11 ms·
How to gain code execution on hundreds of millions of people and popular apps
- oguz-ismail 2y ago[flagged]
- spudlyo 2y agoWhy does it use Neko the cursor chasing cat? Why the goth color scheme? These are stylistic choices, there is no explaining them.
- nickthegreek 2y agowoah, the cat chases your taps on mobile!
- nkrisc 2y agoThankfully there is reader mode. That dumb cat is so obnoxious on mobile.
- jpbastyr 2y agojust the style of their blog
- nickthegreek 2y agoit’s a blog. people regularly use their personal sites to write in a tone and format that they are fond of. i only normally feel like i see this style from people who were on the internet in the 90s. i’d imagine we would see it even more if phones and auto correct didn’t enforce a specific style. imagine being a slave to the shift key. it can’t even fight back! i’m more upset the urls aren’t actually clickable links.
- edm0nd 2y agoits cool. not everything has to be typed in a "normal" way.
- AndrewStephens 2y agowhy do the stars shine? why does rain fall from the sky? using upper case is just a social convention - throw off your chains.
- QuadmasterXLII 2y agoFinding an RCE for every computer running cursor is cool, and typing in all lowercase isn’t that cool. Finding an RCE on millions of computers has much much higher thermal mass than typing quirks, so the blog post makes typing in all lowercase cool.
- ge96 2y agothe cat chase cursor thing is great
- deleted 2y ago[deleted]
- davej 2y agoDave here, founder of ToDesktop. I've shared a write-up: https://www.todesktop.com/blog/posts/security-incident-at-todesktop https://www.todesktop.com/blog/posts/security-incident-at-to... This vulnerability was genuinely embarrassing, and I'm sorry we let it happen. After thorough internal and third-party audits, we've fundamentally restructured our security practices to ensure this scenario can't recur. Full details are covered in the linked write-up. Special thanks to Eva for responsibly reporting this.
- spudlyo 2y ago> cannot happen again. Hubris. Does not inspire confidence. > We resolved the vulnerability within 26 hours of its initial report, and additional security audits were completed by February 2025. After reading the vulnerability report, I am impressed at how quickly you guys jumped on the fix, so kudos. Did the security audit lead to any significant remediation work? If you weren't following PoLP, I wonder what else may have been overlooked?
- davej 2y agoFair point. Perhaps better phrased as "to ensure this scenario can't recur.". I'll edit my post. Yes, we re-architected our build container as part of remediation efforts, it was quite significant.
- deleted 2y ago[deleted]
- ddingus 2y agoThat was solid. Nice way to handle a direct personal judgement! Not your first rodeo. Another way is to avoid absolutes and ultimatums as aggressively as one should avoid personal judgements. Better phrased as: "we did our best to prevent this scenario from happening again. Fact is it just could happen! Nobody likes that reality, and overall when we think about all this stuff, networked computing is a sad state of affairs.. Best to just be 100 percent real about it all, if you ask me. At the very least people won't nail you on little things, which leaves you something you may trade on when a big thing happens. And yeah, this is unsolicited and worth exactly what you paid. Was just sharing where I ended up on these things in case it helps
- rvz 2y agoMy goodness. So much third-party risk upon risk and lots of external services opening up this massive attack surface and introducing this RCE vulnerability. From an Electron bundler service, to sourcemap extraction and now an exposed package.json with the container keys to deploy any app update to anyone's machine. This isn't the only one, the other day Claude CLI got a full source code leak via the same method from its sourcemaps being exposed. But once again, I now know why the entire Javascript / TypeScript ecosystem is beyond saving given you can pull the source code out of the sourcemap and the full credentials out of a deployed package.json.
