| ▲ | usr1106 5 hours ago |
| I don't use Telegram Desktop or Windows. But that's exactly the reason why I run Firefox in a firejail sandbox on Linux. The browser has only access to my Downloads folder. I know that it's considered untrusted and don't keep any files there for a long time. |
|
| ▲ | freebsd_lovefes 5 hours ago | parent | next [-] |
| Or the reason to run Firefox in a FreeBSD jail to get server-grade security. But the question is can an attacker get access to the Firefox profile data? Because you cannot block that from Firefox, obviously. |
| |
| ▲ | usr1106 5 hours ago | parent [-] | | Sure, to some degree you must trust your browser. In the extreme case you could open a new, non-persistent browser session for every page you visit. Could be slightly inconvenient... | | |
| ▲ | bmacho 2 hours ago | parent [-] | | Or you could have 2 (or 3) separate browser sessions, one for only important stuff, and one for fun. |
|
|
|
| ▲ | barrkel 5 hours ago | parent | prev | next [-] |
| I guess it also has access to the cookies for all your logins. |
| |
| ▲ | usr1106 5 hours ago | parent [-] | | Yes, it has access to the internal storage mechanisms of the browser. I used to use Cookie Auto Delete for years. But when I last checked it seemed unmaintained. I log out of all somewhat important services anyway every time I am done. For important stuff like banking I use Firefox containers. Yeah, all of them could have their weaknesses and vulnerabilities. I just hope no attacker hits exactly the stack I use... | | |
| ▲ | eddythompson80 4 hours ago | parent [-] | | Personally I only open Firefox on Linux booted from a read only usb. In theory there could be a firmware vulnerability in the CPU that could let it write persistent data to the UEFI firmware, but I hope the possibility is small. | | |
| ▲ | ShinyLeftPad an hour ago | parent [-] | | What makes it doubly funny is that the OP is not even about any browser vulnerability, it's a hole in desktop client IPC |
|
|
|
|
| ▲ | iririririr 5 hours ago | parent | prev | next [-] |
| interesting you mention. because Firefox doesn't have a way to disable the single instance functionality which was used on this telegram vulnerability. one long time Firefox contributor have been for a couple years now removing every part of the --noremote option. even botching (Ooops!) the console notice that the flag was no-op some time ago. |
| |
| ▲ | lxgr 3 hours ago | parent | next [-] | | Which Firefox functionality was used in the Telegram vulnerability? Isn’t this all about the desktop app? | | |
| ▲ | g-b-r 2 hours ago | parent [-] | | None, I'm not sure what the other user was talking about Telegram wanting to be single instance means that it has to use some serialization, and it not escaping semicolons enables a part of the attack. | | |
| ▲ | lxgr 2 hours ago | parent [-] | | What does "being single instance" mean here? | | |
| ▲ | g-b-r 2 hours ago | parent [-] | | That only one instance of Telegram can run at any time. And if you open a Telegram link it will open in the existing instance. Windows uri handlers actually always create a new process, though; so if you want this single instance behavior, you have to do some check at the start of the process and communicate the uri to the previously running process (as explained in the article). |
|
|
| |
| ▲ | yjftsjthsd-h 5 hours ago | parent | prev [-] | | > removing every part of the --noremote option What's this now? I'm using that to handle multiple profiles and haven't noticed anything breaking |
|
|
| ▲ | maqp 5 hours ago | parent | prev [-] |
| The little I have to run Telegram Desktop for, I run in a VM. I'd never let the little oligarch's code touch my desktop OS. |
| |
| ▲ | lifeisloving 4 hours ago | parent [-] | | I dont write off software because where the person that made it was born. I personally think thats the same thing as refusing to eat at a black owned resturaunt because of the owners skin color. Seems like many people do this when it comes to russian tech. Im American and I certainly trust my data in the hands of a foriegn government/entity (which is not even the case for telegram), than my own. Even if it was a russian op (its not the Ukrainian military literally used telegram for years), the russian government cant touch me. | | |
| ▲ | ornornor 4 hours ago | parent | next [-] | | Telegram is a double threat: the company is Russian and the founder was arrested then mysteriously released without any charges in France. Given why France wanted him and arrested him, the fact they released him a few days later with no charge annihilated the little shred of trust I had in this Russian piece of software, personally. | |
| ▲ | g-b-r 4 hours ago | parent | prev [-] | | You're sure you're replying to the right message? It doesn't mention any country or nationality... Anyhow, people don't write off Telegram because it's Russian, but for many legitimate reasons. There are indications that it could be much closer to the Russian government than they pretend, but that matters not because Russians are bad people, but because the current government of Russia is an aggressive dictatorship. The Ukrainian military literally used Telegram for years and now literally banned it. Maybe in part for this Ukrainian article:
https://texty.org.ua/articles/112347/eight-signsof-danger-te... | | |
| ▲ | feelamee 3 hours ago | parent | next [-] | | > Anyhow, people don't write off Telegram because it's Russian, but for many legitimate reasons. > There are indications that it could be much closer to the Russian government than they pretend Can you give more details, please?
I'm using telegram a lot and want to know if there is something... | | | |
| ▲ | lxgr 3 hours ago | parent | prev | next [-] | | The main reason I consider it suspicious is that they are so adamant about not needing end-to-end encryption. Even assuming they are fully legitimate today, if this ever changes and somebody gets access to their infrastructure, they immediately get a treasure trove of historical messages. | |
| ▲ | lifeisloving 2 hours ago | parent | prev [-] | | Calling him an oligarch, it was implied | | |
|
|
|