17 ms·
Another flaw in Signal desktop app leaks chats in plaintext
- teachrdan 8y agoFrom TFA: "...the new vulnerability (CVE-2018-11101) exists in a different function that handles the validation of quoted messages, i.e., quoting a previous message in a reply. "In other words, to exploit the newly patched bug on vulnerable versions of Signal desktop app, all an attacker needs to do is send a malicious HTML/javascript code as a message to the victim, and then quote/reply to that same message with any random text. "If the victim receives this quoted message containing the malicious payload on its vulnerable Signal desktop app, it will automatically execute the payload, without requiring any user interaction." Is it the case that you don't even need to have the attacker's number in your contacts list?
- symlinkk 8y agoNo, that's incorrect. You have to have someone's number to send a message to them.
- matthewaveryusa 8y agoIn security less is more. The more we try to make encryption mainstream, the more difficult it gets because the mainstream interacts with computers predominately via browsers. The mainstream won't adopt something that isn't highly similar to what a browser has to offer in terms of media richness (photos, videos, html), so you see Signal choosing technologies like Electron, a browser, to develop their native applications. The heart of what signal is and does well (encrypt, decrypt, authenticate) is dwarfed by a pile of code that was added to make signal usable by the mainstream. Desktop Signal, in terms of code and complexity, is no longer a security product -- it's an application with a web-like media experience that happens to tack on a very good library to do encryption and authentication. As we all know, sometimes vulns are in broken crypto, but most of the time they're in a gotcha beneath a mountain of code.
- justicezyx 8y agoIn general less is more, with proper abstraction, not just in security.
- deleted 8y ago[deleted]
- tormeh 8y agoMaybe secure chat clients shouldn't be written in JavaScript or other languages that have excessive dynamicness? Signal seems to be written mostly in languages that are bad for security (significantly worse than the best alternatives). Maybe I'm just a language nerd without any clue about the trade-offs, but I trust the Wire software more. Note that this just applies to mobile clients and server - Wire, like Signal, chose to build their desktop+webapp in JavaScript :(
- pfg 8y agoAs much as I'm not a fan of JavaScript, the problem is not so much the language but rather the choice of Electron and all that comes with it. Heck, even a web version or Chrome app would've successfully mitigated these attacks. Electron means you're one XSS away from remote code execution, and even worse, it makes it way harder to mitigate XSS through CSP (which Signal did utilize, but script-src 'self' can easily be bypassed in Electron). FWIW, Signal's native mobile apps are written in Java and Objective-C respectively, so there's not really much of a difference compared to Wire (which is a good choice as well). Still, even a hypothetical React Native app written in JavaScript wouldn't be much worse; after all, React Native isn't just a Web View made to look like a native app, but uses actual native components.
- mintplant 8y agoSignal Desktop actually used to be a Chrome app. Then Google announced the deprecation of that feature and they ported it over to Electron.
- ehPReth 8y agoSad day for Chrome OS users. No more Signal updates! :(
- ams6110 8y ago> Electron means you're one XSS away from remote code execution So, electron is the new flash. I'll be avoiding that, then.
- JasonFruit 8y agoWhen will people start using plain old PGP — a tool that does one thing only, and does it right? Sure, it's a little harder than using just one tool that handles contacts, communication, formatting, and encryption, while making popcorn and walking the dog, but it works, and it's secure if you use it right. Our efforts to make encryption easy are going to get someone killed.
- roywiggins 8y agoliterally this week https://news.ycombinator.com/item?id=17064129 https://news.ycombinator.com/item?id=17064129
- JasonFruit 8y agoLiterally not PGP, but clients built around it to make encrypted email easy. Read the article you linked. EDIT: typo.
- roywiggins 8y agoIt relies on several features of PGP that mean that messages aren't tamper-proof. If PGP made sure messages replayed and altered by attackers would not decrypt, then the attacks wouldn't work- you couldn't replay an email back to someone to steal it. It relies on a client having an HTML renderer, but the underlying issue is messages that can be tampered with.