- XorNot 2y ago> But once again, I now know why the entire Javascript / TypeScript ecosystem is beyond saving given you can pull the source code out of the sourcemap and the full credentials out of a deployed package.json. You've always been able to do the first thing though: the only thing you can do is obfuscate the source map, but it's not like that's a substantial slowdown when you're hunting for authentication points (identify API URLs, work backwards). And things like credentials in package.json is just a sickness which is global to computing right now: we have so many ways you can deploy credentials, basically 0 common APIs which aren't globals (files or API keys) and even fewer security tools which acknowledge the real danger (protecting me from my computers system files is far less valuable then protecting me from code pretending to be me as my own user - where all the real valuable data already is). Basically I'm not convinced our security model has ever truly evolved beyond the 1970s where the danger was "you damage the expensive computer" rather then "the data on the computer is worth orders of magnitude more then the computer".
- gamedever 2y agoBlaming Js/Ts is ridiculous. All those same problems exist in all environments. Js/Ts is the biggest so it gets the most attention but if you think it's different in any other environment you're fooling yourself.
- TZubiri 2y agoEcosystem, not the lang itself. It truly is a community issue, it's not a matter of the lang. You will never live down fucking left-pad
- GuestFAUniverse 2y ago" please do not harass these companies or make it seem like it's their fault, it's not. it's todesktop's fault if anything) " I don't get it. Why would it be "todesktop's fault", when all the mentioned companies allowed to push updates? I had these kind of discussions with naive developers giving _full access_ to GitHub orgs to various 3rd party apps -- that's never right!
- stefan_ 2y agoYeah, it is their fault. I don't download "todesktop" (to-exploit), I download Cursor. Don't give 3rd parties push access to all your clients, that's crazy. How can this crappy startup build server sign a build for you? That's insane.
- floydnoel 2y agoit blows me away that this is even a product. it's like a half day of dev time, and they don’t appear to have over-engineered it or even done basic things given the exploit here.
- cdmyrm 2y agoSoftware developers don't actually write software anymore, they glue together VC-funded security nightmares every 1-3 years, before moving on to the next thing. This goes on and on until society collapses under its own weight.
- XCabbage 2y agoIn my experience, blame for this basically never lies on grunt-level devs; it's EMs and CTOs/CIOs who insist on using third-party products for everything out of some misguided belief that it will save dev time and it's foolish to reinvent the wheel. (Of course, often figuring out how to integrate a third-party wheel, and maintain the integration, is predictably far more work for a worse result than making your own wheel in the first place, but I have often found it difficult to convince managers of this. In fairness, occasionally they're right and I'm wrong!)
- asciii 2y ago> i wanted to get on the machine where the application gets built and the easiest way to do this would be a postinstall script in package.json, so i did that with a simple reverse shell payload From ToDesktop incident report, > This leak occurred because the build container had broader permissions than necessary, allowing a postinstall script in an application's package.json to retrieve Firebase credentials. We have since changed our architecture so that this can not happen again, see the "Infrastructure and tooling" and "Access control and authentication" sections above for more information about our fixes. I'm curious to know what the trial/error here was to get their machine to spit out the build or if it was in one-shot
- hassleblad23 2y agoI would start by dumping the enviornment variables and directory structure.
- giantg2 2y agoWith rhe number of dependencies and dependency trees going multiple levels deep? Third party risk is the largely unaddressed elephant in the room that companies don't care about.
- TZubiri 2y agoI started to use -paid operating system (rhel) with a team of paid developers and maintainers verifying builds and dependencies. - empty dependencies. Only what the core language provides. It's not that great of a sacrifice. Like 20$/mo for the OS. And like 2 days of dev work which pays itself off in the long run by avoiding a mass of code you don't understand
- vekatimest 2y agoThe cat is cute but I'd rather not have it running in front of the text while I'm trying to read and use my cursor.
- ok_dad 2y agoCats tend to do that.
- internetter 2y agoThen just… put the cursor in the corner? The blog isn’t interactive or anything. I think the cat is cute.
- gblargg 2y agoI had to go back and enable JavaScript. Wow, is the goal to direct my attention away from reading the text?
- carcabob 2y agoIronically, it actually helped me stay focused on the article. Kind of like a fidget toy. When part of my brain would get bored, I could just move the cat and satisfy that part of my brain while I keep reading. I know that sounds kind of sad that my brain can't focus that well (and it is), but I appreciated the cat.
