Comment by iririririr
17 hours ago
interesting you mention. because Firefox doesn't have a way to disable the single instance functionality which was used on this telegram vulnerability.
one long time Firefox contributor have been for a couple years now removing every part of the --noremote option. even botching (Ooops!) the console notice that the flag was no-op some time ago.
> removing every part of the --noremote option
What's this now? I'm using that to handle multiple profiles and haven't noticed anything breaking
they patched multiprofile to work WITH remote!
try it, start with --noremote. you will get the vulnerable rpc/dbus listener. start another "firefox --noremote https://example.com" and it will open on the previous process. ha!
yeah, and you never got a warning about that option going way uh? that's why I'm 80% sure it was malicious. too many convenient mistakes.
Which Firefox functionality was used in the Telegram vulnerability? Isn’t this all about the desktop app?
being a single instance === having a port open somehow (firefox is dbus) that allows full control of the initial process under the assumption the user space is secure.
this is the pattern that was abuses in the telegram hack. and this is what security conscious people implemented --notemote in firefox to close this vector. which is gone.
It doesn't.
If you only want to make a software single-instance, you typically simply use a named mutex on Windows.
In general it only requires *a way* of communicating *some* information, not to "fully control" the other process or to have a port open.
What was abused in the Telegram hack is a hidden feature that shouldn't have existed, and it was even only vulnerable because of a lack of escaping.
None, I'm not sure what the other user was talking about
Telegram wanting to be single instance means that it has to use some serialization, and it not escaping semicolons enables a part of the attack.
What does "being single instance" mean here?
1 reply →
> not sure
so why answer?
1 reply →