Top
Best
New

Posted by auberonedu 16 hours ago

The Deathray: A simple way for an untrusted site to freeze a Mac(auberon.xyz)
212 points | 134 commentspage 4
LoganDark 12 hours ago|
Apple Silicon Macs have a lot of GPU problems. I find that after running any significant GPU workload, the entire operating system starts getting super slow until a reboot. Even if the entire process tree that ever touched the GPU has been completely terminated for days.
abecedarius 9 hours ago|
Sounds like a problem that'd hit anyone running LLMs. I haven't tried on mine so far, but people do talk about ordering a $10k Mac Studio just for that. Anyone else see this? Does the OS version matter?
dermacentor 6 hours ago|||
Never.
LoganDark 2 hours ago|||
I don't think I had the issue before macOS 26, but honestly I have no way to tell. I did run into one other HN commenter that suffers from the same slowness problem, but they didn't connect it to workloads, only uptime. I think it was the same issue though.
chrisjj 4 hours ago||
> recoverable data loss which we do not consider to be a security issue

How about the irrecoverable loss of data in RAM, though?

avaer 4 hours ago||
It's very easy to lock up your browser or machine with WebGPU, it happens on Windows too. You'll do this by accident constantly in a big WebGPU project, until the Chrome GPU trace/renderdoc/nsight shows some crazy deadlock bottleneck you have no hope of understanding at the browser level.

GPU driver engineering has received a tiny fraction of the resources of CPU engineering, while being significantly more complex. And GPU users will not pay for performance hits that better the architecture, they will just buy the other guy's GPU/use their driver. So it's a race to the top with performance and race to the bottom with architecture and stability.

Markoff 4 hours ago||
Absolutely no effect on Firefox on Android 16, same with Vivaldi on W10. Everything works normal, not even higher CPU load, just shows some blank page.
achierius 11 hours ago||
Not 100% surprised that this wasn't picked up as a security issue; denial-of-service is bad, but ultimately doesn't give you a direct path to stealing secrets / hijacking identity / etc.

It is pretty egregious though, I hope they fix this. I expect there'll be a Radar tracking this now that it's made it to the HN front page.

stevomacdaddy 11 hours ago||
This froze my S26 Ultra on chrome
selectodude 12 hours ago||
Zero impact on iOS 27.
skinfaxi 12 hours ago||
The title says "freeze a mac".
embedding-shape 11 hours ago|||
Tried it on my Blackberry too, also nothing. I say it's a nothingburger.
layer8 12 hours ago|||
It’s not an iOS bug to begin with.
iAMkenough 12 hours ago|||
Still impacts macOS 27 release candidate.
wpm 9 hours ago||
Yes, but it didn't kernel panic my computer, it just forced WindowServer to quit, but it "helpfully" reopens all of your windows/apps, so it reloads the tab that caused the deadlock to begin with, rinse and repeat.

It's always funny to me when you put computers into such states. Last time I was tickled this was was when I nuked the TCC database permissions for Zoom while in a meeting, sharing my screen, using my microphone and camera. The OS rrrrreally didn't like that.

vivzkestrel 8 hours ago||
[flagged]
dang 7 hours ago|
It's helpful to let people know when links aren't working but can you please not be a jerk when doing so?

From https://news.ycombinator.com/newsguidelines.html:

"Don't be snarky."

"Edit out swipes."

hyperhello 12 hours ago||
[flagged]
StilesCrisis 11 hours ago||
Blowing up a browser tab with bad JavaScript is not considered to be a problem. But kernel panicking the computer is different--this brings us back to the bad old days of MacOS where a buggy program could force a freeze/restart at any time.
SahAssar 12 hours ago|||
Usually you can't freeze the whole system UI with an infinite counter though. I'm pretty sure normal JS browser processes are not supposed to be able to do that.
LoganDark 12 hours ago||
It only froze Safari tabs for me. Not even Safari's own UI except for the web pages themselves.

It did do it to all tabs though.

mikestew 12 hours ago|||
There's more to it than just a loop. If it was just a loop, it would peg a CPU core and be done with it. But you'll have to reread TFA to find out how it takes out the window server, thus freezing the rest of the system.
hyperhello 12 hours ago||
Why does everyone hate this comment? Attitude? I can’t figure out the wavelength here. I’m just commenting.
StilesCrisis 11 hours ago|||
Because kernel panics are a wildly different class of bug than breaking one browser tab. An "Oh Snap" is the designed outcome of a JavaScript infinite loop. Crashing the whole computer is not.
JumpCrisscross 12 hours ago||||
> Why does everyone hate this comment?

"It's just" dismissals are annoying when they're blatantly wrong. An infinite-loop counter in Orion.app shouldn't cause my entire machine to freeze, down to being unable to force quit.

demibabs 11 hours ago||||
"It's just" is usually an annoying way to start a comment.
LoganDark 12 hours ago||||
An infinite loop in JavaScript causes a different issue. It doesn't cause the rest of your tabs to stop working too. Or allegedly the entire rest of the OS though I can't reproduce that.
fuzzfactor 5 hours ago|||
Hate does seem to be on the rise across the board, even for fairly trivial things. About all one person can do is try to set a non-hate example.

Plus provide a corrective upvote from time to time especially when a knee-jerk robot is suspected, or a maybe it's an actual person where you can't tell the difference.

Sometimes it gets so bad that people hate it when you try to keep a decent article from plummeting under the depths of a sea of slop.

I think it's well-recognized that robots are more prevalent than ever and it doesn't seem to be making things better at this point.

fuzzfactor 15 hours ago|
Maybe that would be better than a meltdown . . .