Live data from Hacker News

RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit

parsiya.net

81–90 of 109 posts

Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit

#82
post #37

If I'm reading this right, it assumes the machine's IP is publicly accessible over the internet; which I'm guessing -even with IPv6- is not the case in 99.999% of cases; who just exposes their development machine directly to the internet with a public IP? Still bad, but not quite as bad as owning from the browser via localhost GET.

This guess would be incorrect both in the percentage, and in the assumption that this would be required for exploitability.

Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit

#83
post #28

Microsoft has the best bounty hunter program: go fuck yourself. If you find a way to take over MS accounts, or force email swaps, or even gamertag shanaigans, there is too much money to be made, there is not even a point for a bug bounty. It's like a $40 reward for returning a purse filled with $250k. I agree with OP: no more free bugs.

It's not just Microsoft. What most bug bounties pay isn't even close to the amount you can get from selling it on the black market (assuming you have the right connections). It's why selling exploits to nation states and vendors who work with them is so lucrative.

How does the black market price compare to the 'nation state' price?

Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit

#84
post #44

Earlier quoted context omitted.

It's not just Microsoft. What most bug bounties pay isn't even close to the amount you can get from selling it on the black market (assuming you have the right connections). It's why selling exploits to nation states and vendors who work with them is so lucrative.

I do agree that bug bounties are too small, but isn't selling bugs on the black market illegal? I would much rather get $40 dollars for a bug and some public acknowledgement (which I could use to get a better paying job) than to sell it for criminal use.

Bitcoin solves this!

Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit

#85
post #40

Earlier quoted context omitted.

Not really all that troubling, all the author is saying is that he wants to get paid for their work. Either Microsoft or other future vendors can actually honor an established bug bounty program, or the author can sell his findings to the highest bidder. Or the author can simply not spend time and energy finding bugs in the first place.

Highest bidder is unethical and illegal. But does not change the monetary reality

How is it illegal?

Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit

#86
post #49
post #44

Earlier quoted context omitted.

I do agree that bug bounties are too small, but isn't selling bugs on the black market illegal? I would much rather get $40 dollars for a bug and some public acknowledgement (which I could use to get a better paying job) than to sell it for criminal use.

Assuming you live in a place where you can get a high paying job and/or leave the country to get one. Taking a US centric view on this is a great way to ensure nation states have compromised your security.

So if you take a non-US centric view and assume there's no legal repercussions and the person finding the bug has no moral compass, what exactly would prevent them from sharing the bug with a nation state and you at the same time? Sure they may get slightly less from the nation state because the bug would have a shorter shelf life, but it would still make it into the wild long before every system could be patched.

Paying more money isn't going to make someone do the right thing.

Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit

#87

Earlier quoted context omitted.

It's not just Microsoft. What most bug bounties pay isn't even close to the amount you can get from selling it on the black market (assuming you have the right connections). It's why selling exploits to nation states and vendors who work with them is so lucrative.

How does the black market price compare to the 'nation state' price?

x = y. Where do you think nation states purchase their tools?

Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit

#89

The "Your editor has DRM" section alone [0] is enough for me to continue to advocate for a better user-friendly FOSS IDE, in addition to the wonderful giants of emacs & vim, and to avoid the VS Code "kool aid". [0] https://parsiya.net/blog/2021-12-20-rce-in-visual-studio-cod...

VSCodium is a FOSS build of the MIT VSCode repo, with an alternate FOSS compliant extension source. Note that some fancy extensions are missing, but otherwise works 100%. I have been using VSCodium as my main IDE for about a year now. https://vscodium.com/

One of those extensions is the one that implements C# debugging, so for C# debugging, VSCodium is a fancy editor, not an IDE.

Re: RCE in Visual Studio Code's Remote WSL for Fun and Negative Profit

#90
post #45

Earlier quoted context omitted.

It's not just Microsoft. What most bug bounties pay isn't even close to the amount you can get from selling it on the black market (assuming you have the right connections). It's why selling exploits to nation states and vendors who work with them is so lucrative.

It's probably illegal in many jurisdictions, no? Not to mention unethical. You are not just harming Microsoft here in this instance, but potentially millions of people.

If we’re looking at ethics, what’s the morality of Microsoft not paying market rate for exploits.
Post reply on HN