4 ms·
Most programs can download new code and open whatever files they want as long as their process has the permissions. You can certainly argue that that shouldn't
by drngdds 7y ago
Most programs can download new code and open whatever files they want as long as their process has the permissions. You can certainly argue that that shouldn't be the case, but calling Discord a RAT because of it is pretty silly.
(Not defending it on the other counts, though. If I wanted a platform for anything controversial or privacy-sensitive, I wouldn't trust Discord or any other centralized, unencrypted service.)
- dependenttypes 7y ago> Most programs can download new code and open whatever files they want as long as their process has the permissions We should avoid and shame the programs that do that. This is literally a backdoor.
- tomatotomato37 7y agoYou would have to add every program with an auto-updater onto that list, because that's what they literally do; take files streamed online and slap them into its install directory Like shit, I have 3rd party mod managers for video games that are exclusively built to do such that
- smichel17 7y agoMost programs I use (on Linux) do not come with an auto updater. Instead, I get updates through my distro's package manager. I have Discord installed, because unfortunately that's where my friends are. However, it cannot access arbitrary parts of the file system because it is installed via flatpak; it only has access to ~/Downloads and ~/Pictures.
- m4rtink 7y agoThis is one benefit of Linux distro package managementany people forget - apps can't just update themeselves (possibly after their updater being compromised) but go via package maintainers and are built from source on trusted distro infrastructure.
- gruez 7y ago>Most programs can download new code and open whatever files they want as long as their process has the permissions. You can certainly argue that that shouldn't be the case, but calling Discord a RAT because of it is pretty silly. I think it's reasonable to call it a RAT because it executes arbitrary remote code AND has those permissions.
- theamk 7y agoGoogle Chrome and Firefox (on windows) do the same, via auto update mechanism. Would you call it a RAT?
- dTal 7y agoI feel as if there is a meaningful distinction to be made between a program that occasionally downloads binary patches to itself (and will run fine without it), and a program that gratuitously downloads scripts every time it is run, runs them directly from ram so that they can't be audited, and refuses to run if it is not allowed to do this.
- freddie_mercury 7y agoSo if you're running Chrome/Firefox dev-channel then they're a RAT? Or is twice a week not enough to trigger your threshold? What about the canaries that are updated daily? What about betas that are updated every week? I'm not sure how you come up with a good distinction.
- gruez 7y ago>So if you're running Chrome/Firefox dev-channel then they're a RAT? No, because it's opt-in and it's explicitly needed for the purposes of a dev/nightly build. This is as opposed to a voip client which needs unrestricted access because... they want to be able to run A/B tests on uninformed subjects?
- adisinom 7y agoOne other distinction to make is that auto-update typically runs the same code on a lot of computers, rather than a RAT which is good at running code on a specific computer. There's still room for problems... the auto-update could deliver a special version for special people or deliver a version that has special code targeted at run-time, but it's not as easy. And I'd love to see work on minimizing problematic updates as well.
- superkuh 7y agoNot most programs that I run (ie, hexchat for IRC which is better than discord in all ways). And those that do don't do it silently every time they start, and not just after they start, but any time they're running with no notification to the user. No, a program with an 'update' feature built in is much less offensive than a program who's entire code is remote and new every time but still has local privs.