Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not 100% surprised that this wasn't picked up as a security issue; denial-of-service is bad, but ultimately doesn't give you a direct path to stealing secrets / hijacking identity / etc.

It is pretty egregious though, I hope they fix this. I expect there'll be a Radar tracking this now that it's made it to the HN front page.

 help



The usual read on cybersecurity determines how bad an issue is using (something akin to) impact on confidentiality, integrity, and availability.

Being able to freeze a computer from the browser is a plain availability risk. It's not exactly a high-priority risk, but still something that should be considered a risk in my opinion.

With operating systems like macOS+Safari reopening a page after reboot, a malware domain can claim to take your computer hostage by te-freezing the PC every time the user moves away from the page until money is paid. People already fall for "we have hacked your computer pay X bitcoin to get it back", this just adds to that.

According to the comments here, this has been a thing for ages, so I kind of doubt that they'll fix it this time. But fingers crossed!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: