The React2Shell Story
lachlan.nz
The React2Shell Story
1–10 of 50 posts
Re: The React2Shell Story
#2I love the "we are so back" vs. "it's so over" graph. Defines so much of this type of work. "Wow? ... nah... WOW?! ... nah..."
Re: The React2Shell Story
#3Re: The React2Shell Story
#4Re: The React2Shell Story
#5Incredible. Realize what you have done from start to finish (with confirmation) in < 24 hours.
Re: The React2Shell Story
#6One correction: The link in "To be honest, I'm not even sure if I understand it, but it's on my GitHub." goes to the wrong file (01 instead of 00).
Re: The React2Shell Story
#7It was really helpful that they had coordinated with WAF providers like cloud flare ahead of disclosure to put rules in place though.
Re: The React2Shell Story
#8- blurring the lines between client code and server code
- creating a brand new protocol for communication between trusted and untrusted actors
- and with all of that allow the protocol to serialize code and not just primitives
Would be a tremendously stupid idea. And for what? To lock developers further into the react ecosystem. What a shitshow react continues to be.
Re: The React2Shell Story
#9Re: The React2Shell Story
#10R2S was a painful one, but Lachlan was a dream of a security researcher to partner with. Not just from a responsible disclosure POV, but things like hopping on multiple calls with Meta and our team to help us validate remediations. Thank you Lachlan for helping make the internet safer (and great job on figuring out this 'labyrinth' of a vulnerability)