TomSellers, to security

Roughly 2 weeks ago Google patched a critical vulnerability, CVE-2023-4863, that was being exploited in the wild. The broad impact of the root cause of the vuln and the fact that it will have a long tail of unpatched software has been poorly communicated. You can read more in @dangoodin 's excellent article on Ars Technica.

As pointed out in the article above, Electron is based on Chromium and is impacted. Electron is bundled in a ton of apps that people might overlook.

I threw together the following shell command to help macOS audit which versions of Electron apps are installed.

find /Applications -type f -name "*Electron Framework*" -exec <br></br>  sh -c "echo  "{}" && strings "{}" | grep '^Chrome/[0-9.]* Electron/[0-9]' | head -n1 && echo " ;<br></br>

When run, you should see something similar to the following:

/Applications/Visual Studio Code.app/Contents/Frameworks/Electron Framework.framework/Versions/A/Electron Framework<br></br>Chrome/114.0.5735.289 Electron/25.8.1<br></br><br></br>/Applications/Slack.app/Contents/Frameworks/Electron Framework.framework/Versions/A/Electron Framework<br></br>Chrome/116.0.5845.188 Electron/26.2.1<br></br>

-2023-4863

alancheilek,

@mjgardner @delfuego @TomSellers @electronjs @getpostman

I see that Microsoft also uses Electron 19.1.8 in ! (Seems like there might be a vector to attack that, somehow, since one can send messages to another user?)
is vulnerable with 22.3.14
Contrary to what I see in the release notes, my updated is on 25.8.0 (not .1)
has 25.5.0

ada, to random

please use matrix we have:

  • a client made by an enterprise who will willingly backdoor your messages
  • a client made by 3 people that get random breaking changes that completely obliterate flow
  • a client that is one giant html5 canvas that uses 100% of your browser gpu power
  • a client that requires systemd
  • way too many abandoned android and ios clients

please use fedi we have:

  • an instance software which is so popular but so feature deprived it makes no sense why it exists, also it's trademarked in a bad way
  • an instance software that has so much code rot it spawned 500 forks to try and fix it only to become rotten themselves
  • an instance software that doesn't really know what it's doing and instead implemented 3 different api standards, and this is the fork i'm talking about. no one should talk about the upstream project.

this really is the FOSS curse, huh?

kkarhan,

@Natanox @ada I mean it's the #InconvenientTruth.

Do you know why #Fax, #SMS, #eMail, #IRC & #XMPP still exist whilst #AIM, #ICQ & #Skype are basically dead?

It's because they are #openStandards that are #decentralized and have a working #MultiVendor / #MultiProvider #ecosystem around them.

Same reason why people still buy gasoline and diesel vehicles: Shit just works and scales...

jplebreton, to random
@jplebreton@mastodon.social avatar

Was reminded recently that Discord has taken nearly $1 billion in VC cash: https://tracxn.com/d/companies/discord/__5rlLgsamoGCjo5gATenpy383J_jyBToAQkMl2B_f99w
No judgment if you've already built a community there, but everyone really needs to treat it as a ticking time bomb. It's already failed its users many times over; it's just a question of when those failures will escalate beyond even the most indifferent user's tolerance. Every community deserves better. Good alternatives are a survival imperative.

kkarhan,

@jplebreton also their #ToS are inacceptable and I urge everyone to give alternatives a try, ranging from #GitHub and espechally #GitLab to #Zulip, #Mumble, #JitsiMeet and #Nextcloud depending on the workflows and needs.

NOONE IS FORVED ONTO #DISCORD!

Imho it's just a combination of all the bad things from #Slack, #MicrosoftTeams, #Skype and #Mattermost woth no redeeming qualities.

You might just use #Matrix, #DeltaChat, #XMPP+#OMEMO or even #IRC instead!!!

Jgmeadows, to linux

Ha ha another reason not to use Windows 11! At least when I install software on my daily driver I don't get chiding pop-ups. https://www.neowin.net/news/microsoft-now-wants-you-to-take-a-poll-before-installing-google-chrome/

chasehainey,

@Jgmeadows Having and other apps keep getting reinstalled after I specifically removed them was what caused me to ditch for good. All of the games I play work in without issue. Had to use a few app alternatives, but overall super glad to not be on Windows anymore.

starshine, to random
@starshine@woem.space avatar

oh don’t worry, discord won’t shut down. it will just gradually enshittify more and more as it keeps trying to make more money as the vc funds dry up, eventually being bought by a large corporation looking to sell the user data for a nice profit.

then once it gets bad enough, another centralized, proprietary platform will pop up that promises to be slightly better than discord (at least, better than discord after its gradual decline), people will move to it in droves, and the cycle will start all over again

discord will continue to stick around for a couple more years after that, until the company that bought it decides it’s not worth running anymore and unceremoniously shuts it down, destroying over a decade worth of people’s memories in the process

:woem:

kkarhan,

@starshine Just like #AIM amd #ICQ and #Skype...

