catcher,omni look. just caught vikingvpn on reddit commenting about browser attacks
There's dozens of way to compromise browsers in order to identify a user. Most of these are executed through Javascript. You also have issues with WebRTC, Geolocation services, browser fingerprinting techniques, cookies in general, and a probable huge number of zero-day attacks lying in wait.
Browsers are extremely complex and hard to maintain, and there are multiple forces pulling ideas in different directions (privacy and security vs fancy and revealing). This combined with everyone wanting backwards compatibility with old technologies leads to a lot of issues.
Adversaries are far more likely to execute a javascript or browser-based attack against a target rather than wrestle with legal process in nations outside of their jurisdiction...
Hmmm, seems to me that Derek Zimmer knows a lot about attacking people using browser exploits and javascript.

Comments