TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Chatbox (GPT desktop front end) malware / supply chain attack risk?

1 点作者 sdrinf10 个月前
Hey HN, supply chain evaluation question:<p>There is this awesome desktop app called chatbox: https:&#x2F;&#x2F;chatboxai.app&#x2F; &lt;- which I&#x27;ve been using for about 3 months now; essentially, it&#x27;s a desktop front-end for chatgpt API with very good local search across all previous conversations. Two red flags:<p>* 1, https:&#x2F;&#x2F;github.com&#x2F;Bin-Huang the author is Chinese, from China, working at Tencent.<p>* 2, As many other desktop apps, this also auto-updates; however:<p>* https:&#x2F;&#x2F;github.com&#x2F;Bin-Huang&#x2F;chatbox&#x2F;issues&#x2F;803 he had, essentially, started distributing binary-only updates, and the source code on github no longer reflects the actual app that is automatically downloaded to my computer<p>This is sus. How sus is it. Specifically: the attack vector I&#x27;m querying for is supply-chain attack via the auto-update mechanism. This thing has 20K stars on github, and around ~250K visits on their website (15% of this from the US = ~36K US visits per month;) probably predominantly devs. This is a <i>very</i> juicy target.<p>(Alternatively, and instant-upvote: looking for a desktop frontend for chatgpt API which has built-in full-text search for 2mb of plaintext, and integration for the full suite of LLMs currently available on the market, from a reliable source, for windows please.)

暂无评论

暂无评论