Maybe it's time people start considering actual alternatives lile #Zulip ( https://zulip.com ) and #IRC as well as #XMPP+#OMEMO...

josephcox, to random

New from 404 Media: hackers can grab your IP address through Skype by just sending a link. Target doesn't even need to click it.

I know because researcher did it to me. Sent me a link, then pasted my IP in the chat.

“Damn, RIP 💀,” I wrote in response.

And Microsoft is in no rush to fix. Company only said it would fix eventually after 404 Media contacted for comment. To fund more impact journalism, subscribe to 404 Media in the buttons in the article.

https://www.404media.co/hackers-find-your-skype-ip-address-microsoft-wont-fix/

ai6yr,
@ai6yr@m.ai6yr.org avatar

@josephcox #Skype #cybersecurity (er... lack of security)

sluecking, to random German

Ich finde das digitale Leben ziemlich anstrengend.

Aktuell erhalte ich regelmäßig Zoom-Links für Besprechungen zur zweit oder zu dritt per #Videokonferenz

Ich finde es lästig, dann immer mitzuteilen, dass ich #Zoom nicht benutzen möchte.

Wenn ich mit anderen darüber spreche, kommt oft die Behauptung, dass die freien Alternativen nicht richtig funktionieren (was ich bei einer so geringen Teilnehmerzahl nun wirklich nachvollziehen kann).

Wie kann ich mit solchen Situationen besser umgehen, ohne ständig dass Gefühl zu haben, mich dafür rechtfertigen zu müssen?

digitalcourage,
@digitalcourage@digitalcourage.social avatar

@sluecking Je nachdem, wie polemisch die Begründung sein darf, kannst du entweder auf die #BigBrotherAwards-Laudatio <https://bigbrotherawards.de/2023/zoom> verweisen oder auf die dort ganz unten als Quelle verlinkte Untersuchung des Bundeskartellamts in Zusammenarbeit mit dem @bsi:

„Sektoruntersuchung Messenger- und Video-Dienste. Abschlussbericht des Bundeskartellamts unter Mitwirkung des Bundesamts für Sicherheit in der Informationstechnik. Bericht gemäß § 32e GWB. Az. V-28/20. Mai 2023“ (PDF)
https://www.bundeskartellamt.de/SharedDocs/Publikation/DE/Sektoruntersuchungen/Sektoruntersuchung_MessengerVideoDienste.pdf?__blob=publicationFile&v=4

Diese Untersuchung beschäftigt sich außer mit #Zoom auch mit anderem Murks wie z.B. #Cisco #WebEx und MS #Skype und #Teams. Wer sie genau liest, wird zu dem Schluss kommen, dass diese Produkte in der EU nicht legal einsetzbar sind. Die Studie empfiehlt quelloffene Lösungen wie #BigBlueButton und #JitsiMeet. /c

Wyndix, to random

Am I the only one who thinks that #Signal would have worked better as a p2p app?

knu,

@Wyndix You mean, like the original #Skype, until Microsoft took over in 2014 or so?
No, you are not the only one.
{No #ai in this message}

deltatux, to infosec

Looks like Microsoft has released patches against CVE-2023-4863 and CVE-2023-5217 vulnerabilities for Microsoft Edge, Teams and Skype. The patches revolve around the vulnerable the libvpx & libwebp open source libraries used by these products. Update now!

https://www.bleepingcomputer.com/news/microsoft/microsoft-edge-teams-get-fixes-for-zero-days-in-open-source-libraries/

vascorsd, to privacy
@vascorsd@mastodon.social avatar

New Jami messenger release.
Improvements include:

  • message editing
  • faster conmection to peers
  • extensions store (to add for example green background to video calls)
  • push to talk

Eleutheria, for more enjoyable private, and secure communication
https://jami.net/eleutheria/

#jami #privacy #chat #gnu #security


Depending on your requirements could replace some usage of any of the following: #xmpp #matrix #signal #skype #googlemeet #msteams #jitsi #zoom

paco, to random

Did you know #skype can kiss my ass? #skype is abusing the notification permissions I granted it to send me bullshit notifications.

uslmz, to microsoft Turkish

#Microsoft :
#Skype ( 29 Ağustos 2003)

#Meta Platform :
#Facebook ( 4 Şubat 2004) , #Instagram ( 6 Ekim 2010 ) , #WhatsApp (Ocak 2010 ) , #Threads ( 6 Temmuz 2023 )

