Joanna Rootkovska ☠️ is a user on mastodon.social. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

About the Subgraph attack:
1. The main problem that @micahflee exploited is the unfortunate decision made by Subgraph OS to keep Gnome/Nautilus in the TCB *and* letting this complex software process *untrusted* files,
2. The specific Nautilus bug (handling of .desktop files) is just *one* example of what could go wrong in this case,
3. We can think of other potential problems (e.g. Thumbnails processing)
4. More details: micahflee.com/2017/04/breaking

Joanna Rootkovska ☠️ @rootkovska

Also, the Subgraph reaction has been baffling. They:
1. Ignored Micah's report for 2 weeks (which he gave them to patch) & did nothing to resolve the problem,
2. Downplayed/denied the bug once it got published: twitter.com/bleidl/status/8518
twitter.com/subgraph/status/85
3. Falsely implied that the bug affected QubesOS: twitter.com/bleidl/status/8518
4. Finally patched: twitter.com/subgraph/status/85

· Web · 11 · 19

@rootkovska Yeah... I really don't understand how getting calc to run **still contained in the same AppVM** is at all the same as bypassing intended sandbox restrictions.

@rootkovska The real jarring thing isn't that a supposedly secure software system has a vulnerability.
It happens to even the best of us. (although their design decision is mind-boggling, it should have been obvious)

No, the real issue is how they handled it: denial and dismissal.
The way a group deals with vulnerability reports tells you all you need to know about their product's security and whether they really care about security or about the mere *appearance* of security.