GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    srslypascal (srslypascal@chaos.social)'s status on Friday, 27-Oct-2023 18:17:05 JST srslypascal srslypascal
    in reply to
    • Alexandre Dulaunoy

    @adulau

    They should just get rid altogether of the liability/technical debt that is Electron.

    As of signal-desktop 6.36.0, they still use Electron 25.8.4, which is affected by at least 8 different security issues according to the release notes of Electron 25.9.0 through 25.9.3.

    https://github.com/signalapp/Signal-Desktop/blob/v6.36.0/package.json#L275

    And on top of all of these issues, there remains the issue of the disabled sandbox, which they haven't bothered to fix in over 4 years.

    https://github.com/signalapp/Signal-Desktop/issues/3573

    In conversation Friday, 27-Oct-2023 18:17:05 JST from chaos.social permalink

    Attachments


    • Embed this notice
      Alexandre Dulaunoy (adulau@infosec.exchange)'s status on Friday, 27-Oct-2023 18:17:10 JST Alexandre Dulaunoy Alexandre Dulaunoy
      • Signal
      • jvoisin

      Digging a little bit in the some ICC profiles added in signal-app, I updated the original issue and there is clearly an issue where new ICC profiles are created from the Google skia library.

      https://github.com/signalapp/Signal-Desktop/issues/6031#issuecomment-1702432836

      This issue only appears when the media-quality is to high. Maybe an allow-list strategy like the mat2 tool written by @jvoisin would be better to be sure that new metadata created are discarded by default.

      @signalapp

      #privacy #signal #signalapp #metadata

      In conversation Friday, 27-Oct-2023 18:17:10 JST permalink

      Attachments


      1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/110/989/239/354/120/776/original/784eef0aacd6c835.png
      2. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
        Signal Desktop inserts invalid information (including copyright information) into photo exif data · Issue #6031 · signalapp/Signal-Desktop
        I took a picture of an object, when sending a photo to Signal (in a private message) and uploading it to a PC through Signal Desktop, I get an excessive amount of metadata (exif), and the worst tag...
      pettter repeated this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.