← Back to context

Comment by lxgr

14 hours ago

Which Firefox functionality was used in the Telegram vulnerability? Isn’t this all about the desktop app?

being a single instance === having a port open somehow (firefox is dbus) that allows full control of the initial process under the assumption the user space is secure.

this is the pattern that was abuses in the telegram hack. and this is what security conscious people implemented --notemote in firefox to close this vector. which is gone.

  • It doesn't.

    If you only want to make a software single-instance, you typically simply use a named mutex on Windows.

    In general it only requires *a way* of communicating *some* information, not to "fully control" the other process or to have a port open.

    What was abused in the Telegram hack is a hidden feature that shouldn't have existed, and it was even only vulnerable because of a lack of escaping.

None, I'm not sure what the other user was talking about

Telegram wanting to be single instance means that it has to use some serialization, and it not escaping semicolons enables a part of the attack.

  • > not sure

    so why answer?

    • Because I do know what this vulnerability was about, and it had nothing to do with Firefox (and I know that you specifically probably didn't mean that Firefox was involved, but even Telegram's desire to be single instance was not what caused the vulnerability).

  • What does "being single instance" mean here?

    • That only one instance of Telegram can run at any time.

      And if you open a Telegram link it will open in the existing instance.

      Windows uri handlers actually always create a new process, though; so if you want this single instance behavior, you have to do some check at the start of the process and communicate the uri to the previously running process (as explained in the article).