- ok_dad 2y agoI can't see the cat! I went back and it just isn't working for me. I'm sad, I like cats.
- lloeki 2y agoHere it is: https://en.m.wikipedia.org/wiki/Neko_(software) https://en.m.wikipedia.org/wiki/Neko_(software) Ah, whimsy memories of running that on beige boxen of my youth. Also remember a similar thing with some Lemmings randomly falling and walking around on windows. Played way too long having them pile up and yank the window from under them.
- mcoliver 2y ago"i wanted to get on the machine where the application gets built and the easiest way to do this would be a postinstall script in package.json, so i did that with a simple reverse shell payload" Just want to make sure I understand this. They made a hello world app and submitted it to todesktop with a post install script that opened a reverse shell on the todesktop build machine? Maybe I missed it but that shouldn't be possible. Build machine shouldn't have outbound open internet access right?? Didn't see that explained clearly but maybe I'm missing something or misunderstanding.
- trallnag 2y agoIsn't it really common for build machines to have outbound internet access? Millions of developers use GitHub Actions for building artifacts and the public runners definitely have outbound internet access
- arccy 2y agoA few decades ago, it was also really common to smoke. Common != good, github actions isn't a true build tool, it's an arbitrary code runtime platform with a few triggers tied to your github.
- tomjakubowski 2y agoIndeed, you can indeed punch out from an actions runner. Such a thing is probably against GitHub's ToS, but I've heard from my third cousin twice removed that his friend once ssh'ed out from an action to a bastion host, then used port forwarding to get herself a shell on the runner in order to debug a failing build.
- gtirloni 2y agoSo this friend escaped from the ephemeral container VM into the build host which happened to have a private SSH on it that allowed it to connect to a bastion host to... go back to the build host and debug a failed build that should be self-contained inside the container VM which they already had access in the first place by the means of, you know, running a build on it? Interesting.
- felixrieseberg 2y agoAs an Electron maintainer, I'll re-iterate a warning I've told many people before: Your auto-updater and the underlying code-signing and notarization mechanisms are sacred. The recovery mechanisms for the entire system are extremely painful and often require embarrassing emails to customers. A compromised code-sign certificate is close to the top of my personal nightmares. Dave and toDesktop have build a product that serves many people really well, but I'd encourage everyone building desktop software (no matter how, with or without toDesktop!) to really understand everything involved in compiling, signing, and releasing your builds. In my projects, I often make an argument against too much abstraction and long dependency chain in those processes. If you're an Electron developer (like the apps mentioned), I recommend: * Build with Electron Forge, which is maintained by Electron and uses @electron/windows-sign and @electron/osx-sign directly. No magic. * For Windows signing, use Azure Trusted Signing, which signs just-in-time. That's relatively new and offers some additional recovery mechanisms in the worst case. * You probably want to rotate your certificates if you ever gave anyone else access. * Lastly, you should probably be the only one with the keys to your update server.
- paradite 2y agoHi. I'm an electron app developer. I use electron builder paired with AWS S3 for auto update. I have always put Windows signing on hold due to the cost of commercial certificate. Is the Azure Trusted Signing significantly cheaper than obtaining a commercial certificate? Can I run it on my CI as part of my build pipeline?
- felixrieseberg 2y agoAzure Trusted Signing is one of the best things Microsoft has done for app developers last year, I'm really happy with it. It's $9.99/month and open both to companies and individuals who can verify their identity (it used to only be companies). You really just call signtool.exe with a custom dll. I wrote @electron/windows-sign specifically to cover it: https://github.com/electron/windows-sign https://github.com/electron/windows-sign Reference implementation: https://github.com/felixrieseberg/windows95/blob/master/forge.config.js#L26-L31 https://github.com/felixrieseberg/windows95/blob/master/forg...
- orliesaurus 2y agoToDesktop vulnerability: not surprised. Trust broken.
