Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1192484 > unrolled thread

Bug#1068122: /usr/bin/firefox: clings to USB stick, Debian 12.5 up-to-date, Xfce

Started byAntti-Pekka Johannes Känsälä <antti.pekka.kansala@iki.fi>
First post2024-03-31 12:00 +0200
Last post2024-05-06 18:40 +0200
Articles 8 — 3 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#1068122: /usr/bin/firefox: clings to USB stick, Debian 12.5 up-to-date, Xfce Antti-Pekka Johannes Känsälä <antti.pekka.kansala@iki.fi> - 2024-03-31 12:00 +0200
    Bug#1068122: My thoughts on the possible problem Antti-Pekka Känsälä <antti.pekka.kansala@gmail.com> - 2024-03-31 17:30 +0200
    Bug#1068122: /usr/bin/firefox: clings to USB stick, Debian 12.5 up-to-date, Xfce Max Nikulin <manikulin@gmail.com> - 2024-04-06 09:52 +0200
    Bug#1068122: /usr/bin/firefox: clings to USB stick, Debian 12.5 up-to-date, Xfce Max Nikulin <manikulin@gmail.com> - 2024-04-06 16:40 +0200
    Bug#1068122: /usr/bin/firefox: clings to USB stick, Debian 12.5 up-to-date, Xfce Antti-Pekka Känsälä <antti.pekka.kansala@gmail.com> - 2024-04-09 13:40 +0200
      Bug#1068122: /usr/bin/firefox: clings to USB stick, Debian 12.5 up-to-date, Xfce Max Nikulin <manikulin@gmail.com> - 2024-04-12 18:50 +0200
    Bug#1068122: /usr/bin/firefox: clings to USB stick, Debian 12.5 up-to-date, Xfce Antti-Pekka Känsälä <antti.pekka.kansala@gmail.com> - 2024-04-18 19:40 +0200
      Bug#1068122: /usr/bin/firefox: clings to USB stick, Debian 12.5 up-to-date, Xfce Max Nikulin <manikulin@gmail.com> - 2024-05-06 18:40 +0200

#1192484 — Bug#1068122: /usr/bin/firefox: clings to USB stick, Debian 12.5 up-to-date, Xfce

FromAntti-Pekka Johannes Känsälä <antti.pekka.kansala@iki.fi>
Date2024-03-31 12:00 +0200
SubjectBug#1068122: /usr/bin/firefox: clings to USB stick, Debian 12.5 up-to-date, Xfce
Message-ID<Io08N-2ZVc-1@gated-at.bofh.it>
Package: firefox-esr
Version: 115.9.1esr-1~deb12u1
Severity: normal
File: /usr/bin/firefox
X-Debbugs-Cc: antti.pekka.kansala@iki.fi

Dear Maintainer, please consider

https://lists.debian.org/debian-user/2024/03/msg00721.html

I am worried Gmail in a Firefox tab is able to break out of Firefox
somehow, gaining unauthorized access to 128 files on a mounted USB stick.

The desired behavior is that stick can be unmounted cleanly right after
a single attached file is uploaded in Gmail.  (In my test case an
encrypted binary of no importance to the issue.)

Clinging problem persists with full Debian reinstalls of recent stable
minor versions.


-- Package-specific info:


-- Addons package information

-- System Information:
Debian Release: 12.5
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 6.1.0-18-amd64 (SMP w/4 CPU threads; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages firefox-esr depends on:
ii  debianutils          5.7-0.5~deb12u1
ii  fontconfig           2.14.1-4
ii  libasound2           1.2.8-1+b1
ii  libatk1.0-0          2.46.0-5
ii  libc6                2.36-9+deb12u4
ii  libcairo-gobject2    1.16.0-7
ii  libcairo2            1.16.0-7
ii  libdbus-1-3          1.14.10-1~deb12u1
ii  libdbus-glib-1-2     0.112-3
ii  libevent-2.1-7       2.1.12-stable-8
ii  libffi8              3.4.4-1
ii  libfontconfig1       2.14.1-4
ii  libfreetype6         2.12.1+dfsg-5
ii  libgcc-s1            12.2.0-14
ii  libgdk-pixbuf-2.0-0  2.42.10+dfsg-1+b1
ii  libglib2.0-0         2.74.6-2
ii  libgtk-3-0           3.24.38-2~deb12u1
ii  libnspr4             2:4.35-1
ii  libnss3              2:3.87.1-1
ii  libpango-1.0-0       1.50.12+ds-1
ii  libstdc++6           12.2.0-14
ii  libvpx7              1.12.0-1+deb12u2
ii  libx11-6             2:1.8.4-2+deb12u2
ii  libx11-xcb1          2:1.8.4-2+deb12u2
ii  libxcb-shm0          1.15-1
ii  libxcb1              1.15-1
ii  libxcomposite1       1:0.4.5-1
ii  libxdamage1          1:1.1.6-1
ii  libxext6             2:1.3.4-1+b1
ii  libxfixes3           1:6.0.0-2
ii  libxrandr2           2:1.5.2-2+b1
ii  libxtst6             2:1.2.3-1.1
ii  procps               2:4.0.2-3
ii  zlib1g               1:1.2.13.dfsg-1

