Live data from Hacker News

Signal-desktop HTML tag injection advisory

ivan.barreraoro.com.ar

1–10 of 41 posts

Re: Signal-desktop HTML tag injection advisory

#7
post #5

I know that an unsanitized HTML input is a stupid issue to begin with, but update issued within 24 hours of discovery (and within 5 hours from disclosure)? That's really impressive.

> I know that an unsanitized HTML input is a stupid issue to begin with

Input is never the issue, output is: you don't know how the input will be used/rendered, so it should be messed with as little as possible.

Re: Signal-desktop HTML tag injection advisory

#8
post #2

Ah, Electron /sigh. Luckily this is fixed in the latest version (v1.11.0), so if you're a Signal user (you should be!) and you haven't upgraded already, you should upgrade immediately.

> (you should be!)

I don't see how going from one IM silo to another just because it's encrypted is going to help with anything. Especially one that's hostile towards alternative clients. I'm using XMPP with OMEMO, as I should be :P

Re: Signal-desktop HTML tag injection advisory

#10
Is this a joke?

>Solution/Vendor Information/Workaround

>For safer communications on desktop systems, please consider the use of a safer end-point client like PGP or GnuPG instead.

---

Meanwhile, regarding yesterday's PGP flaw:

https://www.eff.org/deeplinks/2018/05/not-so-pretty-what-you...

>EFF’s recommendations: Disable or uninstall PGP email plugins for now. Do not decrypt encrypted PGP messages that you receive. Instead, use non-email based messaging platforms, like Signal, for your encrypted messaging needs.

Post reply on HN