GoSign Desktop RCE flaws affecting users in Italy

(ush.it)

84 points | by ascii 3 days ago ago

29 comments

  • CodesInChaos 2 days ago ago

    I'm a bit confused by the privilege escalation part. Doesn't modifying the settings require the same privileges the application has?

    • SkiFire13 2 days ago ago

      I suppose the application runs as root (to update the application files) but reads the user settings (which are writable without root priviledges)

  • 3 days ago ago
    [deleted]
  • 4 days ago ago
    [deleted]
  • gritzko 3 days ago ago

    Paris Cloudflare Error

    • chasing0entropy 3 days ago ago

      AI scrapes internet from millions of IPs worldwide proving an orchestrated, intelligent, botnet effectually becoming a large percentage of total internet traffic overnight.

      Internet responds by retreating to behind a single cloud provider who can mysteriously keep ai at bay... Same provider network is probably responsible for the near instantaneous distribution of AI traffic to begin with.

      Internet's last bastion of hope is attacked, rather quickly, and half of the internet is scrambling to remember how to administer DNS (The other half never knew).

      • agos 3 days ago ago

        Cloudflare was already a thing before AI scrapers

        • immibis 3 days ago ago

          And they were strongly suspected to DDoS their prospective customers, so they would suddenly have a need to buy DDoS protection.

          • amalcon 2 days ago ago

            The claim I think you're referring to is in two parts:

            1) They were willing to sell DDoS protection to DDoS services

            2) This decision was made specifically because the existence of DDoS services increased the value of their product

            This was always a weird claim, because the first part is 100% true -- while the second part was always unfounded speculation. The conclusion is thus most likely false. They just didn't want to incorporate that sort of thing into their ToS or vet their customers in that way, for various understandable reasons.

          • steelbrain 3 days ago ago

            First I’m hearing of it, got a source?

          • gruez 2 days ago ago

            How does this work given there are many competing DDoS protection providers like Akamai, Azure, or AWS?

          • giancarlostoro 3 days ago ago

            That is a wild claim, got some evidence?

      • 3 days ago ago
        [deleted]
      • nullbyte808 3 days ago ago

        what is this "AI" your referring to?

    • N19PEDL2 2 days ago ago

      How is this related with the Cloudflare outage? The bug was present in GoSign Desktop <= 2.4.0, so it seems that it was introduced long time ago.

    • VladVladikoff 3 days ago ago

      Cloudflare yet again making the internet a shittier place. I will never understand why so many people willingly allow their website to be MiTM’d by this garbage company.

      • delichon 3 days ago ago

        Then I suppose you know a better alternative when your site is being effectively DDOSed by a ridiculously high volume of scrapers. Please share.

        • chasing0entropy 3 days ago ago

          There are so many CDNs, they have existed since the internet was just for porn. The problem is they are not as easy to use for today's novice webdev with zero knowledge of how to administer or even research infrastructure beyond the stack specs.

          • whizzter 3 days ago ago

            I don't think the issue is a skill one but rather giving a sane option.

            Going to Akamai's site I don't see a single mention of pricing, I don't want to be smooched by some enterprise salesman to get my pricing options.

            Going to Fastly's site I see egress costs that makes me think I could probably be better of just staying on AWS,Azure or smth and have a single bill to care about. (That have their own expensive options).

            There's probably other small players with sane options pricing wise, but when it comes to managing DDoS issues people want someone big to handle the bulk.

        • codingminds 3 days ago ago

          E.g. https://www.fastly.com/

          But Cloudflare has the best marketing of all of them ¯\_(ツ)_/¯

          • ramon156 3 days ago ago

            iirc isn't steam also on fastly? I vaguely remember their stack to either include fastly or they're using fastify. Names...

            • hofrogs 3 days ago ago

              I think Steam uses akamai, at least for user-generated content

              • codingminds 3 days ago ago

                Seems to be correct

                  store.steampowered.com. 30 IN A 184.31.101.220
                
                  NetRange:       184.24.0.0 - 184.31.255.255
                  CIDR:           184.24.0.0/13
                  NetName:        AKAMAI
    • deaux 3 days ago ago

      LA here.

    • nullbyte808 3 days ago ago

      Bonjour!

  • alan-jordan13 2 days ago ago

    [flagged]

    • Fire-Dragon-DoL 2 days ago ago

      Coming from Italy, the word "quickly" makes me think 20 years at least,lol

  • Barry-Perkins 2 days ago ago

    [flagged]

    • 2 days ago ago
      [deleted]