- JasonFruit 8y agoIt also relies on clients misusing an API call. And then passing the result to a full HTML viewer that can access the internet. So, again, not an exploit if you use plain PGP.
- 0xCMP 8y agoAh, so don't use the now secured opensource client using Signal's protocol. We should use PGP with all the weak yet-to-be-patched clients. Cause it's not PGP which got hacked it was the client. Very different from how the Signal client got hacked not their protocol. /s
- andrepd 8y ago>Researchers—Iván Ariel Barrera Oro, Alfredo Ortega, Juliano Rizzo, and Matt Bryant—responsibly reported the vulnerability to Signal, and its developers have patched the vulnerability with the release of Signal desktop version 1.11.0 for Windows, macOS, and Linux users. >However, The Hacker News has learned that Signal developers had already identified this issue as part of a comprehensive fix to the first vulnerability before the researchers found it and reported them. >Signal app has an auto-update mechanism, so most users must have the update already installed. You can read this guide to ensure if you are running updated version of Signal. Seems everything is patched, and was already going to be patched before the vuln was reported.
- tptacek 8y agoHonestly, and none of you are going to like hearing this, and the Signal people aren't going to appreciate me saying it: if you're serious about messaging securely, don't use Signal Desktop; don't use desktop secure messengers at all. Desktop applications are incredibly risky, far more so than iOS mobile apps are.
- 4ad 8y agoDesktop applications are incredibly risky, yes; as for iOS mobile apps we can't even know, as these devices don't allow auditing what software is running on them. PGP has many problems and I hope a better replacement will come along, but the first step of secure messaging can't be using devices with closed, unauditable software...
- kome 8y agoThey down-vote you, but you are 100% right. Using a mobile phone is intrinsically more insecure because they can track you much more easily, and you have much less control over the OS.
- kasey_junk 8y agoA reason you are getting downvotes is that it’s not true that closed source software is unauditable. This is a common but untrue belief. It’s a fundamental axciom of software security that you can’t trust source, so you must diagnose the binary. Source may be helpful, but in the grand scheme of things lots of other properties are more important.
- mbid 8y ago> It’s a fundamental axciom of software security that you can’t trust source, so you must diagnose the binary. What if you trust the build tool chain and can reproduce the binary from source?
- kasey_junk 8y agoThat’s functionally harder in most cases than just inspecting the binary.
- Jedi72 8y agoOn their Android app, first thing it makes you do is give them permission to read your SMSs. It wont let you vefiry by entering a code. I immediately uninstalled - doesn't seem like a privacy focussed organisation to me.
- aaomidi 8y agoYep. I've complained about this so much.
- f2n 8y ago> It wont let you vefiry by entering a code That's odd because I've absolutely verified numerous Signal clients by entering a code, without granting access to my SMS (I use Google Voice so my SMS database is basically empty except for random spam from my shitty carrier)
- ianburrell 8y agoIt used to be that Signal required reading the code from SMS and didn't work with Google Voice. But they listened to complaints and changed it to allow entering the code.
- cornholio 8y agoThat sounds absolutely horrendous. Even Whatsapp allows you to verify using a fixed line and claim that number on the mobile for privacy. Coupled with the recent LocationSmart revelations, it would make Signal unusable for those who wish to keep their location private. You absolutely need to provide the mobile number of the actual terminal being used.
- bigiain 8y agoNot true. I have Signal running in an iPod Touch. I needed to give them a phone number I could read SMS from to set it up, but there's no need for that to be "the mobile number of the actual terminal being used".
- newscracker 8y ago
- downer55 8y agoOh boy! Another security fire drill! I love these!
- peterburkimsher 8y agoSomeone invited me to use signal. I thought "It's a trap!"