Versions of packages firefox-esr recommends:
ii  libavcodec59  7:5.1.4-0+deb12u1

Versions of packages firefox-esr suggests:
pn  fonts-lmodern          <none>
pn  fonts-stix | otf-stix  <none>
ii  libcanberra0           0.30-10
ii  libgssapi-krb5-2       1.20.1-2+deb12u1
ii  pulseaudio             16.1+dfsg1-2+b1

-- no debconf information

[toc] | [next] | [standalone]


#1192508 — Bug#1068122: My thoughts on the possible problem

FromAntti-Pekka Känsälä <antti.pekka.kansala@gmail.com>
Date2024-03-31 17:30 +0200
SubjectBug#1068122: My thoughts on the possible problem
Message-ID<Io5i9-3397-5@gated-at.bofh.it>
In reply to#1192484

[Multipart message — attachments visible in raw view] — view raw

Sorry for the amount of text that follows:

MY MONOLOGUE ON FACEBOOK 30.-31.3.2024

Antti-Pekka Känsälä
antti.pekka.kansala@iki.fi

If it's not in Debian, but it's because of my activity, I'm somewhat
out of ideas.

Out of ideas concerning my own data security.

In that case, I better move on, and focus on something else.

(The problem has persisted for some time. I have quietly assumed
my machine has been breached, by legal (not to say legitimate) means
(in short, I've been under the "official eye"), that the Debian
project has been forced to comply to, or by means that are beyond
software. Thus my helplessness continues.)

Frequent reinstallations of the system clearly won't help, I have
tried that.

Is it possible, that I have bogus installation media, and
cryptographical verification fails in my case?

Just my thoughts.

I think this is the second time I'm in this kind of despair with
Debian. However, I know of no other way to use a computer,
that would come even close in quality for my needs. Thanks.

The GNU/Linux Debian distribution of Linux is the basis for most
other distributions. It affects the entire digital world, that
it works correctly. Their security team I believe includes the best.
I think they have a public disclosure policy, once they discover
a problem. If there is a problem here, I may never even find out
where it was, but it will be fixed, by the best.

You should use Debian too.

The USB stick problem is not the only symptom. The other is
complete lockups, that may well be just because of old hardware.
However, if the system is breached, the lockups could be intentional.
The problem could be somewhere completely elsewhere from USB sticks,
it's just that someone's playing interested in my sticks on
a breached system.

Haha... So it's ok, if it's just the corrupted officials monitoring
me, so long as the problem is not in Debian, God forbid!

It's quite the system. No systems limps on quite as well, even when
completely breached...

Things sure happen fast, when a computer most likely is breached.
Nearly all of the attack tools targeted at my machine must be fully
automated.

Not much use being even the best sysadmin on a breached machine,
it's people elsewhere who investigate.

Why would Gmail running in Firefox be interested in 128 files
on my USB stick, in addition to the 1 that I have just uploaded
as an e-mail attachment? Good question.

Because they are not, but running Gmail in Firefox reveals
something about how the system is compromised.

There was news just today, I think, of a major backdoor problem,
that was discovered. They suspect it was definitely by a
governmental level actor. What is happening on my machine could
be a consequence of the backdoor problem, but I'm just one
of the God knows how many affected, and my case may or may not
be relevant at all to figuring out what else has become corrupted.

What is worrisome however, is that this seems to be happening
on several versions of recently, freshly-reinstalled Debian
stable. I saw someone writing that "no version of Debian stable
is known to be affected", but this could change.

I got some very professional help, quickly, from the debian-user
mailing list. Being worried about USB stick security must be
well-known. I have been aware of the "lsof" command before,
to display open files, and I think I may have even tried it to
investigate this problem, but have given up, for the reason
that there's not really anything I can do if my activity
is just being "legally" monitored by officials.

