Security Weekly Podcast Network (Audio)

VSCode Vulnerabilities - Thomas Chauchefoin, Paul Gerste - PSW #804

Oct 26, 2023
Thomas Chauchefoin and Paul Gerste, Sonar Vulnerability Researchers, discuss their research on the security of Visual Studio Code, uncovering ways for attackers to gain code execution. They highlight the risk to developers and the accidental $30,000 bounty they received from Microsoft for these bugs.
Ask episode
Chapters
Transcript
Episode notes
1
Introduction
00:00 • 2min
2
Welcoming Back David Johnson, Introducing Josh Morpitt, and New Co-Host Bill Swearngen
02:22 • 2min
3
Supporting CISO Community and Hardware Hacking with Nitric Acid
04:23 • 2min
4
Iron Key and the Challenges of Decrypting Cryptocurrency
06:38 • 13min
5
Perception and Vulnerabilities of PHP
19:48 • 11min
6
Discussion on Infrared Add-ons and Diodes
30:57 • 1min
7
Customized Cases and Successful 3D Printing
32:01 • 11min
8
GPS Tampering and Spoofing
43:26 • 20min
9
Discussion on the Convenience and Durability of a Folding Phone
01:03:30 • 2min
10
Customer Service and Bluetooth Anecdotes
01:05:25 • 9min
11
The Importance of Command Line Interface for Cisco Devices
01:14:20 • 20min
12
Choosing Default Apps and Importance of Privacy
01:34:24 • 9min
13
Raspberry Pi 5 and its Features
01:43:22 • 18min
14
Reverse Engineering Zavio IP Cameras
02:01:49 • 9min
15
Backgrounds, Capture the Flag, and Initial Projects at Sonar
02:10:20 • 3min
16
Security Implications of Electron for Desktop Clients
02:13:31 • 2min
17
Analyzing the Design and Security of VSCode
02:15:14 • 19min
18
Charitable Donations for Research Bounty
02:34:40 • 9min
19
VSCode Security Vulnerabilities and Supply Chain Attacks
02:43:54 • 14min