Comment by Panzerschrek
17 hours ago
It's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file. Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory (like downloads for a browser or Telegram-client).
At the same time the mobile operating systems are vulnerable to vendor lock-in due to the absence of this functionality. It is clearly a worse problem that a user can't give their backup system access to the photos stored by other applications (often social media), or for instance reliably capture media streams to use in for instance a remixing application. Bringing custom clients when the software originally used to create the interesting files starts acting against the users by introducing subscriptions or being abandoned is another example of the user dictating what software accesses what files is critical to secure the users operations. Consumers need security against commercial interests infinitely much more than commercial interests need protections against consumers, and it would be unethical to enable commerce at the expense of individuals like the mobile operating systems do.
There is a lot of middle ground between “every app can do anything as the user” and “no shared file system, no user access to app ‘owned’ files”.
Any time big corp implements strong sandboxing they'll inevitably put the user inside of the sandbox.
1 reply →
> It's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file.
No, it's definitely a Telegram specific vulnerability. It might be worse because of poor defense in depth, but without Telegram itself being vulnerable it wouldn't matter.
If you don't believe it's a vulnerability, then you must believe that tricking Telegram into uploading your messages database to the attacker, leaking all your private conversations, is A-OK? Telegram owns that file, after all.
I didn't say it's not a vulnerability. It is clearly one. But allowing such vulnerabilities to deal damage beyond data of its host application is an OS vulnerability.
Yes, and there are many ways for apps to opt into this, to limit their own blast radius in a case like this.
Does Telegram do that, or do they consider themselves beyond bugs, just like they consider themselves too clever and untouchable by anyone to need end-to-end encryption?
> vulnerability of all modern desktop operating systems allowing any user process to read/write any user file
not true on macos.
Not true for apps installed via AppStore. A lot of popular apps aren’t in AppStore, Chrome/FF for example.
I would argue one of the main purposes of OSs is securing files between different users. All modern OSes do this securely if set up properly.
Or Linux with Flatpaks.
Or Windows Store as long as the proper integrity is used
That's broadly-speaking a vulnerable design of all OSes, but strictly speaking it is a bug in Telegram that is now fixed at the app level. Though sandboxes / app isolation solutions exist even in the broadly vulnerable OSes, so apps could use them already today to avoid such issues in the future?
Telegram is available sandboxed from the Mac App Store on macOS.
It could easily sandbox itself in the non-store distribution as well, yet the developers apparently choose not to.
It is also sandboxed in Flatpak.
Looking at the flatpak manifest it has `share=ipc` but no directories shared.. I'm not sure on flatpaks defaults for what it would actually have access to on the host.
That is not the same app.
Telegram Desktop is also on the app store though.
I know, it's (slightly) better
> Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory
So how will you spam all the group chats you're on with meme gifs downloaded from facebook then? :)
Download an image from Facebook into browser's private downloads directory, copy it using a file-manager application (one of the exceptional applications having full filesystem access) into Telegram's private directory, upload it into chats you need to post it.
The file-manger application managed above is a single point of failure, of course. So, it should be allowed to use only one provided by OS vendor.
Sounds like effort, people don't like effort when spreading memes, so would be enraged if this would be the default now, or nobody would activate it.
There is a lot of middle ground, like having a shared folder for access. "Downloads" might be a good default, if clearly communicated, that anything in there, is accessible by any app.
Clicking upload opens an OS file picker that lets the user select a file outside the app sandbox. At least flatpak and Android do it that way.
MacOS sandboxes user folders by default. The user need to explicitly give a permission for every application.
It sandboxes some use folders. ~/projects won’t be sandboxed for example.
> It's a vulnerability of all modern desktop operating systems
Uhm, OpenBSD would like a word, buddy.
https://man.openbsd.org/unveil
And Linux would like to present you bubblewrap [1][2][3][4] or the infamous SELinux.
[1]: https://github.com/containers/bubblewrap#usage
[2]: https://man.archlinux.org/man/bwrap.1
[3]: https://wiki.archlinux.org/title/Bubblewrap#Usage_examples
[4]: https://wiki.archlinux.org/title/Bubblewrap/Examples#p7zip
That has the caveat that it only works as far as apps opt into it
Chromium and Firefox have unveil on OpenBSD, which is a good start.
It is.
Not all user processes upload those files somewhere surreptitiously.
Of course operating systems should support that isolation (hopefully in some better way than the hell that smartphones are), but it's not like Telegram can blame the OS for this vulnerability.
> Not all user processes upload those files somewhere surreptitiously.
Only if you have access to full source code, can audit it (including each update) and somehow can prove that it has no vulnerabilities. Otherwise one should assume that any application is potentially-harmful and/or vulnerable.
No, that kind of audit is neither necessary nor sufficient. (A firewall works without application source code, and trusting trust means we can hand wave anything even with source.)
Ok, at least if it has network access, but can you recognize that this was a vulnerability, and that you're talking of something only tangential to it?
[flagged]