Earlier quoted context omitted.
Under what theory of psychology are you operating? This is along the same lines as the theory that punishment is an effective deterrent of crime, which we know isn’t true from experience.
While I think that resigning is stupid here, asserting that "punishment doesn't deter crime" is just absurd. It does!
How to gain code execution on hundreds of millions of people and popular apps
101–110 of 350 posts
Re: How to gain code execution on hundreds of millions of people and popular apps
#102Earlier quoted context omitted.
> cannot happen again. Hubris. Does not inspire confidence. > We resolved the vulnerability within 26 hours of its initial report, and additional security audits were completed by February 2025. After reading the vulnerability report, I am impressed at how quickly you guys jumped on the fix, so kudos. Did the security audit lead to any significant remediation work? If you weren't following PoLP, I wonder what else ma…
Fair point. Perhaps better phrased as "to ensure this scenario can't recur.". I'll edit my post. Yes, we re-architected our build container as part of remediation efforts, it was quite significant.
Re: How to gain code execution on hundreds of millions of people and popular apps
#103Earlier quoted context omitted.
This is the wrong response, because that means that the learning would be lost. The security community didn't want that to happen when one of the CA's got a vulnerability, we do not want it to happen to other companies. We want companies to succeed and get better, being shameful doesn't help towards that. Learning the right lessons does, and resigning means that you are learning the wrong ones.
I don't think the lesson is lost. The opposite. If you get a slap on the wrist, do you learn? No, you play it down. However if a dev who gets caught doing a bad is forced to resign. Then all the rest of the devs doing the same thing will shape up.
Re: How to gain code execution on hundreds of millions of people and popular apps
#104Earlier quoted context omitted.
Azure Trusted Signing is one of the best things Microsoft has done for app developers last year, I'm really happy with it. It's $9.99/month and open both to companies and individuals who can verify their identity (it used to only be companies). You really just call signtool.exe with a custom dll. I wrote @electron/windows-sign specifically to cover it: https://github.com/electron/windows-sign Reference implementation…
The big limitation with Azure Trusted Signing is that your organization needs to be at least 3 years old. Seems to be a weird case where developers that could benefit from this solution are pushed towards doing something else, with no big reason to switch back later.
Re: How to gain code execution on hundreds of millions of people and popular apps
#105Earlier quoted context omitted.
how much of a bounty was paid to Eva for this finding?
> they were nice enough to compensate me for my efforts and were very nice in general. They were compensated, but doesn't elaborate.
> for those wondering, in total i got 5k for this vuln, which i dont blame todesktop for because theyre a really small company
Re: How to gain code execution on hundreds of millions of people and popular apps
#106Dave here, founder of ToDesktop. I've shared a write-up: https://www.todesktop.com/blog/posts/security-incident-at-to... This vulnerability was genuinely embarrassing, and I'm sorry we let it happen. After thorough internal and third-party audits, we've fundamentally restructured our security practices to ensure this scenario can't recur. Full details are covered in the linked write-up. Special thanks to Eva for resp…
how much of a bounty was paid to Eva for this finding?
Re: How to gain code execution on hundreds of millions of people and popular apps
#107It also is, they are responsible for which tech pieces they pick in constructing their own puzzle
Re: How to gain code execution on hundreds of millions of people and popular apps
#108Earlier quoted context omitted.
This is the wrong response, because that means that the learning would be lost. The security community didn't want that to happen when one of the CA's got a vulnerability, we do not want it to happen to other companies. We want companies to succeed and get better, being shameful doesn't help towards that. Learning the right lessons does, and resigning means that you are learning the wrong ones.
I don't think the lesson is lost. The opposite. If you get a slap on the wrist, do you learn? No, you play it down. However if a dev who gets caught doing a bad is forced to resign. Then all the rest of the devs doing the same thing will shape up.
Re: How to gain code execution on hundreds of millions of people and popular apps
#109Earlier quoted context omitted.
This is not how the law works anywhere, thankfully.
Well for one it was a gift so there is no valid contract right? There are no direct damages because there is nothing paid and nothing to refund. Wrt indirect damages, there's bound to be a disclaimer or two, at least at the app layer. IANAL, not legal advice
Re: How to gain code execution on hundreds of millions of people and popular apps
#110Dave here, founder of ToDesktop. I've shared a write-up: https://www.todesktop.com/blog/posts/security-incident-at-to... This vulnerability was genuinely embarrassing, and I'm sorry we let it happen. After thorough internal and third-party audits, we've fundamentally restructured our security practices to ensure this scenario can't recur. Full details are covered in the linked write-up. Special thanks to Eva for resp…