Telegram Desktop vulnerability allowed any user's file to be stolen
beaksec.github.io
[15 comments hidden]
[3 comments hidden]
one long time Firefox contributor have been for a couple years now removing every part of the --noremote option. even botching (Ooops!) the console notice that the flag was no-op some time ago.
[2 comments hidden]
[3 comments hidden]
[2 comments hidden]
I used to use Cookie Auto Delete for years. But when I last checked it seemed unmaintained. I log out of all somewhat important services anyway every time I am done.
For important stuff like banking I use Firefox containers.
Yeah, all of them could have their weaknesses and vulnerabilities. I just hope no attacker hits exactly the stack I use...
[6 comments hidden]
[5 comments hidden]
Seems like many people do this when it comes to russian tech. Im American and I certainly trust my data in the hands of a foriegn government/entity (which is not even the case for telegram), than my own. Even if it was a russian op (its not the Ukrainian military literally used telegram for years), the russian government cant touch me.
[hidden]
[3 comments hidden]
Anyhow, people don't write off Telegram because it's Russian, but for many legitimate reasons.
There are indications that it could be much closer to the Russian government than they pretend, but that matters not because Russians are bad people, but because the current government of Russia is an aggressive dictatorship.
The Ukrainian military literally used Telegram for years and now literally banned it.
Maybe in part for this Ukrainian article: https://texty.org.ua/articles/112347/eight-signsof-danger-te...
[hidden]
Even assuming they are fully legitimate today, if this ever changes and somebody gets access to their infrastructure, they immediately get a treasure trove of historical messages.
[hidden]
> There are indications that it could be much closer to the Russian government than they pretend
Can you give more details, please? I'm using telegram a lot and want to know if there is something...
[20 comments hidden]
[4 comments hidden]
Not all user processes upload those files somewhere surreptitiously.
Of course operating systems should support that isolation (hopefully in some better way than the hell that smartphones are), but it's not like Telegram can blame the OS for this vulnerability.
[3 comments hidden]
Only if you have access to full source code, can audit it (including each update) and somehow can prove that it has no vulnerabilities. Otherwise one should assume that any application is potentially-harmful and/or vulnerable.
[2 comments hidden]
[hidden]
[hidden]
Uhm, OpenBSD would like a word, buddy.
[2 comments hidden]
[hidden]
No, it's definitely a Telegram specific vulnerability. It might be worse because of poor defense in depth, but without Telegram itself being vulnerable it wouldn't matter.
[2 comments hidden]
So how will you spam all the group chats you're on with meme gifs downloaded from facebook then? :)
[hidden]
The file-manger application managed above is a single point of failure, of course. So, it should be allowed to use only one provided by OS vendor.
[9 comments hidden]
Like any number of articles like this: https://hackernoon.com/7-reason-why-telegram-is-insecure-by-...
[hidden]
A file exfiltration vulnerability is still noteworthy.
[hidden]
The Most Backdoor-Looking Bug I’ve Ever Seen - https://words.filippo.io/telegram-ecdh/
[4 comments hidden]
And yes, I know that by default chats are not E2E, that phone number has way too many effects on accounts etc. Still, UX and agencies interested in important people are more welcome than data selling, ad-based companies.
[2 comments hidden]
Yeah same can be said for Facebook and WhatsApp that Durov vehemently claims should not be trusted with user's data. Maybe it's a ploy for the Mark Zuckerberg of Russia to get the data of people.
Also, Telegram doesn't have to sell it's users if it's an FSB honeypot.
[hidden]
[hidden]
And what UX problems exactly is Telegram solving that its many competitors aren’t? I hear this all the time, but I use both Telegram and WhatsApp and I haven’t found anything lacking in the latter, UX wise.
[hidden]
[2 comments hidden]
This aspect is also not highlighted much in the article, which weirdly mostly focuses on the account takeover.
To me it seems something remarkable enough to warrant reposting the link with a different title.
Somewhat astonishingly, the core of the vulnerability comes from an internal url scheme added to Telegram to... help them publish their releases on their channel.
The Telegram developers saw no better way to do that than adding an internal tool which uploads any file it's told to.
Everyone else publishing their app on Telegram is able to do that with a script, but they had to do it that way.
It's true that it was exploitable only in a somewhat convoluted way, but still, it's an obviously dangerous feature.
Anyhow, yes, clicking on a link in Telegram Desktop was enough to have any user's file exfiltrated and to access or take over their account.
[2 comments hidden]
[3 comments hidden]
[2 comments hidden]
Last I checked, that's exactly how Telegram works by default. It's laughable to consider a service tied to a phone number secure.
[hidden]
[2 comments hidden]
(Yes, I know they're technically Dubai based now)
SpacePortKnight[8 comments hidden]
modeless[4 comments hidden]
miroljub[2 comments hidden]
gvfsa[hidden]
freehorse[hidden]
The web experience is actually better, as eg there I can do web searches when right clicking sth with my default search engine without slack highjacking the options to force me onto google.
Eueudhsbsj32[hidden]
Razengan[hidden]
https://news.ycombinator.com/item?id=12463338
monster_truck[hidden]
It gets buttoned up fast and is always getting better, but its absolutely not a silver bullet.