- Alexandria Ocasio-Cortez supports resolution that could lead to Trump’s impeachment Thursday 9:46 PM
- Ricardo Milos dancing memes are the new Rickroll Thursday 9:09 PM
- Laura Loomer sues Twitter, Muslim lobbying group over account ban Thursday 8:15 PM
- Far-right troll Ian Miles Cheong gets flamed for mocking a ‘Star Wars’ fan Thursday 6:17 PM
- Facebook says ‘millions,’ not ‘tens of thousands,’ affected by Instagram password bug Thursday 5:13 PM
- Leading 2020 Democrats mock redactions in Mueller report Thursday 4:04 PM
- 8 weed accessories for stealthy stoners Thursday 4:00 PM
- Super Smash Bros. Ultimate players are now fighting on giant d*cks Thursday 3:37 PM
- Why are Facebook and Google translating this Spanish word into a racial slur? Thursday 3:32 PM
- Instagram page encourages meme creators to join a meme union Thursday 3:24 PM
- 28 smokin’ hot gifts for your stoner friend Thursday 1:33 PM
- The 5 most important conclusions from Robert Mueller’s report Thursday 1:28 PM
- Facebook bans many of the U.K.’s infamous far-right groups Thursday 1:15 PM
- Cersei and Tyrion Lannister learned about respect from Elmo Thursday 12:57 PM
- The Mueller Report includes a footnote about the pee tape Thursday 12:08 PM
Hacker scores $5,000 payday for finding address bar flaw in Chrome and Firefox
Developers can’t find every bug themselves, so they use bug bounties to encourage hackers to help them keep programs secure.
While developers do their best to ensure the programs and apps they make are secure when they’re released, it’s often impossible for a team to find every bug. That’s why bug bounties exist, as a way to reward users who help developers find security flaws in the programs we use every day. It’s also why Rafay Baloch is currently $5,000 richer.
Baloch recently discovered a vulnerability in the way Chrome and Firefox render website addresses, which allowed attackers to send users to spoof websites that appear to be real but are actually elaborate frauds. The vulnerability was caused by the browser’s flipping of web addresses that are written right-to-left, since that’s how some languages, such as Arabic, are read.
According to Baloch’s example, if a user were to input 127.0.0.1/I/http://example.com, the browser would display it as simply http://example.com/i/127.0.0.1, while still sending the user to 127.0.0.1/i/http://example.com. This allowed scam artists to trick users to visiting spoof sites that use the guise of official domains.
According to Baloch the issue will be resolved when Chrome 53 and Firefox 48 are released. In the meantime let Baloch’s windfall be your inspiration. If you’ve got the skill to discover a bug it could pay off in more than just a pat on the back for making the world a better place. It could land you cold hard cash.
John-Michael Bond is a tech reporter and culture writer for Daily Dot. A longtime cord-cutter and early adopter, he's an expert on streaming services (Hulu with Live TV), devices (Roku, Amazon Fire), and anime. A former staff writer for TUAW, he's knowledgeable on all things Apple and Android. You can also also find him regularly performing standup comedy in Los Angeles.