- peterburkimsher 8y agoIt's a pun on inter-process communication signals and traps in UNIX. https://www.tutorialspoint.com/unix/unix-signals-traps.htm https://www.tutorialspoint.com/unix/unix-signals-traps.htm
- namuol 8y agoPretty mindblowing that Signal allows things like `dangerouslySetInnerHTML` in any of their apps. A simple linter would have caught this.
- sakarisson 8y agoWith such an obviously "DON'T USE THIS" method name as dangerouslySetInnerHtml, I'd expect that we'd see something like // eslint-disable-next-line above it.
- pokemongoaway 8y agoAnyone else have an aesthetic feeling for this? Signal desktop felt clunky to such a degree that takes away from trust that Telegram feels equally secure - even though it is not.
- verroq 8y agoIs there a native Signal client that isn’t an Electron abomination? It is clear at the point the Signal desktop people has no idea what they are doing and cannot be trusted to write a secure desktop application.
- AlexCoventry 8y agoYou can run it as a chrome extension, which I do, in a dedicated VM.
- soziawa 8y agoNope. But you can try Threema or Wire. They're both pretty good.
- pmlnr 8y agoJust go XMPP with OMEMO or Matrix.
- tlrobinson 8y agoWhy is this flagged?
- on_and_off 8y agoSame question. Also, is there somewhere where we can see why a thread is flagged ?
- tlrobinson 8y agoUnfortunately there's no way to know why users flag something, but that brings up an interesting idea: in order to flag something require the user types out a reason, and if an article is flagged it could show why people flagged it.
- verroq 8y agoProbably signal-desktop devs in full damage control mode over their bloated electron abomination. Upvote the thread to counter the flagging.
- geofft 8y agoI usually have a "vouch" button but I can't find it - maybe I don't have it on posts and only on comments?
- ddtaylor 8y agoI had the same question, the title seemed generous considering this was technically a RCE exploit. EDIT It also appears lots of comments just got hit with a wave of downvotes. It's possible there is some brigading or vote manipulation.
- Ceezy 8y agoBecause the discution is already a flame war. I feel like everybody has a solution. Try not to get burn because JS is bad! a sorry electron is terrible! No innerhtml is a sin!
- verroq 8y ago
- ddtaylor 8y agoI don't know if this is exploitable, but they are using many different methods to escape HTML content: https://github.com/signalapp/Signal-Desktop/blob/d1f7f5ee8c1111c2b12a2870c64a830ca0f4fd04/components/mocha/mocha.js#L89 https://github.com/signalapp/Signal-Desktop/blob/d1f7f5ee8c1... Then here it's a different function: https://github.com/signalapp/Signal-Desktop/blob/d1f7f5ee8c1111c2b12a2870c64a830ca0f4fd04/components/mustache/mustache.js#L56 https://github.com/signalapp/Signal-Desktop/blob/d1f7f5ee8c1... Then sometimes they use the underscore library to do it: https://github.com/signalapp/Signal-Desktop/blob/d1f7f5ee8c1111c2b12a2870c64a830ca0f4fd04/components/backbone/backbone.js#L295 https://github.com/signalapp/Signal-Desktop/blob/d1f7f5ee8c1... Which their implementation seems to be using regular expressions as well.
- hawkice 8y agoThe first one doesn't escape single quotes or slash, but I have no idea how to get any HTML parser to treat just those as anything but text. Underscore's implementation will be correct, I'm sure.
- codedokode 8y agoSlash doesn't need to be encoded. Only 5 characters that have special meaning have to be encoded (&, <, >, " and ').
- hawkice 8y agoWhich raises the best question: how would you exploit someone not escaping single quotes? I do not know. Perhaps it isn't possible.
- jscissr 8y agoI think escaping quotes only matters for attributes (which can use ' or "). Example: <img src="$url"> Exploit: foo.jpg" onload="alert('pwned')
- fastball 8y agoWhat is this website? "The Hacker News"? And no actual relation to HN? This website doesn't even have an about page...
