Agost Biro pfp
Agost Biro
@agostbiro
App updater used by apps like Notion and Cursor could be hijacked to push arbitrary updates to these apps. This is why I'm extremely reluctant to install new apps on my host. For new stuff it's either browser based or goes into a VM. https://kibty.town/blog/todesktop/
2 replies
0 recast
4 reactions

Tudor 🟣🟡 pfp
Tudor 🟣🟡
@tudorizer
that’s the right approach, particularly in the context of sensitive data. I once worked with a DeFi startup and their dashboard for trading’s strategies was a bundled Electron app in a similar manner. Easy to deliver and looks “premium” to have a native app. That raised al kinds of flags in my mind. Sadly, this increases the number of moving pieces and a taller stack topples over quicker. Fine for some cases (eg. maybe Linear doesn’t hold sensitive data), critical in others.
0 reply
0 recast
1 reaction

MetaEnd🎩 pfp
MetaEnd🎩
@metaend.eth
All it takes is one app to poison your AI coder
0 reply
0 recast
1 reaction