Live data from Hacker News

GoSign Desktop RCE flaws affecting users in Italy

ush.it

21–30 of 30 posts

Re: GoSign Desktop RCE flaws affecting users in Italy

#21
post #11
post #7

Earlier quoted context omitted.

Cloudflare was already a thing before AI scrapers

And they were strongly suspected to DDoS their prospective customers, so they would suddenly have a need to buy DDoS protection.

That is a wild claim, got some evidence?

Re: GoSign Desktop RCE flaws affecting users in Italy

#22
post #11
post #7

Earlier quoted context omitted.

Cloudflare was already a thing before AI scrapers

And they were strongly suspected to DDoS their prospective customers, so they would suddenly have a need to buy DDoS protection.

How does this work given there are many competing DDoS protection providers like Akamai, Azure, or AWS?

Re: GoSign Desktop RCE flaws affecting users in Italy

#26
post #11
post #7

Earlier quoted context omitted.

Cloudflare was already a thing before AI scrapers

And they were strongly suspected to DDoS their prospective customers, so they would suddenly have a need to buy DDoS protection.

The claim I think you're referring to is in two parts:

1) They were willing to sell DDoS protection to DDoS services

2) This decision was made specifically because the existence of DDoS services increased the value of their product

This was always a weird claim, because the first part is 100% true -- while the second part was always unfounded speculation. The conclusion is thus most likely false. They just didn't want to incorporate that sort of thing into their ToS or vet their customers in that way, for various understandable reasons.

Re: GoSign Desktop RCE flaws affecting users in Italy

#29

I'm a bit confused by the privilege escalation part. Doesn't modifying the settings require the same privileges the application has?

I suppose the application runs as root (to update the application files) but reads the user settings (which are writable without root priviledges)
Post reply on HN