Top
Best
New

Posted by g-b-r 2 hours ago

Telegram Desktop vulnerability allowed any user's file to be stolen(beaksec.github.io)
44 points | 11 comments
opengrass 21 minutes ago|
doas jexec -U opengrass tellyjail env DISPLAY=:0 Telegram
Panzerschrek 30 minutes ago||
It's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file. Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory (like downloads for a browser or Telegram-client).
nvme0n1p1 12 minutes ago||
If you don't believe it's a vulnerability, then you must believe that tricking Telegram into uploading your messages database to the attacker, leaking all your private conversations, is A-OK? Telegram owns that file, after all.
Panzerschrek 5 minutes ago||
I didn't say it's not a vulnerability. It is clearly one. But allowing such vulnerabilities to deal damage beyond data of its host application is an OS vulnerability.
eviks 8 minutes ago|||
That's broadly-speaking a vulnerable design of all OSes, but strictly speaking it is a bug in Telegram that is now fixed at the app level. Though sandboxes / app isolation solutions exist even in the broadly vulnerable OSes, so apps could use them already today to avoid such issues in the future?
g-b-r 20 minutes ago||
It is.

Not all user processes upload those files somewhere surreptitiously.

Of course operating systems should support that isolation (hopefully in some better way than the hell that smartphones are), but it's not like Telegram can blame the OS for this vulnerability.

Panzerschrek 3 minutes ago||
> Not all user processes upload those files somewhere surreptitiously.

Only if you have access to full source code, can audit it (including each update) and somehow can prove that it has no vulnerabilities. Otherwise one should assume that any application is potentially-harmful and/or vulnerable.

erelong 1 hour ago||
I thought telegram was flagged as insecure like a decade ago, it's never really been "very secure"

Like any number of articles like this: https://hackernoon.com/7-reason-why-telegram-is-insecure-by-...

g-b-r 59 minutes ago|
Absolutely, but mostly for their protocols, statements, people and infrastructure.

A file exfiltration vulnerability is still noteworthy.

KingOfCoders 44 minutes ago||
It's not a bug it's a feature.
g-b-r 2 hours ago|
This link has already been posted with https://news.ycombinator.com/item?id=50019667 , but that post's title ("Telegram Desktop: one-click account takeover") doesn't say that the vulnerability allowed also any user-accessible file on the disk to be stolen.

This aspect is also not highlighted much in the article, which weirdly mostly focuses on the account takeover.

To me it seems something remarkable enough to warrant reposting the link with a different title.

Somewhat astonishingly, the core of the vulnerability comes from an internal url scheme added to Telegram to... help them publish their releases on their channel.

The Telegram developers saw no better way to do that than adding an internal tool which uploads any file it's told to.

Everyone else publishing their app on Telegram is able to do that with a script, but they had to do it that way.

It's true that it was exploitable only in a somewhat convoluted way, but still, it's an obviously dangerous feature.

Anyhow, yes, clicking on a link in Telegram Desktop was enough to have any user's file exfiltrated and to access or take over their account.