Forgot your password?
typodupeerror

Submission + - Skype, Slack, Other Electron-Based Apps Can Be Easily Backdoored (arstechnica.com)

An anonymous reader writes: The Electron development platform is a key part of many applications, thanks to its cross-platform capabilities. Based on JavaScript and Node.js, Electron has been used to create client applications for Internet communications tools (including Skype, WhatsApp, and Slack) and even Microsoft's Visual Studio Code development tool. But Electron can also pose a significant security risk because of how easily Electron-based applications can be modified without triggering warnings. At the BSides LV security conference on Tuesday, Pavel Tsakalidis demonstrated a tool he created called BEEMKA, a Python-based tool that allows someone to unpack Electron ASAR archive files and inject new code into Electron's JavaScript libraries and built-in Chrome browser extensions. The vulnerability is not part of the applications themselves but of the underlying Electron framework—and that vulnerability allows malicious activities to be hidden within processes that appear to be benign. Tsakalidis said that he had contacted Electron about the vulnerability but that he had gotten no response—and the vulnerability remains.

While making these changes required administrator access on Linux and MacOS, it only requires local access on Windows. Those modifications can create new event-based "features" that can access the file system, activate a Web cam, and exfiltrate information from systems using the functionality of trusted applications—including user credentials and sensitive data. In his demonstration, Tsakalidis showed a backdoored version of Microsoft Visual Studio Code that sent the contents of every code tab opened to a remote website. The problem lies in the fact that Electron ASAR files themselves are not encrypted or signed, allowing them to be modified without changing the signature of the affected applications. A request from developers to be able to encrypt ASAR files was closed by the Electron team without action.

Submission + - Ecuador hands over Julian Assange's belongings to US (bbc.com)

Joce640k writes: Ecuador has begun giving the US some of Wikileaks co-founder Julian Assange's possessions left behind following his stay in its London embassy. The material includes manuscripts, legal papers, medical records and electronic equipment.

Mr Assange's lawyer said the move was "completely unprecedented in the history of asylum".

"Ecuador is committing a flagrant violation of the most basic norms of the institution of asylum by handing over all the asylee's personal belongings indiscriminately to the country that he was being protected from," added lawyer Aitor Martinez.

Submission + - Arizona attempts to make trolling illegal. (yahoo.com) 1

LordofEntropy writes: "Though unlikely to pass any First Amendment test. Arizona's Gov. Jan Brewer has a bill on her desk that would in essence make "trolling" illegal. The law states "It is unlawful for any person, with intent to terrify, intimidate, threaten, harass, annoy or offend, to use ANY ELECTRONIC OR DIGITAL DEVICE and use any obscene, lewd or profane language or suggest any lewd or lascivious act, or threaten to inflict physical harm to the person or property of any person.""

Slashdot Top Deals

Keep the number of passes in a compiler to a minimum. -- D. Gries

Working...