30 comments
Sure, if the plugin developer sanitized the comments before inserting them, this wouldn't have happened _this way_, but having a browser engine two years outdated (for a reason which IMO is absolutely reasonable compared to other situations before) and having the Chromium sandbox completely disabled with nothing to substitute it is crazy in a software onto which people insert random plugins from the internet to get random functionality.
Hopefully those two changes ship fast to OBS. I may be supporting the project financially in the future if they update their security posture, as I'm generally very fond of OBS.
Well damn.
Not even counting the time it took to make this PR, releasing a security update for the browser took 4 months to merge. For reference Brave has a 1 day SLA for releasing the update itself after a security fix gets published.
That's not the end user's problem. End user's don't want to be told that they got hacked because keeping your product secure was too hard.
Read the full thread on Hacker News →
Related stories
- Lobsters · 86 points · about 1 year ago
- Hacker News · 8 points · 6 days ago
- The Verge · 0 points · 6 days ago
- Hacker News · 1 points · 6 days ago
- Remote Code Execution (RCE) in a DoD Websitehackerone.comHacker News · 1 points · 8 days ago
- Emacs Arbitrary Code Execution Returnseshelyaron.comLobsters · 5 points · about 1 month ago