I'm really annoyed by what I gather, that the Debian project
is legally obliged to allow such official monitoring. On the
other hand, the situation is no different from phones, which
the police (at least) can tap.

My understanding is, that Debian is close to a system, that
not even the authorities would be able to monitor, were it not
for their "legal" intervention in the system's development.

I do feel a bit digitally raped here.

With Windows it would be constantly in bed with Bill Gates?

With Apple... Well.

You hear of Windows computers getting slow with age? Well,
I got alarmed when on Linux an action started to take
two seconds on this old machine!

You just kind of have to settle with something, that you assume
is a noticeable tap on your system, from month to month,
by the officials, legally?

The backdoor I mentioned has been fixed now, and possibly
did not affect my suspected problem. I have some ideas though,
why Gmail "might" be interested in USB sticks... Enough so
to break out of Firefox?

In that case, what I'm experiencing could just be a minor
problem. Maybe just in Firefox, but is it really being
exploited by our honest friend Google?!

I have nowhere near complete evidence, under which conditions
can the system try to steal files off my USB sticks.

I just know I can't use USB sticks securely here.

To some people, that might sound surprising, if you read what
they say about malware, etc., and warn about unknown sticks.
But with GNU/Linux Debian there have actually been standards
of security, you could actually hope that USB sticks would
work for their intended purpose!

If Firefox has a hole, it's going to somewhat limit my
browsing experience. Maybe as workaround, I will try switching
to another browser at some point. Firefox just happens to ship
as the default.

A fancy file chooser dialogue, that stays around analyzing
the directory is now suspected. But it could be that someone
is interested in what kind of binaries people try to e-mail
to somewhere from their USB sticks (!)

(The backdoor discovery I mentioned yesterday is a nice example,
of how things work in the open source community. The problem
was admitted, discussed openly, and fixed the same day.
Regarding Debian, it only affected developmental versions,
not the stable distribution I'm using. I read some SSH tools
were compromised, if they had been used by early-adopter
developers throughout the world, a huge number of systems
could still be corrupted all around the world. Even though
the root of the problem was fixed in less than a day,
after it was brilliantly discovered by noting that a particular
infected program ran a bit slower, that it should have!)

If you got interested in my suspected problem, the technical
discussion is here:
https://lists.debian.org/debian-user/2024/03/msg00721.html
LISTS.DEBIAN.ORG
Debian 12.5 up-to-date Xfce, Firefox clings to USB stick

I'm not sure if I should even bother reporting this to Mozilla,
since their page hardly even has a simple feature to report problems!

To contribute to data security responsibly, I think I am going
to need to push this all the way through, until I get an answer,
or see the problem fixed.

The problem could be local to Debian, so I think I'll "stick"
to that for now.

I just used the Debian "reportbug" tool for the first time
in my life, on the package "firefox-esr".

It would be a way to begin contributing, to report *everything*
I notice.

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068122
BUGS.DEBIAN.ORG
bugs.debian.org
bugs.debian.org

Who knows, I may have "hit jackpot"!

Now that I think of it, I'm no longer sure how I mounted the stick
in the first place. Did I double click the icon, opening a window
manager window, that promptly began analyzing the directory
in the background? Is it just that? Previews of files were still
being computed when I was already done with Gmail, and tried to unmount?

No... I think this is related to someone being interested in
me apparently planning on using Gmail to send encrypted data.
They may have a right to be interested. But not by compromising
my Debian!

I don't always see this kind of behavior, with the same stick,
even if I quickly plug it in to retrieve a single file. I don't know
where the previews are stored, not on the stick, I think. I mean,
it took a minute or so, before unmounting cleanly, and 129 files on
the stick really were open by the browser.

If I copy a single file out of a stick, and it is done, then
the expected behavior is that the stick can be unmounted. If it's
a storage device, not an espionage device.

And, I've noticed manual mounting in the terminal, copying the file
to disk, then unmounting in the terminal (as root, I know) also does
"resolve" the clinging problem. What is supposed to be the problem
with using "su" in a terminal, nobody has bothered to explain to me?
Is my system compromised in some completely different way, because
of me using "su"?

I think "sudo" has finer grained control over subprocesses being
granted root privileges? If you assume programs are full of
undiscovered root exploits, then using "sudo" could be safer,
privileges would not escalate?

Well, starting from my next reinstall it will be "sudo" then.

