Mozilla VPN: CVE-2023-4104: vpndaemon wrongly implements Polkit authentication
openwall.com
openwall.com
> [...]
> 2023-05-04: We privately shared the findings with security@...illa.org, offering coordinated disclosure according to the openSUSE disclosure policy.
> Until 2023-06-12: There has been a lack of communication by upstream. Relevant questions about the disclosure process remained unanswered, there was no formal reply to our report and no wishes have been expressed about how to continue the coordinated disclosure, or what the next steps would be.
> 2023-06-12: We learned that the embargo over this issue was violated by upstream via a GitHub PR [3] and, inspired by that, our community packager followed suit via another GitHub PR [5].
What a complete clusterfuck. It's unbelievable that in 2023, a company of Mozilla's stature appears to have no proper processes in place for handling serious security vulnerabilities even when they are being reported to them (for free!) by cooperative third parties.
This taints the image of the entire product in my view.
Why? Technically, it shouldn't be impossible - one shouldn't exclude the other.
Isn't it just a way to sync a reading list across browsers, and have those pages pre-cached on a mobile device for reading when you have no connection?
I'm interested in what people find objectionable about it.
The strongest argument I've heard is that it's not core browser functionality, it was fine before Mozilla bought them, and therefore it's just a distraction/bloat for Firefox. Which is definitely arguable, but probably not a reason to write off the biggest independent browser.
Imo the people making a big deal out of it are using it to justify why they're OK sticking with chrome (best case), or have a partisan political reason to hate Mozilla because of their ESG / DEI positions (ughhhhhh)
HN loves to simultaneously criticize Mozilla for
1) being utterly financially dependent on Google
2) putting resources into anything except Firefox
3) doing anything that smells like monetizing Firefox
Spoiler alert: They can't avoid 1 without doing 2 or 3. It is what it is.
Basically, and I’ve been using it for that since before the acquisition, although recently the Android version had removed the option to cache full versions (only reader mode remains), which has enough of an impact on my usage that I’m planning to migrate away.
Still, there’s a lot of things that seem very misaligned with Mozilla’s mission: the huge dark-pattern tracking banner, the non-open-source nature, the huge dark-pattern tracking banner, the default homepage with weird US-politics-related recommendations that has replaced the actual list, the huge dark-pattern tracking banner, the recommended links inserted at the end of each article as an engagement-driven manipulation, and have I mentioned the huge dark-pattern tracking banner with the accompanying tracking. This would be an expected amount of evil assholery from a random SV startup, but from Mozilla it does feel like a point to add to the betrayal tally (hello EME/Widevine),
A browser made by an Ad Tech company that aims to lock down and control the web.
And a browser made by a nonprofit that occasionally makes a minor mistep.
You cannot seriously compare the remote attestation DRM, manifest v3 changes, to, what ? the Mr. Robot ad that was tacky? the pocket integration that's pointless and annoying but otherwise harmless?
Seriously, y'alls double standards are insane and focuses so much towards how bad it was that Brendan Eich got kicked out that it comes off as extremely political
But actively caring about browser companies, and choosing Chrome because Mozilla "sold out" when they added pocket is a pretty wild take imo.
& hey, if you prefer Chrome because you find it more usable or performant that's a perfectly good reason
I'm mostly upset at the people in this thread (presumably not you) who seem to be against Firefox for ideological reasons which seems completely backwards to me
As much as I'd love it though, I don't think it's reasonably to expect everyone else to care as much as we do. There's plenty of other issues that matter too that I'm glad other people are out there caring about on my behalf. Eg. I know being vegan is better but its a big annoying change and I haven't been able to do it yet.
I'm mostly concerned with all the rhetroic here that's trying to paint firefox as unsympathetic when they are clearly the people fighting on our side. If you don't personally care enough to switch to FF, or use Graphene OS, or run Linux etc. I get that, but pleeease don't also try to discourage other people too, y'know?
