

VSCode Vulnerabilities - Thomas Chauchefoin, Paul Gerste - PSW #804
Oct 26, 2023
Thomas Chauchefoin and Paul Gerste, Sonar Vulnerability Researchers, discuss their research on the security of Visual Studio Code, uncovering ways for attackers to gain code execution. They highlight the risk to developers and the accidental $30,000 bounty they received from Microsoft for these bugs.
Chapters
Transcript
Episode notes
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19
Introduction
00:00 • 2min
Welcoming Back David Johnson, Introducing Josh Morpitt, and New Co-Host Bill Swearngen
02:22 • 2min
Supporting CISO Community and Hardware Hacking with Nitric Acid
04:23 • 2min
Iron Key and the Challenges of Decrypting Cryptocurrency
06:38 • 13min
Perception and Vulnerabilities of PHP
19:48 • 11min
Discussion on Infrared Add-ons and Diodes
30:57 • 1min
Customized Cases and Successful 3D Printing
32:01 • 11min
GPS Tampering and Spoofing
43:26 • 20min
Discussion on the Convenience and Durability of a Folding Phone
01:03:30 • 2min
Customer Service and Bluetooth Anecdotes
01:05:25 • 9min
The Importance of Command Line Interface for Cisco Devices
01:14:20 • 20min
Choosing Default Apps and Importance of Privacy
01:34:24 • 9min
Raspberry Pi 5 and its Features
01:43:22 • 18min
Reverse Engineering Zavio IP Cameras
02:01:49 • 9min
Backgrounds, Capture the Flag, and Initial Projects at Sonar
02:10:20 • 3min
Security Implications of Electron for Desktop Clients
02:13:31 • 2min
Analyzing the Design and Security of VSCode
02:15:14 • 19min
Charitable Donations for Research Bounty
02:34:40 • 9min
VSCode Security Vulnerabilities and Supply Chain Attacks
02:43:54 • 14min