

Long story short: Microsoft just helped pop an alleged hacker using some windows device ID. I linked to a post in the hackernews thread about d-bus:


Long story short: Microsoft just helped pop an alleged hacker using some windows device ID. I linked to a post in the hackernews thread about d-bus:


Who defines the untrusted applications though?
¯\(ツ)/¯
If GNOME wrote it then they probably trust it. If you’re using GNOME, then you’ve accepted their security model on some level.
At least you know to go look for it. Attackers will only get more sophisticated:


according to their stated security model, untrusted applications must not be allowed to communicate with the secret service.
That won’t be a popular stance to take when someone eventually steals a bunch of cached, unlocked credentials off of D-BUS because of an oversight somewhere in the npm/aur/pip/cargo/whatever ecosystem.
More rabbit hole:
Ah, sorry.
D-Bus has a similar mechanism to the one that got this hacker arrested. I guess I was expanding upon the previous conversation about how much stuff is considered inside the inner security circle for d-bus.