Debian 12.5, hostname "renaissance". uname -a follows:

Linux renaissance 6.1.0-18-amd64 #1 SMP PREEMPT_DYNAMIC
Debian 6.1.76-1 (2024-02-01) x86_64 GNU/Linux

"su" is shorter than "sudo".

Maybe this monologue would all have belonged to one of the Debian
IRC channels.

I've had difficulty working with colleagues in computer science
since around who knows when.

I believe what I'm doing here is doing my share in "digital
forensics".

Obviously I cannot communicate securely with anybody using this
computer for now. I'll have to wait for an update to Debian,
and do a full reinstall again.

Time to start thinking of a good hostname, a pleasure.

[toc] | [prev] | [next] | [standalone]


#1193057

FromMax Nikulin <manikulin@gmail.com>
Date2024-04-06 09:52 +0200
Message-ID<Iq90p-4oGU-4467@gated-at.bofh.it>
In reply to#1192484
On Sun, 31 Mar 2024 12:51:52 +0300 Antti-Pekka Johannes Känsälä wrote:
> 
> https://lists.debian.org/debian-user/2024/03/msg00721.html

Notice that this thread is broken into many part. (Perhaps because gmail 
does not support In-Reply-To in mailto: links)

> I am worried Gmail in a Firefox tab is able to break out of Firefox
> somehow, gaining unauthorized access to 128 files on a mounted USB stick.

Output of the command to confirm the statement was not provided.

 From my point of view, something close to valid behavior was described.

- If a file from an external drive is chosen for <input type="file"> 
then it is reasonable to expect that it can be used later when a form is 
submitted or an e-mail with the attachment is sent. Users are free to 
select another file, so eagerly reading the file to memory is not always 
reasonable. As a result it may be impossible to unmount the drive 
immediately.
- File icons should appear in the file chooser and it may assume 
determining media types of these files.

So precise description of steps and observed effects is necessary to 
make this bug report convincing.

[toc] | [prev] | [next] | [standalone]


#1193200

FromMax Nikulin <manikulin@gmail.com>
Date2024-04-06 16:40 +0200
Message-ID<Iqfn3-4sJH-9@gated-at.bofh.it>
In reply to#1192484
On Mon, 1 Apr 2024 21:32:41 +0300 Antti-Pekka Känsälä wrote:
> Closing the Gmail tab will not help.

I rarely use gmail web UI. At least in the case of KDE, Firefox releases
file descriptor a few seconds after compose dialog is closed. It seems
even closing the tab is not necessary. It was a file on an internal
drive, but I do not think it matters.

> appe@renaissance:~$ lsof | grep -i KINGSTON
> x-www-bro 83803                             appe  128r      REG
>   8,33      3433       6939 /media/appe/KINGSTON/noname/file4.gpg
> x-www-bro 83803 83807 glean.dis             appe  128r      REG
>   8,33      3433       6939 /media/appe/KINGSTON/noname/file4.gpg
[...]

 From my point of view it is in contradiction with the original complain:

> I am worried Gmail in a Firefox tab is able to break out of Firefox
> somehow, gaining unauthorized access to 128 files on a mounted USB stick.

Isn't /media/appe/KINGSTON/noname/file4.gpg the file you attached? What 
are other 127 files?

[toc] | [prev] | [next] | [standalone]


#1193568

FromAntti-Pekka Känsälä <antti.pekka.kansala@gmail.com>
Date2024-04-09 13:40 +0200
Message-ID<IrhZv-56XO-5@gated-at.bofh.it>
In reply to#1192484

[Multipart message — attachments visible in raw view] — view raw

On Sat, 6 Apr 2024 21:26:25 +0700 Max Nikulin <manikulin@gmail.com> wrote:
> On Mon, 1 Apr 2024 21:32:41 +0300 Antti-Pekka Känsälä wrote:
> > Closing the Gmail tab will not help.
>
> I rarely use gmail web UI. At least in the case of KDE, Firefox releases
> file descriptor a few seconds after compose dialog is closed. It seems
> even closing the tab is not necessary. It was a file on an internal
> drive, but I do not think it matters.
>
> > appe@renaissance:~$ lsof | grep -i KINGSTON
> > x-www-bro 83803                             appe  128r      REG
> >   8,33      3433       6939 /media/appe/KINGSTON/noname/file4.gpg
> > x-www-bro 83803 83807 glean.dis             appe  128r      REG
> >   8,33      3433       6939 /media/appe/KINGSTON/noname/file4.gpg
> [...]
>
>  From my point of view it is in contradiction with the original complain:
>
> > I am worried Gmail in a Firefox tab is able to break out of Firefox
> > somehow, gaining unauthorized access to 128 files on a mounted USB
stick.
>
> Isn't /media/appe/KINGSTON/noname/file4.gpg the file you attached? What
> are other 127 files?

