6 ms·
Malware infiltrates Pidgin messenger's official plugin repository
- itohihiyt 2y agoI used to use pidgin years ago before social media ruined the internet as a central place to message people across different services. I didn't know it was still going in the social media/walled garden age.
- rw_grim 2y agoYeah we're still here and trying to get an experimental pre-alpha release of Pidgin3 out by the end of the year. Unfortunately basically everything had to change to support modern chat features, so initial protocol support is going to be very light.
- ASalazarMX 2y agoFormer Trillian user here. It all went to shit when AOL started the AIM Wars, and then Trillian gradually changed from cool to enshittified. It was an awesome time when interoperability was a thing, though.
- blueflow 2y agoOriginal announcement: https://pidgin.im/posts/2024-08-malicious-plugin/ https://pidgin.im/posts/2024-08-malicious-plugin/ LWN: https://lwn.net/Articles/987320/ https://lwn.net/Articles/987320/ The plugin provided some kind of screen sharing.
- rw_grim 2y agoA more in-depth post will be coming soon. I'm working on the first draft of it tonight on everything that happened.
- deleted 2y ago[deleted]
- molticrystal 2y agoZerodium [0] [1] offered $100k for a remote code execution exploit for Pidgen about 3 years ago, the offer ran from June to September of 2021. Governments and a lot of bad agents must really want to get into that app. I haven't used it for years since AIM and ICQ became unpopular to my peers, and most places like Google dropped XMPP support. Perhaps Pidgen added support and became a great chat client for some protocol on the rise that I am unaware. Is it still widely deployed in certain contexts or countries? [0] https://twitter.com/rw_grim/status/1399817799657218059 https://twitter.com/rw_grim/status/1399817799657218059 [1] https://news.ycombinator.com/item?id=27371612 https://news.ycombinator.com/item?id=27371612
- rw_grim 2y agoWe're finally gearing up to have an experimental release of Pidgin 3.0 by the end of the year, but the goal right now only include the IRC protocol. But everything has been updated to support all of the newer chat features so support for other protocols should come quick.
- self_awareness 2y ago(warning, heavily opinionated post follows) I know it's asking for a lot, but it would be really cool if Pidgin would have 1st-class out-of-the-box support for Matrix. I don't want to get into discussions if it's better than Jabber, because I don't really think it is, but since the momentum is on Matrix rather than XMPP, then I'd say that Pidgin could use the fact that currently Matrix lacks a proper client. By "proper client" I mean something that is feature-complete by standards of year 2000 (actually good software, like Pidgin), not 2020 (which features broken, half-ass web prototypes that people call software). It would probably help with fighting the parasites like Discord, which is way too popular than it should be.
- Arathorn 2y agosomeone could certainly pick up https://github.com/matrix-org/purple-matrix https://github.com/matrix-org/purple-matrix and finish it.
- secfirstmd 2y agoIntersting. Pidgin and variations are used by some gov orgs.
- chewbaxxa 2y agoPidgin (and its OTR plugin) used to be the most popular client for OTR (Off-The-Record, an encryption protocol) messaging. That was my experience about 10 years ago and back then I think the plugins were known to be a weak point in its security.
- ris 2y agoSurprise! In-app plugin repos are a supply-chain disaster zone. I had to walk away from a project that wouldn't take the threat seriously lest I get caught up in the fallout when it all goes horribly wrong.
- rw_grim 2y agoSurprise, this is just an index of plugins on a webpage and not in app at all...
- vxxzy 2y agooh wow. I have become fond of pidgin over the years. There is a slack plugin that makes life a lot better. It seems for plugins, extensions, app stores, and general third-party repositories (pip, npm, crates, etc) risks are increasing. Centralization breeds certain risks that are tough to mitigate. So far, mitigating these risks involve trusting a central steward, cryptographic signing, and contributor reputation.I wonder if we can ever truly mitigate the contributor or steward aspects?
- rectang 2y ago> A red flag is that ss-otr only provided binaries for download and not any source code, but due to the lack of robust reviewing mechanisms in Pidgin's third-party plugin repository, nobody questioned its security. Opaque binaries without deterministic builds are an open source supply chain security hole that we will slowly, inevitably narrow. There will be much kicking and screaming along the way, though.
- noman-land 2y agoIs Pidgen still the default IRC client bundled with Tails?
- 3np 2y agoThat's Pidgin not "Pidgen". And yes.
- woodruffw 2y ago> To prevent similar incidents from happening in the future, Pidgin announced that, from now on, it will only accept third-party plugins that have an OSI Approved Open Source License, allowing scrutiny into their code and internal functionality. This is an understandable policy, but how would it have stymied the attacker in this case? It's unlikely that Windows users would be building from source (and Darkgate appears to be Windows only). Unless there's a policy that Pidgin extensions are strictly reproducible, it seems unlikely that the presence of an adjacent, benign source artifact would have increased the likelihood of early discovery.
- lolinder 2y ago> The moral is obvious. You can't trust code that you did not totally create yourself. (Especially code from companies that employ people like me.) No amount of source-level verification or scrutiny will protect you from using untrusted code. — Ken Thompson, Reflections on Trusting Trust, 1984 https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...
- woodruffw 2y agoI think quoting RoTT in this context is a little cliche: as a practical matter, we're all trusting immense amounts of code that we haven't read. The question is what to do about that practical reality, other than "give up because of the existential threat of a compiler backdoor."
- Dalewyn 2y agoThe answer is to procure your binaries from sources you trust: * Commercial vendors like Microsoft, Intel, Valve, etc. who have a vested financial interest in your continued patronage. * Private vendors like the guys behind WINE, Notepad++, ffmpeg, etc. who are reputable and have that reputation on the line. Speaking practically, if you don't trust your source to begin with you aren't going to waste your time auditing their code and compiling it yourself either.
- gus_ 2y agowas this the malicious plugin? (from the reddit thread [0]) https://github.com/jabberplugins/pidgin-screenshare https://github.com/jabberplugins/pidgin-screenshare The plugin uses a reverse-tunneling SocketIO-server (to bypass NAT) on https://jabberplugins.net (*hosted by me*) which is used for routing OTR-encrypted (if enabled) screenshare packets between you & your buddy. It also includes the libotr lib, modified by the author. I'd love to read the analysis by Johnny Xmas, the report from 0xfffc0000 and even the binary so other people can test it with other tools and/or analyze it. [0] https://www.reddit.com/r/linux/comments/1f1jv08/comment/lk1oa70/ https://www.reddit.com/r/linux/comments/1f1jv08/comment/lk1o...