No, I do agree - from my perspective C/C++ class bugs are more difficult. Maybe they see this as magic as well.
Still, it was painstaking work and in either case CountryX will easily surpass those difficulties.
565 karma · joined August 29, 2020
No, I do agree - from my perspective C/C++ class bugs are more difficult. Maybe they see this as magic as well.
Still, it was painstaking work and in either case CountryX will easily surpass those difficulties.
(it’s more than 30MB of compressed JS)
There is little value in going through the email chains to note each date:(. Final decision was made 2020-11-19
I can’t call this “spoofing” as there are many many things you can do wih it
But if not addressed to me, there is no need to pay, you can start here: - https://www.electronjs.org/docs/tutorial/security - https://github.com/electron/electron/security/advisories
As you can see there are plenty of considerations and pitfalls to take into account. Best option is to enable contextIsolation for everything.
Further, Electron security is closely tied to Chrome security so that is one deep rabbit hole
I mean, do you look at that demo and think "yeah, that's technically just 'important' let's fix it in 2 months"?
not saying you are safe - I don’t know :)
the real answer is more complicated as it is not necessarily a global setting and depends on what you call a “sandbox”
I think it will take a long time before we can call ElectronJS secure. there are regular sandbox escapes and that is from what we know publicly
As for when it was fixed - I have no idea, as they never told me, one day it just was.
Even outside RCE, just consider the impact of access to SSO tokens and wormability :)
In this case it was possible to abuse lack of context isolation to overwrite functionality (first part of the JS exploit). This changed function behaviour to return (leak) a BrowserWindow class (https://www.electronjs.org/docs/api/browser-window) when calling window.open(). A BrowserWindow class allows to instantiate a new window with your own security settings :)
Some of the current non-standard functions in Slack: https://imgur.com/a/OSjS0kJ
More info: https://www.electronjs.org/docs/tutorial/security
In other cases maybe yes, maybe no - for some nonprofit, maybe someone needs help? are they a business and can they afford to compensate this kind of work? maybe it is some prominent product? there is no simple answer
I support and agree to everything you are saying. I love the community response. I too loathe the bug bounty asymmetry in power between corporations and reporters, but it exists.. by design. How do you imagine a researcher can 'demand' more money in this situation? They can choose the amounts arbitrarily and there is nothing legal or ethical you can do about it.
I haven't seen any proposals for real solutions - how would you ask this? How do you decide the amount for each company? Solutions, which do not bypass ethics or laws. I hope that 'the market' will solve this eventually and I think I at least raised awareness.
depends on exploit, program, company etc
However, bug bounties are not a job. Nobody is forced or obligated to do anything. I'm giving them 'a pass' in the future :) It's great people are discussing this and surely it will improve things for future researchers.
I consider bug bounties like competitions. The 'prize money' is defined beforehand. You don't have to compete if you don't want it. You can also compete for the 'notoriety'. Knowing the stakes, do you complain after getting 'first place'?
Everything you own or do is only worth as much as someone is willing to pay for it, everything else is just speculation.
99% of people saying something about black markets or govt agencies have never really faced this decision or thought about it for more than 5 minutes. So it was a question - have you REALLY thought about it?
Sure the bounty is low, but ultimately it's their money and their decision. They will deal with the 'consequences' of others skipping their program and some public shaming.
I find everyone talking about black markets etc. kind of ridiculous. Really? You would sell something like this, so someone can be spied upon or maybe literally chopped to pieces? Jesus, not everything is about money - it was a fun challenge to chain it all together and I learned a lot from it.
The most outrageous part for me was the blog post I discovered by accident - it included no references or mentions (check archive.org). Both of the code snippets there are from my RCE reports. At the same time they were denying my requests for disclosure.
Of course, I understand that coordination mistakes like this happen, so I accept their apology and move on!
Evidence - original RCE video with huge CSS injection overlay: https://www.dropbox.com/s/11pv2ghdkw5g84b/css-rce-overlay.mo...