22 ms·
Discord Desktop App RCE
- skim_milk 6y agoThis is both a pitiful amount of money for finding flaws in three different pieces of software but at the same time the biggest thing Discord did wrong was not practicing defense in depth through disabling contextIsolation. Although it makes sense, I'm almost surprised Discord paid out given that biggest reason the RCE exists was due to the Electron top-level navigation bug allowing XSS despite Discord's existing mitigations in the first place.
- dannyw 6y agoIf you get tired of paying RCEs for a third party library, you should stop using that library. A RCE is a RCE.
- cestith 6y agoAlternately take responsibility for fixing it, sending changes upstream, applying pressure that the get accepted, and building defenses against the specific bug in your surrounding code just in case.
- stefan_ 6y agoThis seems to be a bit of a concerning attitude, and it's also in that top Discord guys post. No, it's not a bug in some third-party library that you are excused from - you use it, it's your bug now! And who other than Discord would be poised to take charge and fix it? They need a desktop client almost like no other Electron user. Time to grow up and take some responsibility for the stuff you ship. Instead we have $ git log --oneline --author "discordapp.com" | wc -l 7 They are building their business centerpiece software around something they don't understand and don't maintain.
- est31 6y agoYeah the moment you take on a dependency and put it into your code, you vouch for it. That's why so many open source (or even proprietary) licenses have the NO LIABILITY clause.
- dancemethis 6y agothe biggest thing Discord did wrong was decide on being proprietary software.
- daehee 6y agoMore details on CVE-2020-15174 Electron navigation restriction bypass here: https://www.cvebase.com/cve/2020/15174 https://www.cvebase.com/cve/2020/15174
- ed25519FUUU 6y agoThese types of exploits are exactly why I just prefer to use the browser version of everything. The browser is superior (both mobile and desktop). It’s safer, typically faster and less resource intensive, and it has reliable and consistent controls. For example, “going back” means something different to every app, but in safari it’s always just a click away. And most importantly in the browser I can have full ad blocking/tracking protections enabled.
- enjeyw 6y agoYeah I noticed recently that I actually prefer browser apps from a UX point of view - creating tabs of content and jumping between them is something I do a lot, and it's baked in very nicely to the browser. (As is sending a link to share the exact screen i'm on, back button as u mention etc etc)
- smichel17 6y agoIf the browser is your OS, it makes a lot of sense. In contrast, I often organize my browser tabs onto multiple separate windows (even when I don't have that many open), because opening programs in windows and jumping between them is something I do a lot, and it's baked in very nicely to my window manager :) To avoid misinterpretation since text is horrible this way: I am NOT disparaging or even really disagreeing with the parent comment. They're just two different workflows, and while I appreciate the advantages of the browser, apps work better in mine.
- fomine3 6y agoChrome's Webpage-to-App feature is best experience for me. I wish Firefox had similar feature.
- modo_mario 6y agoDo you mean PWA's? Because firefox has had that for a long time.
- 6y ago
- blackoil 6y agoAre such exploits possible in electron, or is it sandboxed to prevent such errors?
- dvt 6y agoElectron is going to get a lot of shit for this, but this is really Discord's screw-up for allowing third-party (e.g. not vetted) iframe embeds.. why would that ever be a good idea? CVE-2020-15174 is an interesting exploit (the only part I find pretty damning).
- pilif 6y agoIn the web context, iframes are reasonably safe (if you discount ad privacy issues). One of the touted advantages of Electron is that you can use web technologies and thus have engineers familiar with web technologies working on your application. It’s very easy to see a web developer do what is perfectly fine on the web. Heck, this feature might even have been added for their web client and then brought over to the electron version, possibly unbeknownst to the original author of the feature. No. I wouldn’t call this a bug screwup. Just another effect of the footgun that is electron
- pjmlp 6y agoIt is more like use ChromeOS technologies thus Web developers don't have to bother writing portable Web applications. Slack doesn't do anything so amazing that cannot be a portable Web application, with the browser I already have installed.
