cc @signalapp @moxie
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Signal desktop app is based on the insecure Electron runtime. See my report here:https://github.com/signalapp/Signal-Desktop/issues/1635 …
-
I wish I could feel the sweet "I told you so, fuckers" sensation you are having right now.
-
Electron: what could possibly go wrong with an out-of-date Chromium that disables sandboxing by default?
-
wonder if RiotChat / http://matrix.org web apps are affected too
-
as far as we know, this one is Signal specific.
-
as far as we know there are two issues here; an XSS vuln of some kind in Signal (the original post) and then the RCE in electron you linked. The XSS is Signal specific, and we’re not aware of a way to exploit the RCE via riot-web. That said, roll on proper native Matrix clients..
-
Oh , yes, I was considering already a native Qt/cpp desktop client.
End of conversation
New conversation -
-
-
Wow, reproduced this. I can't believe this trivial of a mistake was made and not caught before deployment. The patch looks very sketchy too, I doubt it can't be bypassed. Nice work folks!
-
-
It's so great, there must be an X's law for thispic.twitter.com/JEZ6Ub6UVL
-
behind every major vulnerability forewarned by basic threat modelling there is an engineer with a hill to die on
End of conversation
New conversation -
-
-
que dice el popup? ubuntu? no se ve una mierda
-
Ponelo en full screen, no se si OpenBSD lo soporta.
-
sos re malo.
End of conversation
New conversation -
-
-
There are quite a few identically implemented chat clients. I wonder if this is also exploitable on those: whatsapp messengerfordesktop slack...
-
discord :^)
-
And Slack. VS Code might be hit as well?
-
i would guess this exploit is specific to signal but, it's a good example of why we shouldnt be using electron. for anything.
-
Do we know that it is signal specific and not some content related bug that gets passed to electron no matter the actual transport?
-
they checked other platforms and apps, we also thought this could be electron and not signal specific. But it is just signal
-
This, at least is a good news. Until further discoveries. :)
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.