← Back to context

Comment by usr1106

17 hours ago

I don't use Telegram Desktop or Windows. But that's exactly the reason why I run Firefox in a firejail sandbox on Linux. The browser has only access to my Downloads folder. I know that it's considered untrusted and don't keep any files there for a long time.

Is "firejail" a white list (only these things allowed) or black list solution (everything not explicitly disallowed is allowed)? I glanced through the issues and it seemed to me it is very hacky and feels amateur-ish and doesn't make me trust it, so I am starting writing my own, white-list based sandboxes. For example, No-net Sandbox will not allow a single packet out, including DNS query, unless allowed, Proc Sandbox will restrict access to /proc etc.

Or the reason to run Firefox in a FreeBSD jail to get server-grade security. But the question is can an attacker get access to the Firefox profile data? Because you cannot block that from Firefox, obviously.

  • Sure, to some degree you must trust your browser. In the extreme case you could open a new, non-persistent browser session for every page you visit. Could be slightly inconvenient...

    • > In the extreme case you could open a new, non-persistent browser session for every page you visit.

      This is seamless on Qubes OS: You just click a link and a new empty VM with Firefox opens. You close the browser, and the VM is destroyed. Can't recommend it enough.

      2 replies →

I guess it also has access to the cookies for all your logins.

  • You mean a website A can have login/auth cookies of website B, D, Z, HK… etc? SOP doesn't work? Or is there some sort of exploit on top of third party cookies? (Just curious. I don't know anout browser dev/etc).

    By the way, they don't have just one web apps. They have A, they have K, and apparently a Z – subdomain is webz, or maybe that's actaully A. Not sure.

  • Yes, it has access to the internal storage mechanisms of the browser.

    I used to use Cookie Auto Delete for years. But when I last checked it seemed unmaintained. I log out of all somewhat important services anyway every time I am done.

    For important stuff like banking I use Firefox containers.

    Yeah, all of them could have their weaknesses and vulnerabilities. I just hope no attacker hits exactly the stack I use...

    • Personally I only open Firefox on Linux booted from a read only usb. In theory there could be a firmware vulnerability in the CPU that could let it write persistent data to the UEFI firmware, but I hope the possibility is small.

      1 reply →

The little I have to run Telegram Desktop for, I run in a VM. I'd never let the little oligarch's code touch my desktop OS.

  • I dont write off software because where the person that made it was born. I personally think thats the same thing as refusing to eat at a black owned resturaunt because of the owners skin color.

    Seems like many people do this when it comes to russian tech. Im American and I certainly trust my data in the hands of a foriegn government/entity (which is not even the case for telegram), than my own. Even if it was a russian op (its not the Ukrainian military literally used telegram for years), the russian government cant touch me.

    • Telegram is a double threat: the company is Russian and the founder was arrested then mysteriously released without any charges in France. Given why France wanted him and arrested him, the fact they released him a few days later with no charge annihilated the little shred of trust I had in this Russian piece of software, personally.

      15 replies →

    • You're sure you're replying to the right message? It doesn't mention any country or nationality...

      Anyhow, people don't write off Telegram because it's Russian, but for many legitimate reasons.

      There are indications that it could be much closer to the Russian government than they pretend, but that matters not because Russians are bad people, but because the current government of Russia is an aggressive dictatorship.

      The Ukrainian military literally used Telegram for years and now literally banned it.

      Maybe in part for this Ukrainian article: https://texty.org.ua/articles/112347/eight-signsof-danger-te...

      8 replies →

    • >I dont write off software because where the person that made it was born.

      That's fine. I write it off because it by default leaks all of your content and metadata to the server, and then I ask why, and who is learning all that information and I do not like the answer.

      >Seems like many people do this when it comes to russian tech

      Yeah as a Finn it's not very hard to distrust Russia.

      > Even if it was a russian op (its not the Ukrainian military literally used telegram for years)

      You didn't prove anything with this, if anything, the fact that Ukraine banned using Telegram on the state officials devices, speaks the exact opposite: https://www.bbc.com/news/articles/c78dwepw95do

      >the russian government cant touch me

      If it's a Russian op, they're collecting your entire life, your political opinions, your relationship issues, everything, in search of kompromat that they'd use to coerce you during recruiting.

interesting you mention. because Firefox doesn't have a way to disable the single instance functionality which was used on this telegram vulnerability.

one long time Firefox contributor have been for a couple years now removing every part of the --noremote option. even botching (Ooops!) the console notice that the flag was no-op some time ago.

  • > removing every part of the --noremote option

    What's this now? I'm using that to handle multiple profiles and haven't noticed anything breaking

    • they patched multiprofile to work WITH remote!

      try it, start with --noremote. you will get the vulnerable rpc/dbus listener. start another "firefox --noremote https://example.com" and it will open on the previous process. ha!

      yeah, and you never got a warning about that option going way uh? that's why I'm 80% sure it was malicious. too many convenient mistakes.

  • Which Firefox functionality was used in the Telegram vulnerability? Isn’t this all about the desktop app?

    • being a single instance === having a port open somehow (firefox is dbus) that allows full control of the initial process under the assumption the user space is secure.

      this is the pattern that was abuses in the telegram hack. and this is what security conscious people implemented --notemote in firefox to close this vector. which is gone.

      1 reply →

    • None, I'm not sure what the other user was talking about

      Telegram wanting to be single instance means that it has to use some serialization, and it not escaping semicolons enables a part of the attack.

      4 replies →