- dvt 6y ago> In the web context, iframes are reasonably safe (if you discount ad privacy issues). This is a dubious claim; not sure how long you've been developing for the web, but iframes have had many many exploits fixed over the years. That's neither here nor there though, as Discord purports to be a native application and therefore should be extra careful.
- jrwr 6y agoYou can say that about any major piece of tech being used on the internet, right down to the microcode running on your processor having issues. I mean, shit windows had ANOTHER ping of of death style exploit this month. Should we just stop using windows? What about all the linux exploits that exist?
- pilif 6y agoMy main takeaway from this article is the question why conextIsolation was introduced defaulting to false. This is one huge lever to help with the maxime “XSS is RCE in electron” and yet they default to not helping. I know this is about backwards compatibility, but they could easily have decided to throw if the property is unset. Security-minded people would have set it to true and dealt with the fallout, whereas others could have set it to false and shipped their update still. But by defaulting to false, this security tool is hidden from both existing and new users. Old code will not even have the chance to get fixed and new code will be written in an insecure state. I’m sure the release notes talked about this feature, but who reads release notes? Especially not past release notes (when starting fresh today). The backwards compatibility cost of throwing and in the message even suggesting setting to false as an emergency out would have been minimal compared to the fallout this is causing.
- Semaphor 6y agoMaybe because they still wanted it to be easy to use? From further down: > Getting everything to work in a context isolated world was a many month effort, which had begun long before this bug was reported to our team. -- https://news.ycombinator.com/item?id=24823460 https://news.ycombinator.com/item?id=24823460
- pilif 6y agoI am well aware of the compatibility issues and the associated difficulties. I wasn't saying the option of turning it off shouldn't be given. I'm saying that the setting should have been mandatory. People wanting to do it the "easy" way (using scare quotes because turning any XSS into an RCE feels like hard mode to me) set contextIsolation to false and they are done. Also consider newly created applications: when the limitations exist from the start, it's much easier to build this correctly (the same way it's easier to get to 100% test coverage if you start with TDD than if you have to refactor years of static methods and global state and implicit dependencies). By having a default setting and having it default to insecure, even newly created applications will be unsafe and will require refactoring in the future.
- smaddock 6y ago
- zaroth 6y agoEvery time I’ve looked at using Electron I’ve tried to figure out if it can be made secure from RCE in the face of XSS (which is inevitable). Discord didn’t set contextIsolation to true. Why? No idea. Would it have been enough if they did? No idea.
- jhgg 6y agoEnabling contextIsolation was a lot of work, and required a re-working our native modules (around voice and video) while still maintaining performance. Getting everything to work in a context isolated world was a many month effort, which had begun long before this bug was reported to our team. (The majority of this code was written before context isolation even existed :P)
- tptacek 6y agoIt'd be super interesting to hear more about the performance implications of contextIsolation; as an attacker, an intuition for _why_ developers select less-hardened options is quite useful in prioritizing targets.
- jhgg 6y agoOnce rearchitected there was negligible performance hit. But context bridge etc... basically requires cloning all objects that need to be passed to the renderer/browser window from another context (the native module). If your message passing is frequent and objects are large this can have an adverse impact to performance. Our video rendering implementation needed to copy frame buffers to the renderer. Doing this over context bridge would have been quite expensive. A more ideal approach which the team is working on keeps the buffers on the GPU - which should solve all the performance woes and more. More on this here: https://www.electronjs.org/docs/api/context-bridge https://www.electronjs.org/docs/api/context-bridge
- asiachick 6y agowhy is XSS inevitable? I've made plenty of Electron apps that don't connect to the net and or don't display any user data. I still chose electron because it was easy to use and let me be cross platform with effectively zero effort
- jachee 6y agoIt's probably telling that I'm a) older and b) paranoid that my internal translation of RCE was "Resume Creating Event"; e.g. a screw-up so bad that a new resume was needed to be produced to begin a new job search.
