Telegram Desktop vulnerability allowed any user's file to be stolen

beaksec.github.io

379 points by g-b-r 18 hours ago


farhanhubble - 7 hours ago

I once read The Bugs We Have to Kill: https://www.usenix.org/publications/login/aug15/bratus and one particular thing that has stuck with me forever:

“Any sufficiently complex input format is indistinguishable from bytecode; the code receiving it is indistinguishable from a vir- tual machine.”

bita_nidir - 6 hours ago

Related: could we please stop, by default, allowing software to:

  a) access all your files, and
  b) roam the internet at will.
That was somewhat OK in the 80s, but it hasn't been since.
crossroadsguy - 8 hours ago

One of the challenges with Telegram is - they regularly re-enable settings inside the app/account that you had specifically disabled. So at any point you don't know what is happening and what is not. Meaning, even if you didn't see a thing, a malicious file might be sitting all warm and fuzzy on your computer - among possible other things. I used to like the snappiness of this app (and it is still snappier than almost all other IM apps combined, by a margin), but after a while I realised it was a ticking time-bomb (to keep it installed on the desktop) and possibly a scammer safe haven, nothing else.

SpacePortKnight - 13 hours ago

I think it is one of the reasons why I am always hesitant to install any software on my windows pc. Web versions are often more than good enough.