- orthecreedence 8y agoThis is BLASPHEMY!!
- deleted 8y ago[deleted]
- AlexCoventry 8y agoIs the chrome extension also vulnerable to this?
- aortega 8y agoNo, it is not.
- onetimemanytime 8y agoInteresting, more or less, nothing is 100% secure. Looks like DEA had cracked the whatever crypto Blacberry was using and quite a few drug dealers were caught that way (one example: https://www.thedailybeast.com/the-deas-dirty-cop-who-tipped-off-a-cartel https://www.thedailybeast.com/the-deas-dirty-cop-who-tipped-... ). They must have been using because of the reputation BB had. I wonder what will we find out in time about the narcos, terrorists etc using Signal.
- FrantaH 8y agoIt's mind boggling why messaging app has 181 MB.
- codebolt 8y agoI'm really starting to get tired of all these bloated JavaScript desktop apps. I get that it's more convenient for developing cross-platform apps with modern looking UIs, but I really wish there would be an increased focus on reducing the overall bloat and resource use, both among app and framework devs. Speaking as a Windows user, I would vastly prefer a well-designed native application (WinForms/WPF) over a JS monstrosity any day.
- Aissen 8y agoFrom the researcher who found it: we were able to compile a list of strategic defense-in-depth recommendations for Signal Desktop which we’ve sent to the Signal security team per their request. At the end of the day there will always be new “hot” vulnerabilities, but the “vendor” response is generally what separates the wheat from the chaff. The Signal team’s quick patch time along with a strong interest in mitigating vulnerabilities of this type in the future was encouraging to see. I’ll remain a Signal user for the foreseeable future :) https://thehackerblog.com/i-too-like-to-live-dangerously-accidentally-finding-rce-in-signal-desktop-via-html-injection-in-quoted-replies/ https://thehackerblog.com/i-too-like-to-live-dangerously-acc...
- baby 8y agoThis news saddens me. I’ve been the last user of the Signal desktop app around me and it looks like I have been too optimistic about Electron. I’ve now deleted any Electron app and recommend everyone to do the same.
- ccnafr 8y agoWasn't this domain imitating the actual Hacker News banned years ago? Plus, I think they violate rules because this is just blog spam. The actual source of the story is: https://ivan.barreraoro.com.ar/signal-desktop-html-tag-injection-variant-2/ https://ivan.barreraoro.com.ar/signal-desktop-html-tag-injec...
- rando444 8y agoI don't see anything imitating this website.. other than a technology based news feed and a similarly used name. I used to browse a website called "hacker news" back in the late 90s / early 2000s, but I wouldn't go as far as to call News YC a copy of that.
- ccnafr 8y agoI was referring to the fact of imitating the HN brand by capitalizing on the domain name so they could scoop up all the traffic and SEO love. That's why the domain was banned to begin with a few years back. There was a whole discussion about it.
- rando444 8y agoThe site that I was referring to was literally hackernews.com, and was very popular among the tech crowd from the late 90s onward. (long before YC was conceived) ALmost 20 years ago, I used to rotate between hacker news, fark, and slashdot to get my daily dose of internet. https://web.archive.org/web/*/hackernews.com https://web.archive.org/web/*/hackernews.com One would be perfectly justified in also trying to claim that the name here was stolen from the original. .. but sometimes, just because things share a common name, does not necessarily mean they are related. https://en.wikipedia.org/wiki/Post_hoc_ergo_propter_hoc https://en.wikipedia.org/wiki/Post_hoc_ergo_propter_hoc
- ccnafr 8y agoNot that one. That's owned by Space Rogue. I'm talking about the one linked now, owned by some Indians who keep copying articles off other sites. There was a reason this got banned years ago. At one point you could trace articles from The Register and Motherboard paragraph by paragraph to their stories, but with bad grammar and bad sentence structure.
- throwawaymanbot 8y agoHow was this Vuln introduced? And who introduced it?