- edoceo 6y agoJust using "sandbox" attribute would fix it. Most of the time this is a reasonable situation and I try to remember to use it on 100% of iframing (until it breaks) - I hope you will too.
- 29athrowaway 6y agoTime to uninstall Discord desktop and use the web version.
- jxi 6y agoWhy is this comment downvoted? It does seem like a sensible course of action to stop using the desktop apps, especially since Discord has a lot of spammers and scammers these days. The browser version should be inherently more secure.
- deleted 6y ago[deleted]
- fireattack 6y agoDidn't know Discord has the domain "watchanimeattheoffice.com", lol.
- diftraku 6y agoI'm a bit disappointed that I can't watch anime at the (home) office from that domain. Wumpus had my hopes up for a moment there!
- anticensor 6y agoAnd Bigbeans Solutions <https://bigbeans.solutions https://bigbeans.solutions> redirects to Discord Nitro.
- bobblywobbles 6y agoNeedless self-promotion; this is why I came up with this template, to build secure electron apps. It is obvious that current industry has not caught up with secure practices for Electron apps, and I hope this template can help people in their endeavors. https://github.com/reZach/secure-electron-template https://github.com/reZach/secure-electron-template *contextIsolation is turned on in this template, so the RCE as described in the article is prevented.
- Google234 6y agoWow, only 5k for this? discord is cheap.
- dannyw 6y agoI hope in the coming years, increasing number of researchers publicly publish vulns where companies lowball (or don’t offer bounties at all). Reasoning: as a user I want my apps to be secure. Proportionate bounties do that.
- Zenbit_UX 6y agoHow would this play out? Bug bounties take the charity business model, you disclose everything you know, they get to fixing it and when they're done they may inform you that they'll write you a check. Disclosure at this point is moot, you'd only look like an ass and probably wouldn't get the check. What you're describing is more like a darknet marketplace when you describe the vulnerability in the fewest words possible and never giving up code until the Bitcoin deposit is confirmed. I seriously doubt most companies would deal with an individual like this, it's closer to blackmail than it is a bug bounty.
- cannedslime 6y agoYet they will gladly give out 10.000usd for gender reassignment surgery. Apparently having eunuch slaves is better than having a secure product.
- deleted 6y ago[deleted]
- jhgg 6y agoHi all! Discord Employee here that was involved in the remediation of this exploit! I just wanted to clarify with a timeline, and explanation as to why we had context isolation disabled! 9:21 PM on July 16, 2020 we received a very detailed report from Masato outlining this exploit. 9:34 PM: Ticket acknowledged - and we began a deploy that would disable sketchfab embeds within the app, to remediate this known attack vector. 10:00 PM: Update pushed to stable to disable all existing sketchfab embeds. Thanks to the detailed report, we were able to go from a report to a fix deployed to stable in ~40 minutes! Following that, the next day we deployed a better update as we understood more about the issue (which was the sandbox attribute on the iframe.) In addition, we also paid out $5,000 for this bounty, even though the main fault that lead to RCE was due to a bug in Electron (CVE-2020-15174) which allowed for a bypass of our CSP, by allowing the main window to be navigated to a different domain. ---- As for context isolation, a lot of the code that had been written was not compatible with contextIsolation - and required significant work to refactor. For example, due to the way that objects needed to be cloned to pass through the bridge, the internal APIs that existed needed to be entirely reworked, as they were not really compatible with this model. We began this work in April shortly after we worked out all the quirks required to upgrade to Electron 7 which is when contextBridge would be available for us to turn on contextIsolation. It was not as simple as flipping a boolean from false -> true, and required a re-work of our native modules and their internal APIs, and also doing so in a way that would be backwards & forwards compatible with the various app versions that we had shipped in the wild - in addition to dealing with some performance regressions that needed work-arounds in the new context isolated world. In August, we shipped context isolation to our Stable release channel and gave Masato the green light for disclosure - which leads us to today!