- sky2224 2y agoThis is the second big attack found by this individual in what... 6 months? The previous exploit (which was in Arc browser), also leveraged a poorly configured firebase db: https://kibty.town/blog/arc/ https://kibty.town/blog/arc/ So this is to say, at what point should we start pointing the finger at Google for allowing developers to shoot themselves in the foot so easily? Granted, I don't have much experience with firebase, but to me this just screams something about the configuration process is being improperly communicated or overall is just too convoluted as a whole.
- nightpool 2y agoI don't think Firebase is really at fault here—the major issue they highlighted is that the deployment pipeline uploaded the compiled artifact to a shared bucket from a container that the user controlled. This doesn't have anything to do with firebase—it would have been just as impactful if the container building the code uploaded it to S3 from the buildbot.
- itsnotvalid 2y agoAgreed. I recently stumbled upon the fact that even Hacker News is using Firebase for exposing an API for articles. Caution should be taken when writing server-side software in general.
- cdmyrm 2y ago[flagged]
- 999900000999 2y agoFirebase let's anyone get started in 30 seconds. Details like proper usage, security, etc. Those are often overlooked. Google isn't to blame if you ship a paid product without running a security audit. I use firebase essentially for hobbyist projects for me and my friends. If I had to guess these issues come about because developers are rushing to market. Not Google's fault ... What works for a prototype isn't production ready.
- aorloff 2y agoI guess what I'm surprised at here is that a popular ? IDE would be delivered over a delivery platform like this (immature or not) I would've expected IDE developers to "roll their own"
- luxurytent 2y agoLove the blog aesthetic, and the same goes to all your friends (linked at the bottom).
- throitallaway 2y agoThe lack of capitalization made it difficult for me to quickly read sentences. I had to be much more intentful when scanning the text.
- noisy_boy 2y agoQuestion/idea: can't GitHub use LLMs to periodically scan the code for vulnerabilities like this and inform the repo owner? They can even charge for it ;)
- TZubiri 2y agoProblem: a tool built with LLMs for building LLMs with LLMs has a vuln Solution: more LLMs Snap out of it
- nonesuchuser 2y agoSo you're saying one more LLM?
- deleted 2y ago[deleted]
- cdmyrm 2y ago[flagged]
- graynk 2y agoYou mean like this, but worse? https://docs.github.com/en/code-security/code-scanning/introduction-to-code-scanning/about-code-scanning-with-codeql https://docs.github.com/en/code-security/code-scanning/intro...
- TZubiri 2y agoI can't post things like "what a bunch of clowns" due to hacker news guidelines so let me go by another more productive route. These people, the ones who install dependencies (that install dependencies)+, these people who write apps with AI, who in the previous season looped between executing their code and searching the error on stackoverflow. Whether they work for a company or have their own startup, the moment that they start charging money, they need to be held liable when shit happens. When they make their business model or employability advantage to take free code in the internet, add pumpkin spice and charge cash for it, they cross the line from pissing passionate hackers by defiling our craft, to dumping in the pool and ruining it for users and us. It is not sufficient to write somewhere in a contract that something is as is and we hold harmless and this and that. Buddy if you download an ai tool to write an ai tool to write an ai tool and you decided to slap a password in there, you are playing with big guns, if it gets leaked, you are putting other services at risk, but let's call that a misdemeanor. Because we need to reserve something stronger for when your program fails silently, and someone paid you for it, and they relied on your program, and acted on it. That's worse than a vulnerability, there is no shared responsibility, at least with a vuln, you can argue that it wasn't all your fault, someone else actively caused harm. Now are we to believe the greater risk of installing 19k dependencies and programming ai with ai is vulns? No! We have a certainty, not a risk, that they will fuck it up. Eventually we should license the field, but for now, we gotta hold devs liable. Give those of us who do 10 times less, but do it right, some kind of marketing advantages, it shouldn't be legal that they are competing with us. A vscode fork got how much in VC funding? My brothers lets take arms and defend. And defend quality software I say. Fear not writing code, fear not writing raw html, fear not, for they don't feel fear so why should you?
