4 ms·
The OP is asking for more detail than “not enough”, though: “Can it escape the Chromium renderer sandbox? Or is that sandbox disabled?”
by untog 6y ago
The OP is asking for more detail than “not enough”, though:
“Can it escape the Chromium renderer sandbox? Or is that sandbox disabled?”
- oskarsv 6y agoto simplify - no it’s not enabled the real answer is more complicated as it is not necessarily a global setting and depends on what you call a “sandbox”
- mwcampbell 6y agoThanks. I'd pay (moderately) for the more complicated answer. An ebook on Electron security might be a good idea.
- oskarsv 6y agoI'm not an expert on Electron security! But if not addressed to me, there is no need to pay, you can start here: - https://www.electronjs.org/docs/tutorial/security https://www.electronjs.org/docs/tutorial/security - https://github.com/electron/electron/security/advisories https://github.com/electron/electron/security/advisories As you can see there are plenty of considerations and pitfalls to take into account. Best option is to enable contextIsolation for everything. Further, Electron security is closely tied to Chrome security so that is one deep rabbit hole
- pjmlp 6y agoBest Electron security is not using it in first place.
- MaxBarraclough 6y agoRather just keep it in the browser? ;-P
- kevingadd 6y agoThis is safer to a significant degree.
- coldtea 6y agoYeah, let's stick with raw C/C++, that would be much safer... Or maybe let's use some research language made by Wirth, and get access to all 10 of packages and 5 devs worldwide using it :-)
- gitweb 6y agoTelegram Desktop is a cross-platform C++ app. What similar remote code execution exploit has existed in the wild for it?
- valand 6y agoFYI it's not just PL that factors into security. The engineers, for example.
- coldtea 6y agoThe exact same kind of RCE? https://securelist.com/zero-day-vulnerability-in-telegram/83800/ https://securelist.com/zero-day-vulnerability-in-telegram/83... and others... https://www.notebookcheck.net/Researchers-at-Symantec-discover-media-file-vulnerability-in-WhatsApp-and-Telegram.427741.0.html https://www.notebookcheck.net/Researchers-at-Symantec-discov...
- gitweb 6y agoOne of them requires the user to click run on a file, much like running an EXE. The other, simply saves potentially malicious data to external storage which would then have to be run by a separate malicious third-party app. This are far from RCE exploits that execute immediately without poor user decision making, and Rust is not impervious to security exploits similar to these.
- untog 6y agoC'mon. Just because there is one C++ app without remote exploits doesn't mean all C++ apps are immune.
- pjmlp 6y agoFor starters, leave it on the browser. I didn't mention any programming language.