Remix.run Logo
▲ iririririr 5 hours ago

interesting you mention. because Firefox doesn't have a way to disable the single instance functionality which was used on this telegram vulnerability.

one long time Firefox contributor have been for a couple years now removing every part of the --noremote option. even botching (Ooops!) the console notice that the flag was no-op some time ago.

▲lxgr 3 hours ago | parent | next [-]

Which Firefox functionality was used in the Telegram vulnerability? Isn’t this all about the desktop app?

▲g-b-r 2 hours ago | parent [-]

None, I'm not sure what the other user was talking about

Telegram wanting to be single instance means that it has to use some serialization, and it not escaping semicolons enables a part of the attack.

▲lxgr 2 hours ago | parent [-]

What does "being single instance" mean here?

▲g-b-r 2 hours ago | parent [-]

That only one instance of Telegram can run at any time.

And if you open a Telegram link it will open in the existing instance.

Windows uri handlers actually always create a new process, though; so if you want this single instance behavior, you have to do some check at the start of the process and communicate the uri to the previously running process (as explained in the article).

▲yjftsjthsd-h 5 hours ago | parent | prev [-]

> removing every part of the --noremote option

What's this now? I'm using that to handle multiple profiles and haven't noticed anything breaking