- vitiral 2y agohttps://civboot.org https://civboot.org Join me my brother or sister
- sendintheclowns 2y ago[flagged]
- FitCodIa 2y ago
- deleted 2y ago[deleted]
- eviks 2y ago> please do not harass these companies or make it seem like it's their fault, it's not It also is, they are responsible for which tech pieces they pick in constructing their own puzzle
- gunian 2y agotbh if i had one wish i would love to see how five eyes get root level access to every device seems an insane amount of data
- permo-w 2y agoI'm a huge fan of the writing style. it's like hacking gonzo, but with literally 0 fluff. amazing work and an absolute delight to read from beginning to end
- milesrout 2y ago[flagged]
- mikechalmers 2y agoObnoxious is a bit harsh - I liked the feeling it gave to the article, found it very readable and I had no trouble discerning sentences, especially with how they were broken up into paragraphs.
- kylecodes 2y ago"the build container now has a privileged sidecar that does all of the signing, uploading and everything else instead of the main container with user code having that logic." Does this info about the fix seem alarming to anyone else? It's not a full description, so maybe some important details are left out? My understanding is that containers are generally not considered a secure enough boundary. Companies such as AWS use micro VMs (Firecracker) for secure multi tenant container workloads.
- ksynwa 2y agoThis website loads extremely fast wow
- cdmyrm 2y agoServing HTML is actually really fast if you don't bolt 17 layers of JavaScript on top of it first.
- 29athrowaway 2y ago> security incidents happen all the time, its natural. what matters is the company's response, and todesktop's response has been awesome, they were very nice to work with. This was an excellent conclusion for the article.
- sneak 2y agoAutomatic update without some manual step by a user means that the devs have RCE on your machine. I made Signal fix this, but most apps consider it working as intended. We learned nothing from Solarwinds.
- neuralkoi 2y agoFrom the ToDesktop write-up: We have reviewed logs and inspected app bundles. No malicious usage was detected. There were no malicious builds or releases of applications from the ToDesktop platform. Is there an easy way to validate the version of Cursor one is running against the updated version by checking a hash or the like?
- donatj 2y agoAs someone who already has trouble reading due to eye issues, the lack of capital letters made this infuriatingly difficult to read.
- jongjong 2y agoI'm shocked at how insecure most software is these days. Probably 90% of software built by startups has a critical vulnerability. It seems to keep getting worse year on year. Before, you used to have to have deep systems knowledge to trigger buffer overflows. It was more difficult to find exploits. Nowadays, you just need basic understanding of some common tools, protocols and languages like Firebase, GraphQL, HTTP, JavaScript. Modern software is needlessly complicated and this opens up a lot of opportunities.
- mihaaly 2y ago> security incidents happen all the time Do they have to? Isn't this notion making developers sloppy?
- cdmyrm 2y agoYes.
- swiftcoder 2y ago> update: cursor (one of the affected customers) is giving me 50k USD for my efforts. Kudos to cursor for compensating here. They aren't necessarily obliged to do so, but doing so demonstrates some level of commitment to security and community.
- zx8080 2y ago> [please don't] make it seem like it's their fault, it's not. it's todesktop's fault if anything What?! It's not some kind of joke. This could _already_ literally kill people, stole money and ruin lives. It isn't even an option to avoid taking reaponsibility for the decisions which lead to security and safety of users for any app owner/author. It's as simple as this: no safety record to 3rd party - no trust, for sure. No security audit - no trust. No transparency in the audit - no trust. Failing to make the right decision does not exempt from the liability, and should not. Is it a kindergarden with "it's not me, it's them" play? It does not matter who failed, the money could has been be stolen already from the random ones (who just installed an app wrapped with this todesktop installer), and journalists could have been tracked and probably already killed in some dictatorship or conflict. Bad decisions does not always make the bad owner. But don't take it lightly, and don't advocate (for those who just paid you some money) "oh, they are innocent". As they are not. Be a grown-up, please, and let's make this world better together.