(& ofc the real solution is through policy and getting an American version of GDPR/California Privacy act, getting courts to stop the NSA etc. Being preachy online is counterproductive to getting broad support and the mission overall imo)
I'm not a privacy fanatic and I don't really care if my browser supports proprietary DRM so that I'm able to watch shows on streaming platforms. However, I see a lot of potential for the remote attestation mechanism proposed by Google to give companies an easy way to enforce "We support this set of browsers on this set of operating systems" and effectively cut off support for Linux and browsers that aren't popular Chromium variants. That doesn't mean I can't go and switch companies but that requires a lot of effort on my part to do so.
I don't think it's fair to claim the nonprofit side only exists to "claim legitimacy." All of their revenue goes back into the corporation or the foundation.
This a very common arrangement used by charities to enable a commercial process that funds the charity. For example, high street charity shops may be part of the commercial sub-entity so that their accounts are processed like a normal company, but 100% of their profits become donations to fund the parent charity's activities, called the charitable purpose(s).
If they didn't separate into a parent charity with a commercial sub-entity, all of the activities of the sub-entity would be subject to charity auditing, accounting and purpose rules, which in practice would make it difficult to run a shop competitively, or alternatively the parent could not have charity status and the shop profit would be subject to tax instead of all being directed to the audited, charitable purpose(s).
In Mozilla's case, if it was a tax-exempt non-profit without a commercial sub-entity giving 100% of profits to its parent, it would not be able to take Google funding as a trade in exchange for making Google the default search engine without losing its tax-exempt status, and it might not be able to pay its software engineers a competitive market rate, even if it needs to do that to compete. It would be able to take donations (not as a trade in exchange for something, just as a donation), but that wouldn't be enough to develop a competitive browser.
That doesn't sound like a bad thing. Googles funding is not a boon but a shackle that holds FF back. Same for developers that expect SV market rates - those will be developers that are used to user-hostile software developement practiced in other SV companies.
> It would be able to take donations (not as a trade in exchange for something, just as a donation), but that wouldn't be enough to develop a competitive browser.
How do you know? Individual donations are also far from the only possible way to fund a real charity.
But it is really a nonprofit in that (like the sibling says) the corp is fully owned by a nonprofit, not public shareholders.
And its not like google doesn't get anything out of their $. They get set as the default engine. Apple gets paid hundreds of billions by google for this. So its not like Google is paying Firefox for control over it's development.
Like, seriously, they're not perfect but its a pretty wide jump in behavior between it and chrome
Free, up to date and does not send neither money nor data to Mozilla.
But personally I don't care so much about privacy extremism:
The day another more liberal organization forks it again, adds Google search for some easy cash and start fixing the extension API etc I am probably going to recommend that.
I already dial back some extreme measure(s), nuking my sessions whenever I close the browser comes to mind.
Also of course I will not use Google myself, but it seems to be the way for browser developers to make a living so I'll allow whoever takes care of the future of Firefox to do the same.
> It is possible that Apple Silicon users see their recently downloaded LibreWolf flagged as broken or unsafe by the OS. This happens because we do not notarize the macOS version of the browser: we don't have a paid Apple Developer license and we don't want to support this signing mechanism that is put behind a paywall without providing significant gains.
Eeerm... no, thank you.
Will reconsider if it appears in openSUSE Tumbleweed repos after passing a security review from the openSUSE team ;)
"Selling users off" only matters to anyone trying to push some unheard of and less-secure forks of Chrome or Firefox. Nobody notable code-reviews theses browsers, you're at the mercy at some random person or small group to play catch-up with upstream browsers, and you're ultimately still locked into somebody else's decisions.
I use Firefox because double-clicking code one-liners from my wiki doesn't add a newline when pasted into Terminals on Linux, which I use on desktop for the challenge of it. Windows Terminal on Windows doesn't have this issue from any browser and I'm free to use Edge or Chrome there.
Same with that hidden spyware ad/extension (distributed using channels reserved for delivering 0day bugfixes). Mozilla shit on it's users without even getting paid for it.
Maybe I have reading comprehension issues, because it seems to me like it isn't worse than selling users off. Mozilla sold its users... to itself. That's really bad, right?
