Live data from Hacker News

How to gain code execution on hundreds of millions of people and popular apps

kibty.town

101–110 of 350 posts

Re: How to gain code execution on hundreds of millions of people and popular apps

#101
post #93

Earlier quoted context omitted.

Under what theory of psychology are you operating? This is along the same lines as the theory that punishment is an effective deterrent of crime, which we know isn’t true from experience.

While I think that resigning is stupid here, asserting that "punishment doesn't deter crime" is just absurd. It does!

The overwhelming majority of evidence suggests otherwise.

https://www.psychologytoday.com/us/blog/crime-and-punishment...

https://www.unsw.edu.au/newsroom/news/2020/07/do-harsher-pun...

https://www.ojp.gov/pdffiles1/nij/247350.pdf

https://www.helsinki.fi/en/news/economics/do-harsh-punishmen...

Re: How to gain code execution on hundreds of millions of people and popular apps

#102
post #12
post #9

Earlier quoted context omitted.

> cannot happen again. Hubris. Does not inspire confidence. > We resolved the vulnerability within 26 hours of its initial report, and additional security audits were completed by February 2025. After reading the vulnerability report, I am impressed at how quickly you guys jumped on the fix, so kudos. Did the security audit lead to any significant remediation work? If you weren't following PoLP, I wonder what else ma…

Fair point. Perhaps better phrased as "to ensure this scenario can't recur.". I'll edit my post. Yes, we re-architected our build container as part of remediation efforts, it was quite significant.

[deleted]

Re: How to gain code execution on hundreds of millions of people and popular apps

#103
post #85
post #81

Earlier quoted context omitted.

This is the wrong response, because that means that the learning would be lost. The security community didn't want that to happen when one of the CA's got a vulnerability, we do not want it to happen to other companies. We want companies to succeed and get better, being shameful doesn't help towards that. Learning the right lessons does, and resigning means that you are learning the wrong ones.

I don't think the lesson is lost. The opposite. If you get a slap on the wrist, do you learn? No, you play it down. However if a dev who gets caught doing a bad is forced to resign. Then all the rest of the devs doing the same thing will shape up.

I suggest reading one or two of Sydney Dekker’s books, which are a pretty comprehensive takedown of this idea. If an organization punishes mistakes, mistakes get hidden, covered up, and no less frequent.

Re: How to gain code execution on hundreds of millions of people and popular apps

#104
post #45

Earlier quoted context omitted.

Azure Trusted Signing is one of the best things Microsoft has done for app developers last year, I'm really happy with it. It's $9.99/month and open both to companies and individuals who can verify their identity (it used to only be companies). You really just call signtool.exe with a custom dll. I wrote @electron/windows-sign specifically to cover it: https://github.com/electron/windows-sign Reference implementation…

The big limitation with Azure Trusted Signing is that your organization needs to be at least 3 years old. Seems to be a weird case where developers that could benefit from this solution are pushed towards doing something else, with no big reason to switch back later.

That limitation should go away when Trusted Signing graduates from preview to GA. The current limitation is because the CA rules say you must perform identity validation of the requester for orgs younger than 3 years old, which Microsoft isn't set up for yet.

Re: How to gain code execution on hundreds of millions of people and popular apps

#105
post #14

Earlier quoted context omitted.

how much of a bounty was paid to Eva for this finding?

> they were nice enough to compensate me for my efforts and were very nice in general. They were compensated, but doesn't elaborate.

They later updated their post, at the bottom:

> for those wondering, in total i got 5k for this vuln, which i dont blame todesktop for because theyre a really small company

Re: How to gain code execution on hundreds of millions of people and popular apps

#106
post #14
post #3

Dave here, founder of ToDesktop. I've shared a write-up: https://www.todesktop.com/blog/posts/security-incident-at-to... This vulnerability was genuinely embarrassing, and I'm sorry we let it happen. After thorough internal and third-party audits, we've fundamentally restructured our security practices to ensure this scenario can't recur. Full details are covered in the linked write-up. Special thanks to Eva for resp…

how much of a bounty was paid to Eva for this finding?

> for those wondering, in total i got 5k for this vuln

Re: How to gain code execution on hundreds of millions of people and popular apps

#108
post #85
post #81

Earlier quoted context omitted.

This is the wrong response, because that means that the learning would be lost. The security community didn't want that to happen when one of the CA's got a vulnerability, we do not want it to happen to other companies. We want companies to succeed and get better, being shameful doesn't help towards that. Learning the right lessons does, and resigning means that you are learning the wrong ones.

I don't think the lesson is lost. The opposite. If you get a slap on the wrist, do you learn? No, you play it down. However if a dev who gets caught doing a bad is forced to resign. Then all the rest of the devs doing the same thing will shape up.

Can you back up your theory with the example of all the mistakes you have committed and force resigned taken?

Re: How to gain code execution on hundreds of millions of people and popular apps

#109
post #87
post #78

Earlier quoted context omitted.

This is not how the law works anywhere, thankfully.

Well for one it was a gift so there is no valid contract right? There are no direct damages because there is nothing paid and nothing to refund. Wrt indirect damages, there's bound to be a disclaimer or two, at least at the app layer. IANAL, not legal advice

I’d suppose there is an ALL CAPS NO WARRANTY clause as well, as is customary with freeware (and FOSS). ToDesktop is a paid product, though.

Re: How to gain code execution on hundreds of millions of people and popular apps

#110
post #3

Dave here, founder of ToDesktop. I've shared a write-up: https://www.todesktop.com/blog/posts/security-incident-at-to... This vulnerability was genuinely embarrassing, and I'm sorry we let it happen. After thorough internal and third-party audits, we've fundamentally restructured our security practices to ensure this scenario can't recur. Full details are covered in the linked write-up. Special thanks to Eva for resp…

no offense man but this is totally inexcusable and there is zero chance i am ever touching anything made by y'all, ever
Post reply on HN