• Twitter Inc. ( X corp.):
#Twitter ( 21 Mart 2006 )

• Snapchat Inc.
#Snapchat ( Eylül 2011 )

• WeChat International Pte. Ltd.
#WeChat ( Ocak 2011)

• Telegram FZ-LLC :
#Telegram ( Ağustos 2013 )

• Signal Foundation
#Signal ( 29 Temmuz 2014 )

• gGmbH
#Mastodon ( 16 Mart 2016 )

matdevdug, to ai
@matdevdug@c.im avatar

As someone who doesn’t like , getting for free is amazing! They’ll mismanage that company into the ground just like they do for all their acquisitions. Enjoy the same rockstar treatment and got.

YurkshireLad, to random
@YurkshireLad@mastodon.social avatar

When you use #skype or #zoom, does the video traffic go through their servers, or does it only go between the two devices that are communicating via video chat?

skry, to journalism
@skry@mastodon.social avatar

“Hackers are able to grab a target’s IP address, potentially revealing their general physical location, by simply sending a link over the mobile app. The target does not need to click the link or otherwise interact with the hacker beyond opening the message, according to a security researcher who demonstrated the issue and successfully discovered my IP address by using it.”

https://www.404media.co/hackers-find-your-skype-ip-address-microsoft-wont-fix/

w/ @josephcox

cassidy, (edited ) to random
@cassidy@blaede.family avatar

Hackers can silently grab your IP address through Skype, and apparently Microsoft is in no rush to fix it.

https://www.404media.co/hackers-find-your-skype-ip-address-microsoft-wont-fix/

remixtures, to Cybersecurity Portuguese
@remixtures@tldr.nettime.org avatar

#Cybersecurity #Hacking #Skype #Microsoft: "Hackers are able to grab a target’s IP address, potentially revealing their general physical location, by simply sending a link over the Skype mobile app. The target does not need to click the link or otherwise interact with the hacker beyond opening the message, according to a security researcher who demonstrated the issue and successfully discovered my IP address by using it.

Yossi, the independent security researcher who uncovered the vulnerability, reported the issue to Microsoft earlier this month, according to Yossi and a cache of emails and bug reports he shared with 404 Media. In those emails Microsoft said the issue does not require immediate servicing, and gave no indication that it plans to fix the security hole. Only after 404 Media contacted Microsoft for comment did the company say it would patch the issue in an upcoming update."

https://www.404media.co/hackers-find-your-skype-ip-address-microsoft-wont-fix/

alternativeto, to random
@alternativeto@mas.to avatar

Hackers can obtain a user's IP address by sending a link via the #Skype mobile app, potentially revealing their physical location. Microsoft was informed of the vulnerability, but only committed to issuing a patch after media attention.
https://alternativeto.net/news/2023/8/a-skype-vulnerability-can-expose-a-user-ip-address-but-microsoft-doesn-t-think-it-s-that-bad/

majorlinux, to microsoft
@majorlinux@toot.majorshouse.com avatar

I mean, why it may not be a "security vulnerability" in Microsoft's eyes, it's still not generally great practice to just let IP addresses just be exposed to everybody.

A Skype app vulnerability could expose your IP address to hackers — and Microsoft has yet to fix it https://www.theverge.com/2023/8/28/23848823/skype-vulnerability-ip-address-microsoft

thomasweibel, to Instagram German
@thomasweibel@swiss.social avatar

"Opa hat was ganz Komisches erzählt. Früher war #Instagram dick und schwer und aus Papier. #Handy​s waren gross wie ein Koffer und in Glaskabinen auf der Strasse festgeschraubt. Zum #Skype​n ohne Bild musste man #Bitcoin​s aus Metall einwerfen, und dann konnte man damit nicht mal googeln."

paco, to TeslaMotors

Signed in to on mobile for the first time in ages. It apparently has some kind of “today” feed full of news. Of all the features nobody asked for and nobody wanted. Anyways, what were the first two items in “my” feed? and . Then an Ad. Then sports, , and then Russia using a new weapon in the war. Amazing.

premartinpatrick, to microsoft French
@premartinpatrick@mastouille.fr avatar

Vous aussi ça vous saoule ?

Bizarrement on retrouve ça de plus en plus souvent sur les réseaux sociaux et même des logiciels maintenant.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • GTA5RPClips
  • Durango
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • provamag3
  • tacticalgear
  • osvaldo12
  • tester
  • cubers
  • cisconetworking
  • mdbf
  • ethstaker
  • modclub
  • Leos
  • anitta
  • normalnudes
  • megavids
  • lostlight
  • All magazines