To add further context, that PR violating the embargo:
- removes authentication entirely instead of fixing it
- discusses it as if they've discovered the CVE independently, even though it had seemingly been reported to them just 1 month prior. It may be that they did discover it independently, but the timing seems odd for a bug that existed for 3 years.
- discusses it in an extremely casual way, as if the vuln is not severe. Honestly I don't know enough about the vectors here to know what type of CVSS it might end up with.
---
Edit: Based on @AAchen's HN comment, it seems compromise requires local shell, so not an incredibly high severity it would seem. Still curious to see what NVD come out with.
9.8
It's always 9.8.
To be fair, this is an application, so the score might be more grounded in reality. The CVEs I encounter as a developer are always insane and generally massive overreach from security to product design. It's not a vulnerability against all downstream libraries and applications that using some obviously unsafe C++ call might cause a DoS due to poor performance.
If you have 10 security bugs, 3 are genuinely high severity and 9 get assigned high severity by NVD, then at least you've managed to deprioritise one of them. It's something (unironiccally).
This is a pretty decent overview https://www.first.org/epss/model
On a side note, CVSS v4.0 arrived around 2023-01 and is.. maybe(?) better: https://www.first.org/cvss/v4-0/
While I agree with your sentiment here, it's not exceptionnal at all and I've seen security researcher complaining about the same thing comming from at least Intel, Cisco and Google[1]! And I wouldn't be suprised if you could find example if that regarding Apple and Microsoft as well.
[1] and for Google it was just one month ago: https://matan-h.com/google-has-a-secret-browser-hidden-insid...
So you need to have a local shell on the system of the user you want to attack. Not cool, it violates permission boundaries that are there for a reason, but the headline sounded to me like a remote authentication bypass (I'm not into the whole D-Bus/Polkit thing) which this is not
ex: Desktop Linux's running X have a trivial escalation path; any program can read all keystrokes across all users. You type your sudo password in, you're screwed.
Or if the attacker is running as your user they can just modify your bashrc, aliases, etc, to do a whole bunch of things - like having `sudo` go to an attacker controlled binary - that one will work on the server, too!
So yeah sandboxing builds is super important because "unprivileged users" are almost always one trivial step away from full root.
Beyond just minding privileges of the user, building in a container/chroot/etc is nice from a cleanliness/repeatability perspective.
For those interested in the Fedora packaging ecosystem -- look into fedpkg and mock
https://docs.fedoraproject.org/en-US/package-maintainers/Pac...
and this is why I tell everyone who wants to run a rolling release distro to go with Opensuse rather than distros where people just install random packages from community repositories. They are so underrated given the scrutiny they put into their packaging and build process.
They did infact
removed polkit : https://github.com/mozilla-mobile/mozilla-vpn-client/pull/70...
refactor auth using D-Bus: https://github.com/mozilla-mobile/mozilla-vpn-client/pull/71...
These are why author's PR was dropped.
A user-configured VPN should not run as root and affect networking for the entire system; the whole VPN process should run in its own network namespace with no more privileges beyond those of the user activating it. Processes that need to use the VPN (rather than clearnet) should be attached to that same network namespace. If necessary, you can even avoid attaching a NAT (e.g.: slirp4netns) to the namespace so that if the VPN dies there is no data leakage.
I get that running things as root has a bit more performance, but compromising on security for the sake of performance doesn't sound like the right approach for this kind of software.
If some pam session module were to set up its own network namespace that is shared by all user processes after login, this could be (mostly) solved. The result would be some surprising behaviour though, as processes outside have a possibly vastly different view of the network.
That the service runs as root isn't really the issue here. None of the attack relies on the abuse of some root capabilities, it's an authentication issue that abuses how the service works. Even if it were unprivileged somehow, this would still be the same impact.
Ultimately this means there is no fix available yet and no ETA when there will be one.
On a related note, Polkit, itself, has had its own privilege escalation problems:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4034
https://blog.qualys.com/vulnerabilities-threat-research/2022...
The name is more than appropriate. It's not the developer of Mozilla VPN.