Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nathan_naveen
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
nathan_naveen
1y ago
Nice! Looks cool!
2.
▲
by
nathan_naveen
1y ago
VMs are themselves untrustworthy we should be computing with paper and pencil (and flipping bits with an eraser)... Lol!
3.
▲
by
nathan_naveen
1y ago
Exactly, that is our thought process! We know that this isn't anything revolutionary, but most people assume that this kind of thing can't happen, so we wrote a blog post about it.
4.
▲
by
nathan_naveen
1y ago
Question... if you change the path wouldn't a decent security tool be able to identify that it is a different executable? Also, if you are allowing an executable to access a directory then the executable should also be protected. Thoug
5.
▲
by
nathan_naveen
1y ago
The idea for this blog post was that if someone becomes a user in your system but you have a basic security policy in place how can they circumvent it. That is how we came across LD_PRELOAD.
6.
▲
by
nathan_naveen
1y ago
KubeArmor...
7.
▲
by
nathan_naveen
1y ago
Hey, we agree that if someone can modify your env variables you have got problems ;) But, if you have valuable data on your system then you should have defense in depth so that your most important stuff (secrets, etc...) isn't stolen.
8.
▲
by
nathan_naveen
1y ago
Thank you! We will take a look!
9.
▲
by
nathan_naveen
1y ago
Yeah... we thought the same thing but we checked a couple other EDRs and saw that a few of them don't do this. If you guys know some EDRs that do this, let us know :)
10.
▲
by
nathan_naveen
1y ago
Hey, the author here... Our blog post is mainly talking about how the vulnerability works, but even if there is an insider threat (or reverse shell or any kind of attack) there are ways to stop this. We at Bomfather have a solution for this
11.
▲
LD_PRELOAD, The Invisible Key Theft
(bomfather.dev)
38 points
by
nathan_naveen
1y ago
|
46 comments
12.
▲
by
nathan_naveen
1y ago
Thanks for your thoughts! Yeah, that is exactly what we thought, so we are migrating our runner to our own infra.
13.
▲
by
nathan_naveen
1y ago
Hey, I'm a co-founder of Bomfather, we just stumbled upon this problem when we were building our product. Our product doesn't actually secure this, the best solution is to just run your own private runner.
14.
▲
by
nathan_naveen
1y ago
We are a security startup and we wanted to know what goes into our build server (which happened to be GH runners). We took a deeper look in the Ubuntu-latest runners and went down the rabbit hole.
15.
▲
GitHub's Ubuntu Runners Have 1,681 Packages and 9 High Severity Vulns
(bomfather.dev)
5 points
by
nathan_naveen
1y ago
|
5 comments