← Back to context

Comment by Panzerschrek

17 hours ago

It's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file. Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory (like downloads for a browser or Telegram-client).

At the same time the mobile operating systems are vulnerable to vendor lock-in due to the absence of this functionality. It is clearly a worse problem that a user can't give their backup system access to the photos stored by other applications (often social media), or for instance reliably capture media streams to use in for instance a remixing application. Bringing custom clients when the software originally used to create the interesting files starts acting against the users by introducing subscriptions or being abandoned is another example of the user dictating what software accesses what files is critical to secure the users operations. Consumers need security against commercial interests infinitely much more than commercial interests need protections against consumers, and it would be unethical to enable commerce at the expense of individuals like the mobile operating systems do.

  • There is a lot of middle ground between “every app can do anything as the user” and “no shared file system, no user access to app ‘owned’ files”.

> It's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file.

No, it's definitely a Telegram specific vulnerability. It might be worse because of poor defense in depth, but without Telegram itself being vulnerable it wouldn't matter.

If you don't believe it's a vulnerability, then you must believe that tricking Telegram into uploading your messages database to the attacker, leaking all your private conversations, is A-OK? Telegram owns that file, after all.

  • I didn't say it's not a vulnerability. It is clearly one. But allowing such vulnerabilities to deal damage beyond data of its host application is an OS vulnerability.

Yes, and there are many ways for apps to opt into this, to limit their own blast radius in a case like this.

Does Telegram do that, or do they consider themselves beyond bugs, just like they consider themselves too clever and untouchable by anyone to need end-to-end encryption?

> vulnerability of all modern desktop operating systems allowing any user process to read/write any user file

not true on macos.

That's broadly-speaking a vulnerable design of all OSes, but strictly speaking it is a bug in Telegram that is now fixed at the app level. Though sandboxes / app isolation solutions exist even in the broadly vulnerable OSes, so apps could use them already today to avoid such issues in the future?

Telegram is available sandboxed from the Mac App Store on macOS.

> Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory

So how will you spam all the group chats you're on with meme gifs downloaded from facebook then? :)

  • Download an image from Facebook into browser's private downloads directory, copy it using a file-manager application (one of the exceptional applications having full filesystem access) into Telegram's private directory, upload it into chats you need to post it.

    The file-manger application managed above is a single point of failure, of course. So, it should be allowed to use only one provided by OS vendor.

    • Sounds like effort, people don't like effort when spreading memes, so would be enraged if this would be the default now, or nobody would activate it.

      There is a lot of middle ground, like having a shared folder for access. "Downloads" might be a good default, if clearly communicated, that anything in there, is accessible by any app.

  • Clicking upload opens an OS file picker that lets the user select a file outside the app sandbox. At least flatpak and Android do it that way.

> It's a vulnerability of all modern desktop operating systems

Uhm, OpenBSD would like a word, buddy.

https://man.openbsd.org/unveil

It is.

Not all user processes upload those files somewhere surreptitiously.

Of course operating systems should support that isolation (hopefully in some better way than the hell that smartphones are), but it's not like Telegram can blame the OS for this vulnerability.

  • > Not all user processes upload those files somewhere surreptitiously.

    Only if you have access to full source code, can audit it (including each update) and somehow can prove that it has no vulnerabilities. Otherwise one should assume that any application is potentially-harmful and/or vulnerable.

    • No, that kind of audit is neither necessary nor sufficient. (A firewall works without application source code, and trusting trust means we can hand wave anything even with source.)

    • Ok, at least if it has network access, but can you recognize that this was a vulnerability, and that you're talking of something only tangential to it?