logoalt Hacker News

Panzerschrek • today at 5:21 AM • 8 replies • view on HN

It's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file. Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory (like downloads for a browser or Telegram-client).


Replies

simonra • today at 6:36 AM

At the same time the mobile operating systems are vulnerable to vendor lock-in due to the absence of this functionality. It is clearly a worse problem that a user can't give their backup system access to the photos stored by other applications (often social media), or for instance reliably capture media streams to use in for instance a remixing application. Bringing custom clients when the software originally used to create the interesting files starts acting against the users by introducing subscriptions or being abandoned is another example of the user dictating what software accesses what files is critical to secure the users operations. Consumers need security against commercial interests infinitely much more than commercial interests need protections against consumers, and it would be unethical to enable commerce at the expense of individuals like the mobile operating systems do.

➕ show 1 reply
yjftsjthsd-h • today at 7:13 AM

> It's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file.

No, it's definitely a Telegram specific vulnerability. It might be worse because of poor defense in depth, but without Telegram itself being vulnerable it wouldn't matter.

nvme0n1p1 • today at 5:39 AM

If you don't believe it's a vulnerability, then you must believe that tricking Telegram into uploading your messages database to the attacker, leaking all your private conversations, is A-OK? Telegram owns that file, after all.

➕ show 1 reply
nottorp • today at 7:14 AM

> Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory

So how will you spam all the group chats you're on with meme gifs downloaded from facebook then? :)

➕ show 1 reply
eviks • today at 5:43 AM

That's broadly-speaking a vulnerable design of all OSes, but strictly speaking it is a bug in Telegram that is now fixed at the app level. Though sandboxes / app isolation solutions exist even in the broadly vulnerable OSes, so apps could use them already today to avoid such issues in the future?

saagarjha • today at 6:09 AM

Telegram is available sandboxed from the Mac App Store on macOS.

➕ show 4 replies
penskymaterial • today at 6:07 AM

> It's a vulnerability of all modern desktop operating systems

Uhm, OpenBSD would like a word, buddy.

https://man.openbsd.org/unveil

g-b-r • today at 5:31 AM

It is.

Not all user processes upload those files somewhere surreptitiously.

Of course operating systems should support that isolation (hopefully in some better way than the hell that smartphones are), but it's not like Telegram can blame the OS for this vulnerability.

➕ show 1 reply