• wewbull@feddit.uk
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 months ago

    I wouldn’t be so quick to write it off.

    It’s a proof of concept showing the weaknesses in Microsoft’s vetting process for extensions published on the store. They then used the process to get pseudo-malicious code inside hundreds of organisations (not hundred of installs) some of which are high profile.

    • FizzyOrange@programming.dev
      link
      fedilink
      arrow-up
      0
      ·
      5 months ago

      Microsoft doesn’t have a vetting process for publishing extensions in the store. Maybe the failure is that people assume they do?

      • Miaou@jlai.lu
        link
        fedilink
        arrow-up
        1
        ·
        5 months ago

        Surely you mean “that Microsoft does not make it clear that they don’t”?

        • FizzyOrange@programming.dev
          link
          fedilink
          arrow-up
          1
          ·
          edit-2
          5 months ago

          Maybe, but I think the only app store that does vet apps is the Apple one, so that should be the default expectation.

          And I think even they wouldn’t manually look for something like this. They’re mainly concerned about people breaking the commercial rules.