In a sense Microsoft forgot its own learnings. Because of exactly things like this they prevent UWP apps from connecting to localhost by default and make it very annoying to circumvent and from my experience, the circumvention is not exactly a stable setup. So they really don't want you to do that, and somebody thought enough to make it extra difficult. So, they have UWP, all those well thought-out policies, then mak…
RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit
51–60 of 109 posts
Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit
#52> Does it fix the issues? Yes. > Do I think there are other security issues here and we can bypass this? Also, yes. > Do I want to spend more time doing free work for a company with a 2.5 TRILLION market cap? Hell, no. Troubling.
Not really all that troubling, all the author is saying is that he wants to get paid for their work. Either Microsoft or other future vendors can actually honor an established bug bounty program, or the author can sell his findings to the highest bidder. Or the author can simply not spend time and energy finding bugs in the first place.
Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit
#53Earlier quoted context omitted.
Highest bidder is unethical and illegal. But does not change the monetary reality
Pass a law that requires companies to pay black market value for bug bounties. It’s also unethical for big corporations to exploit the US oligarchy to get these fixes for free.
Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit
#54Earlier quoted context omitted.
oh how i would love this future.
At this point of time, I give it 10min before we get a magic_proxy nginx module, then your script src will be /magic_proxy/www.evilthirdpary.com/slow_multi_megabyte_script.js You can still import all nasty third parties required by marketing department, bypassing first party protections and leading to even worse security. Or maybe maintain allow lists, basically that's a Content Security Policy. Future is now old man…
Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit
#55Not making websockets follow the same-origin policy was a mistake.
Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit
#56Earlier quoted context omitted.
It's not just Microsoft. What most bug bounties pay isn't even close to the amount you can get from selling it on the black market (assuming you have the right connections). It's why selling exploits to nation states and vendors who work with them is so lucrative.
I do agree that bug bounties are too small, but isn't selling bugs on the black market illegal? I would much rather get $40 dollars for a bug and some public acknowledgement (which I could use to get a better paying job) than to sell it for criminal use.
Bug bounties need to be higher, because the black market is not the only alternative.
Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit
#57Earlier quoted context omitted.
oh how i would love this future.
At this point of time, I give it 10min before we get a magic_proxy nginx module, then your script src will be /magic_proxy/www.evilthirdpary.com/slow_multi_megabyte_script.js You can still import all nasty third parties required by marketing department, bypassing first party protections and leading to even worse security. Or maybe maintain allow lists, basically that's a Content Security Policy. Future is now old man…
Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit
#58Earlier quoted context omitted.
At this point of time, I give it 10min before we get a magic_proxy nginx module, then your script src will be /magic_proxy/www.evilthirdpary.com/slow_multi_megabyte_script.js You can still import all nasty third parties required by marketing department, bypassing first party protections and leading to even worse security. Or maybe maintain allow lists, basically that's a Content Security Policy. Future is now old man…
At least then the server has to deal with the security implications of talking directly to the advertiser, instead of pushing the risk wholly to the client.
On moral/legal issues, integrating script from third or first party hostname sounds like technical detail. If you select partner to run their code on your pages, you should be responsible checking user consent when applicable and taking responsibility. British Airways has been fined £20m even if that script was not on their servers.
Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit
#59Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit
#60Earlier quoted context omitted.
I do agree that bug bounties are too small, but isn't selling bugs on the black market illegal? I would much rather get $40 dollars for a bug and some public acknowledgement (which I could use to get a better paying job) than to sell it for criminal use.
> but isn't selling bugs on the black market illegal? Noob question: is there any specific law that punishes describing how to get into a software/electronic system but not actually doing it? Something that is just not purely US-centric.
https://law.stackexchange.com/questions/11552/is-it-illegal-...