- bashback 2y agoThe problem is that this entire sclerotic industry is so allergic to accountability, that, if you want people to start, you probably have to fire 90% of the workforce. If it were up to me, the developers responsible for this would never write software "professionally" again.
- zx8080 2y agoThe industry (or a couple of generations currently inhabiting it) could start with at least accepting responsibility when something goes wrong. Let me be clear: it's not about ending the "blameless culture" in engineering. No. It's about ending the culture of not taking any responsibility at all, when things go south. See the difference.
- milesrout 2y agoBit breathless. How could this kill people?
- piuantiderp 2y ago"range of hundreds of millions of people in tech environments, other hackers, programmers, executives, etc. making this exploit deadly if used." Bit too hyperbolic or whatever... Otherwise thrilling read!
- cdmyrm 2y ago[flagged]
- cdmyrm 2y ago1. Build a rootkit into your product. 2. Release your product.
- procaryote 2y agoThe javascript world has a culture of lots of small dependencies that end up becoming a huge tree no one could reasonable vendor or audit changes for. Worse these small dependencies churn much faster than for other languages. With that culture supply chain attacks and this kind of vulnerability will keep happening a lot. You want few dependencies, you want them to be widely used and you want them to be stable. Pulling in a tree of modules to check if something is odd or even isn't a good idea.
- m11a 2y agoI’d like to see some thoughts on where we go from here. Is there a way we can keep end users protected even despite potential compromise of services like ToDesktop? (eg: companies still hosting some kind of integrity checking service themselves and the download is verified against that… likely there’s smarter ideas) The user experience of auto-update is great, but having a single fatal link in the chain seems worrying. Can we secure it better?
- ludicrousdispla 2y agoThe first step I'd recommend is to not use Electron when building a native app.
- moktonar 2y agoUnfortunately it’s easy to overlook the SPoF. This will happen again and again. Cloudflare, I’m looking at you..
- maxlin 2y agoOof. I already have enough stress of my own autoupdating, single-file remote access tool I run on all of my computers, given at a small part of the custom OTA mechanics' security is by obscurity. Would make sleeping hard owning something as popular as this.
- oncallthrow 2y agoSo TL;DR the vuln here is that ToDesktop injected production secrets in the container they use to build customer-supplied images. This is completely incompetent to the point of gross negligence. There is no excuse for this
- dboreham 2y agoAs usual, I read the comments here first. I'm glad I read the article though because the comments here have pretty much nothing to do with the vulnerability. Here's a summary because the article actually jumps over explaining the vulnerability in the gap between two paragraphs: This service is a kind of "app store" for JS applications installed on desktop machines. Their service hosts download assets, with a small installer/updater application running on the users' desktop that pulls from the download assets. The vulnerability worked like this: the way application publishers interact with the service is to hand it a typical JS application source code repo, which the service builds, in a container in typical CI fashion. Therefore the app publisher has complete control over the build environment. Meanwhile, the service performs security-critical operations inside that same container, using credentials from the container image. Furthermore, the key material used to perform these operations is valid for all applications, not just the one being built. These two properties of the system: 1. build system trusts the application publisher (typical, not too surprising) and 2. build environment holds secrets that allow compromise of the entire system (not typical, very surprising), over all publishers not just the current one, allow a malicious app publisher to subvert other publishers' applications.
- cytocync 2y ago[dead]
- graynk 2y agoI somewhat enjoy the fact that every time this blog gets posted, half of the comments are about the cat and lack of capital letters.
- palata 2y agoLoved the cat, hated the lack of capital letters :D
- ryanmccullagh 2y agoIn top down orgs, no product manager care would blink a the at wasting time on security. This is why we need to remove incompetent product managers that have no clue and somehow are in the position to control what developers can work on.
- hackburg 2y ago[dead]
- hackburg 2y ago[dead]
- rurban 2y agoOff topic: She has the same name Eva Ivy as the Russian singer. Are they the same?
- najwayaminah 2y ago[dead]