Ranter
Join devRant
Do all the things like
++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatar
Sign Up
Pipeless API
From the creators of devRant, Pipeless lets you power real-time personalized recommendations and activity feeds using a simple API
Learn More
Comments
-
How is it different from any desktop application? Hell, how is that even news?
Yes you can alter an application's behaviour by editing local files and yes if you download a binary from an untrustworthy source it might not be what you're expecting.
This is common knowledge since what? 20 years now? -
The issue is that the cryptographic signature doesn't change. The same is not true in your examples @Commodore @PrivateGER
-
Yes it needs local access and yes a lot can be done if you have that anyway. I don’t think that’s the point of the article.
Making these changes doesn’t change the signature making it extremely difficult to detect. But the fact that it’s a flaw in electron (the platform) makes it much worse.
Someone will only attempt an attack if it’s worthwhile, like if there’s a high chance of finding users with the specific version of windows, running a specific version of the app. The fact that it’s every app, across every OS, and every version, makes it a bigger deal.
Then take into account that it’s apps like slack and Skype that companies use to discuss everything.
Then take into account my hatred of these tools and platforms ... and there ya go, things just got much worse! -
So if you think non-electron apps validate their checksums every bootup, I'd be banned on Steam for editing my configurations inside Counter Strike's folder.
But I don't.
* sigh
Following on with my “hybrid/cross-platform sucks donkey balls” thread
rant
cross-platform
hybrid
electron
bullshit
javascript