep those puzzles coming.)
评论 #40801266 未加载
评论 #40816040 未加载