For my initial bug report, I just quickly did a "wc -l" on a long initial
printout, so I was mistaken to claim those were distinct files, I don't
know if they were.  But now I think it is strange that the same file should
be open so many times, it is wasteful at least and could lead to a cause
for the clinging.  In the dicussion in debian-user I think I said, that the
clinging once lasted for about a minute, after which the unmounting
completed. This probably led me to suspect that other files besides a less
than 4 kB file (an earlier "file3.gpg") could have been accessed.

If the problem is real, I think it should be easy to reproduce.  Maybe it
has to do with semi-legitimate virus scanning, or semi-legitimate concerns
some might have about encrypted messages, and my data security personally
is not at risk.  If the file was on an internal drive, you would be
unlikely to unmount it anyway.

I continue to worry about my USB stick security.  I have received advice,
and have plans to improve my data security (including switching to the
Chromium browser), but I still suspect that something is not right here.

Thanks.

[toc] | [prev] | [next] | [standalone]


#1193910

FromMax Nikulin <manikulin@gmail.com>
Date2024-04-12 18:50 +0200
Message-ID<Issga-5Ph8-9@gated-at.bofh.it>
In reply to#1193568
On Tue, 9 Apr 2024 14:34:36 +0300 Antti-Pekka Känsälä wrote:
> > > I am worried Gmail in a Firefox tab is able to break out of Firefox
> > > somehow, gaining unauthorized access to 128 files on a mounted USB
> stick.
> 
> For my initial bug report, I just quickly did a "wc -l" on a long initial
> printout, so I was mistaken to claim those were distinct files, I don't
> know if they were.  But now I think it is strange that the same file should
> be open so many times, it is wasteful at least and could lead to a cause
> for the clinging.

The file is opened once accordingly to the output you posted. It is how 
lsof reports usage in the case of multithread applications. Perhaps 
other ways to deal with files exist, but I am in doubts concerning real 
benefits for multithread applications related to privacy.

As to access to other files, you may try to figure out if Firefox uses 
file picker provided by desktop-portal. Behavior may be different for 
flatpak/snap and deb packages. I am unsure if XFCE uses some 
desktop-portal implementation. This feature is intended to control what 
files an application may access, however in the case of deb package 
there is no barriers.

> Maybe it has to do with semi-legitimate virus scanning,

You should know better if you have virus scanning software installed. 
 From my point of view, some file indexer should be more probable 
variant (however it should ignore removable devices at least by default).

> I continue to worry about my USB stick security.

You may find processes accessing specific files using autitd.

What actions do you expect from Debian maintainers? (I am not a maintainer.)

[toc] | [prev] | [next] | [standalone]


#1194546

FromAntti-Pekka Känsälä <antti.pekka.kansala@gmail.com>
Date2024-04-18 19:40 +0200
Message-ID<IuDTP-7bw1-5@gated-at.bofh.it>
In reply to#1192484

[Multipart message — attachments visible in raw view] — view raw

On Fri, 12 Apr 2024 23:45:02 +0700 Max Nikulin <manikulin@gmail.com> wrote:
> What actions do you expect from Debian maintainers? (I am not a
maintainer.)

I don't know much about Debian policies, so I don't expect anything
further. I've read that "Debian takes security very seriously". I consider
that I've done my best to report a possible problem, it's been taken
seriously, and I've received plenty of advice. Thank you for your time!

Best regards,
Antti-Pekka Känsälä

[toc] | [prev] | [next] | [standalone]


#1196656

FromMax Nikulin <manikulin@gmail.com>
Date2024-05-06 18:40 +0200
Message-ID<IB9xD-bwlG-1@gated-at.bofh.it>
In reply to#1194546
On Thu, 18 Apr 2024 20:31:45 +0300 Antti-Pekka Känsälä wrote:
> 
> so I don't expect anything further.

Please, consider closing this bug by sending response to
1068122-done@bugs.debian.org

Accordingly to https://www.debian.org/Bugs/Developer

> Normally, the only people that should close a bug report are the
> submitter of the bug and the maintainer(s) of the package against which
> the bug is filed.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web