Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To be fair, the browsers get exploited because of vulnerabilities in flash year after year.

I don't want to suggest there's perfect security, there's not, but they aren't exactly attacking builds with ublock, click to play flash, and disabled javascript.

The profile of the systems is a concession that some builds would be too hard to consistently attack.



At least as far as pwn2own is concerned, browsers are targeted without any access to plugins.

Plugins are usually introduced (some of them separately) on different days and are considered different targets.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: