‹ BackHN Continuity

Thread

How one Twitch chat message became code execution on a streamer’s PC

67 points · 30 comments · tau255

  1. charcircuit · · focus · HN ↗
    <a href="https:&#x2F;&#x2F;github.com&#x2F;obsproject&#x2F;obs-browser&#x2F;pull&#x2F;523" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;obsproject&#x2F;obs-browser&#x2F;pull&#x2F;523

    Not even counting the time it took to make this PR, releasing a security update for the browser took 4 months to merge. For reference Brave has a 1 day SLA for releasing the update itself after a security fix gets published.

    1. landr0id · · focus · HN ↗
      It&#x27;s not just moving a code pointer. They had to migrate CEF runtimes (Alloy to Chrome) which, as I understand from the few minutes of reading I did to understand the complexities outlined in the PR, was necessary because Alloy was removed in M128. So OBS was using the last version of legacy runtime and needed to migrate. I imagine they wanted to do a decent amount of testing to ensure compat.
      1. charcircuit · · focus · HN ↗
        &gt;It&#x27;s not just moving a code pointer.

        That&#x27;s not the end user&#x27;s problem. End user&#x27;s don&#x27;t want to be told that they got hacked because keeping your product secure was too hard.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.