rysiek,
@rysiek@mstdn.social avatar

So wait building all these "secure" chat apps on a browser engine packaged in a thin layer of UI, with its insane number of dependencies and the gigantic, immense attack surface that this entails, was somehow a bad idea?

Who knew! Who could have foreseen this! Shocking, really.

selfisekai,

@rysiek oh hey I wrote a bit about this one. https://liberda.nl/weblog/from-source-or-vulnerable/

gunstick,
@gunstick@mastodon.opencloud.lu avatar

@selfisekai @rysiek isnt all this docker, flatpacks and snaps stuff the same issue that each one comes with their own copy of the library needing a dedicated patch?

rysiek,
@rysiek@mstdn.social avatar
teajaygrey,
@teajaygrey@rap.social avatar

@rysiek A joke in meme form.

Srsly though, the Matasano blog is long gone and I don't feel like dredging up things from the Wayback Machine right now either, but I swear @tqbf has harped upon similarly themed perils for an awfully long time now?

To abstract away even further: it's not just apps that bundle themselves as browsers (e.g. yuck at Signal Electron BS) that succumb to similar pitfalls.

VMs that have outdated toolchains with vulnerabilities, "containers" with similar challenges, etc.

Of course, there are also the software preservationists among others who may have valid reasons for keeping old (vulnerable) toolchains going, but as one colleague phrased it with regards to such precarious things which may occasionally be necessitated: "Not on a publicly routable network, behind at least three layers of firewalls."

eschaton,
@eschaton@mastodon.social avatar

@rysiek The one saving grace is that some of them at least designed and implemented a protocol, allowing them to stop pretending a web age is an application and actually write something native when they come to their senses.

sasha92,
@sasha92@c.im avatar

@rysiek At least Electron apps are super easy for the average user to update.

benpocalypse,
@benpocalypse@mastodon.social avatar

@rysiek I often think of this talk, about "The 30 million line problem."

https://youtu.be/kZRE7HIO3vk

theavidhorizon,

@rysiek God, I used to yell at people like a raving lunatic about the dangers of using this kind of garbage masqueraded as software. I really don't like it when I end up being right about this, because everyone loses.

Benfell,

@rysiek

Care to name names?

rysiek,
@rysiek@mstdn.social avatar

@Benfell libwebp CVSS 10.0 vulnerability affecting anything built on Electron, and being exploited in the wild:
https://thehackernews.com/2023/09/new-libwebp-vulnerability-under-active.html

condalmo,
@condalmo@mstdn.social avatar

@rysiek What apps are we referring to

daisy55,

@rysiek okay, but, we have unlimited custom emoji so

rysiek,
@rysiek@mstdn.social avatar

@daisy55 and stickers. Let's not forget the stickers!

pfm,
@pfm@edolas.world avatar
pfm,
@pfm@edolas.world avatar

@rysiek aw damn, it was supposed to be animated :blobfoxupset:

  • All
  • Subscribed
  • Moderated
  • Favorites
  • infosec
  • DreamBathrooms
  • ngwrru68w68
  • cubers
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • mdbf
  • tacticalgear
  • JUstTest
  • osvaldo12
  • normalnudes
  • tester
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • anitta
  • Leos
  • provamag3
  • modclub
  • megavids
  • lostlight
  • All magazines