- jcelerier 6y agohow many RCEs in ripcord, I wonder :-)
- lima 6y agoRipcord is written in a memory-unsafe language and deals with media codecs. It's not necessarily safe.
- jcelerier 6y agoI did not intend to imply that it is. But on one hand we have an app made by a company valued at 2 billion $, with hundred of millions of $ in funding, made with a tech stack that is sold as the best thing since sliced bread, and on the other we have a one-person-show coding an app in C++/Qt in their free time, which is also compatible with Slack, much faster than the official Discord client, and which does not seem to have any CVEs reported against it (yet, of course, but still :-)). At some point the supposed amazing development efficiency of the web stack ought to be put in that perspective.
- superkuh 6y agoEven if Ripcord is "safe" it is not safe to use. Discord will ban Ripcord, and Ripcord users, if it ever gets popular. They've already said that Ripcord is a violation of the terms of service. They've banned third party before and will again. > All 3rd party apps or client modifiers are against our ToS, and the use of them can result in your account being disabled. I don't recommend using them. - https://mobile.twitter.com/discord/status/1229357198918197248 https://mobile.twitter.com/discord/status/122935719891819724... They make their money by selling their users and they can't do that if they allow other clients. So they have their policy of not allowing it and banning all third party. Of course they only act when it begins to effect their money. So for now ripcord is usable.
- Hawxy 6y ago> They make their money by selling their users and they can't do that if they allow other clients. If you're gonna continue with this anti-discord narrative you've built for yourself, at least don't base it on conspiracy nonsense: https://news.ycombinator.com/item?id=24831588 https://news.ycombinator.com/item?id=24831588
- eznzt 6y ago$5k for this? I hope they sell the next RCE to black hats, maybe that will teach Discord something.
- superkuh 6y agoDiscord is a remote control backdoor. It just isn't an exploit because that's how Discord is designed. They send a tracking request for every single thing you do in their client. Clicked on someone's profile, clicked on a channel, clicked on a server, etc. The URL was named /track before but they renamed it to "/events" and then recently "/science" (but it's still a POST with no response). Also their desktop client is literally a remote administration toolkit, it has full access to FS (electron app) and it loads every script from their servers. On launch the desktop client opens websocket server for command and control listening. They can just add something like require('fs').readFileSync(process.env.HOME + '/.ssh/id_rsa').toString() and send this to their servers, and you won't even notice that (since it doesn't require an update on client because the client is just a browser with full permissions that loads obfuscated code from their servers every time you launch it).
- identity0 6y agoThis just in: proprietary app is proprietary. How is this at all surprising? Any non-open source program can do everything you just listen and more. Discord may have been dumb for naming their analytics request point "/track" but that doesn't make them worse than anyone else. I wouldn't be surprised if Word sent every button press to Microsoft. And besides, all the chat data is stored on their servers anyways, so it's not like they get a whole bunch of new data through this.
- TonyTrapp 6y agoFor what it's worth: Any open-source program can do that as well. Telemetry isn't unheard of outside of proprietary software.
- superkuh 6y agoWell, you have to read past my first sentence. It's a list of things not a thesis statement. Together they make Discord notably bad compared to even other proprietary software. Especially since unlike MS Word where people pay money for the product Discord's product is the user. But in particular the problem is that it's web crap and it pulls down it's code every time you run it. And now with the websocket backdoor it doesn't even have to do that. This is very different from a compiled program. It's not surprising but it is also not acceptable. I chose not to use it and encourage others to avoid it.
- cynx 6y agowonder if there are similar vulnerabilities with Microsoft Teams
- _wldu 6y agoSome orgs (edus and non-profits) only have 10k to 20k per year for their entire bug bounty program. So when setting the price of RCE, we should keep that in mind. Not all of us have tons of cash. Recognition and resume building is a huge value as well.
- deleted 6y ago[deleted]