4 ms·
Is it still possible to unpack the asar, rewrite the source, and repackage the asar?
by cfv 7y ago
Is it still possible to unpack the asar, rewrite the source, and repackage the asar?
- guessmyname 7y ago> Is it still possible to unpack the asar, rewrite the source, and repackage the asar? Yes, it is still possible — https://github.com/electron/asar https://github.com/electron/asar
- bobblywobbles 7y ago(author) Yes, it is quite possible to do that. One of my down the road goals is to add light obfuscation to the source code upon packaging. If anyone is motivated, they can break into _any_ source code and repackage. I'd also like to add some form of checksumming, but again if they have access to the source code they can change anything they want to.
- jimbobimbo 7y agoCode signing with a trusted cert is what really helps in this scenario.
- cjbprime 7y agoIt's tough due to platform limitations -- e.g. I think that macOS codesigning will only sign binaries, and your JS/ASAR files are not binaries.
- jimbobimbo 7y agoShouldn't Electron be a "platform" in this case, and provide affordances for that?
- cjbprime 7y agoIt is better to use OS codesigning than hand-built codesigning because then the OS can enforce it -- e.g. App A can't overwrite App B. Anything you hand-roll can be unrolled by an attacker. I guess my preferred solution for be for Electron to find a way to put the ASAR inside the main binary and find it there and then codesign that, I'm not sure why it hasn't happened yet AFAIK.
- jimbobimbo 7y agoIt depends what the threat model is. My understanding of Electron apps is that the binary part of the app (Chromium, node, whatever are the parts of the Electron that present the app to the user) is not changing all that often, while web app bits can be updated by simply downloading new version from the publisher's site (correct me if I'm off base here). If this is the case, then the threat here would be the attacker MITM'ing communications between the user and publisher's site and serving malicious payload to the user. Electron validating the signature before serving downloaded bits would mitigate the threat even without OS support (remember - Electron haven't changed, only web app bits have). Note that I'm saying "Electron validating the signature" - not web app doing that, which I assume what you meant by "hand-rolling".