69 pointsby g-b-r4 hours ago9 comments
  • usr110633 minutes ago
    I don't use Telegram Desktop or Windows. But that's exactly the reason why I run Firefox in a firejail sandbox on Linux. The browser has only access to my Downloads folder. I know that it's considered untrusted and don't keep any files there for a long time.
    • freebsd_lovefes11 minutes ago
      Or the reason to run Firefox in a FreeBSD jail to get server-grade security. But the question is can an attacker get access to the Firefox profile data? Because you cannot block that from Firefox, obviously.
    • iririririr18 minutes ago
      interesting you mention. because Firefox doesn't have a way to disable the single instance functionality which was used on this telegram vulnerability.

      one long time Firefox contributor have been for a couple years now removing every part of the --noremote option. even botching (Ooops!) the console notice that the flag was no-op some time ago.

  • erelong2 hours ago
    I thought telegram was flagged as insecure like a decade ago, it's never really been "very secure"

    Like any number of articles like this: https://hackernoon.com/7-reason-why-telegram-is-insecure-by-...

    • misiek088 minutes ago
      Still we are using it, because UX kills any other app and people that are (probably) behind it will cause almost no harm to casual, not-interesting people :)

      And yes, I know that by default chats are not E2E, that phone number has way too many effects on accounts etc. Still, UX and agencies interested in important people are more welcome than data selling, ad-based companies.

    • phoronixrlyan hour ago
      Here's one from Filippo

      The Most Backdoor-Looking Bug I’ve Ever Seen - https://words.filippo.io/telegram-ecdh/

    • g-b-r2 hours ago
      Absolutely, but mostly for their protocols, statements, people and infrastructure.

      A file exfiltration vulnerability is still noteworthy.

  • anon_cow111141 minutes ago
    Imagine if you forgot to update your phone number with your personal bank, and then some random guy was given full access to your account and all of its contents. And even if you dug through the account options and set a 2FA password (normally disabled) he could still just delete your account outright.

    Last I checked, that's exactly how Telegram works by default. It's laughable to consider a service tied to a phone number secure.

  • opengrassan hour ago
    doas jexec -U opengrass tellyjail env DISPLAY=:0 Telegram
    • g-b-r44 minutes ago
      Yeah, something like that would not have prevented the account takeover part, though, which relies on Telegram's own files; or the access to cached files.
  • Panzerschrekan hour ago
    It's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file. Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory (like downloads for a browser or Telegram-client).
    • simonra15 minutes ago
      At the same time the mobile operating systems are vulnerable to vendor lock-in due to the absence of this functionality. It is clearly a worse problem that a user can't give their backup system access to the photos stored by other applications (often social media), or for instance reliably capture media streams to use in for instance a remixing application. Bringing custom clients when the software originally used to create the interesting files starts acting against the users by introducing subscriptions or being abandoned is another example of the user dictating what software accesses what files is critical to secure the users operations. Consumers need security against commercial interests infinitely much more than commercial interests need protections against consumers, and it would be unethical to enable commerce at the expense of individuals like the mobile operating systems do.
    • nvme0n1p1an hour ago
      If you don't believe it's a vulnerability, then you must believe that tricking Telegram into uploading your messages database to the attacker, leaking all your private conversations, is A-OK? Telegram owns that file, after all.
      • Panzerschrekan hour ago
        I didn't say it's not a vulnerability. It is clearly one. But allowing such vulnerabilities to deal damage beyond data of its host application is an OS vulnerability.
    • eviksan hour ago
      That's broadly-speaking a vulnerable design of all OSes, but strictly speaking it is a bug in Telegram that is now fixed at the app level. Though sandboxes / app isolation solutions exist even in the broadly vulnerable OSes, so apps could use them already today to avoid such issues in the future?
    • saagarjha41 minutes ago
      Telegram is available sandboxed from the Mac App Store on macOS.
    • penskymaterial44 minutes ago
      > It's a vulnerability of all modern desktop operating systems

      Uhm, OpenBSD would like a word, buddy.

      https://man.openbsd.org/unveil

    • g-b-ran hour ago
      It is.

      Not all user processes upload those files somewhere surreptitiously.

      Of course operating systems should support that isolation (hopefully in some better way than the hell that smartphones are), but it's not like Telegram can blame the OS for this vulnerability.

      • Panzerschrekan hour ago
        > Not all user processes upload those files somewhere surreptitiously.

        Only if you have access to full source code, can audit it (including each update) and somehow can prove that it has no vulnerabilities. Otherwise one should assume that any application is potentially-harmful and/or vulnerable.

        • g-b-ran hour ago
          Ok, at least if it has network access, but can you recognize that this was a vulnerability, and that you're talking of something only tangential to it?
  • KingOfCoders2 hours ago
    It's not a bug it's a feature.
    • iririririr17 minutes ago
      was a feature.

      technically, this is one agency burning the feature of another agency.

  • 2 hours ago
    undefined
  • g-b-r4 hours ago
    This link has already been posted with https://news.ycombinator.com/item?id=50019667 , but that post's title ("Telegram Desktop: one-click account takeover") doesn't say that the vulnerability allowed also any user-accessible file on the disk to be stolen.

    This aspect is also not highlighted much in the article, which weirdly mostly focuses on the account takeover.

    To me it seems something remarkable enough to warrant reposting the link with a different title.

    Somewhat astonishingly, the core of the vulnerability comes from an internal url scheme added to Telegram to... help them publish their releases on their channel.

    The Telegram developers saw no better way to do that than adding an internal tool which uploads any file it's told to.

    Everyone else publishing their app on Telegram is able to do that with a script, but they had to do it that way.

    It's true that it was exploitable only in a somewhat convoluted way, but still, it's an obviously dangerous feature.

    Anyhow, yes, clicking on a link in Telegram Desktop was enough to have any user's file exfiltrated and to access or take over their account.

    • arjie44 minutes ago
      That is such a JiaTan grade feature because it’s an insane way to implement it but also plausibly deniable.
  • bashtoni12 minutes ago
    Russian social media app has backdoor. Who would have thought?

    (Yes, I know they're technically Dubai based now)