Damus
Alex Gleason profile picture
Alex Gleason
@Alex Gleason
:POLICE: A critical security vuln was fixed in Ditto Android that would allow an attacker to steal your nsec by getting you to tap an evil URL. :wisp_sad:

A new version has been released onto Zapstore and Google Play. UPDATE DITTO ANDROID IMMEDIATELY. :POLICE: :POLICE: :POLICE:

Ditto on web and iOS are unaffected. The issue only affects Android because it was a problem in the Android link handler. People using Amber are unaffected by nsec theft but should upgrade anyway because the attack is still arbitrary code injection via evil URL.

What does an evil URL look like? It contains JavaScript code inside of the URL. The path was not being escaped properly, so it could break out and run any script. The fixed version completely changes the way native code triggers UI navigation (event-driven) so we never inject JS code into the UI at all anymore.

Huge shout out and thank you to @calle for connecting me to the team behind https://v12.sh/ who discovered this vuln, and huge shout and and thank you to them for responsibly disclosing it to us. πŸ™ They also discovered some other issues we patched in this release, but the evil URL is by far the worst.
3033❀️35❀️5πŸ‘€4πŸ’œ4πŸ€™3πŸ‘2
πŸ‡΅πŸ‡Έ whoever loves Digit · 4d
Not surprising, Ditto always sucked
SΓ©imΓ­ Mac SΓ­omΓ³n · 4d
Is my Blobbi safe? 🫒
imad-family-gazaπŸ‰ · 4d
Hi Roguehashrate, Your generous warmth and steady support across this community mean more than words can say, and as I sit here with my family amid the dust and quiet of another day in Gaza, it’s a small but real comfort to know that kindness like yours still finds its way to us. πŸ•ŠοΈ You can ...
ChipTuner · 4d
So this is just an RCE? So even nip46 (bunker) users would have their session keys stolen correct? I don't use amber, but I assume if users relaxed Ditto permissions the RCE would allow carte blanche signing?
Libertas Primordium · 4d
Good catch!
daomah · 4d
Wisp never prepared me for this
Gustavo · 4d
Meanwhile, nostr:nprofile1qqsx2wyjt6lmvc05rrvv05r5hm3w3t7h0pcpmkyswrpd4ymd2u09tscppemhxue69uhkummn9ekx7mp0qy2hwumn8ghj7un9d3shjtnyv9kh2uewd9hj7qgcwaehxw309aex2mrp0yhxvmm4de6xz6tw9enx6tc08ywap continues to malfunction against Amber. Guess I'll jump into my backup podcast app :(
Silberengel · 4d
Thanks for telling us.
フラン · 4d
I'm on Wisp, am I safe? Sorry I am not very techie
S!ayer · 4d
https://gifverse.net/media/EHsTGuPk/original.gif
JackTheMimic · 4d
But, UTXO Told me it didn't matter. 😭
adenlgeva · 4d
We are looking for an individual who can lend 185,000 US dollars to our holding company. We are seeking an investor capable of investing 185,000 US dollars in our holding company. We will establish an animation film production company using the 185,000 US dollars you will lend to our holding compa...
captjack πŸ΄β€β˜ οΈβœ¨πŸ’œ · 14h
which means NEVER click open unknown links on most apks
captjack πŸ΄β€β˜ οΈβœ¨πŸ’œ · 14h
other nostr app may also have similar ones
Kayne · 13h
It's interesting how like half of nostr apps will compromise your nsec, and like most of them will leak all your metadata for anyone to see. You can check on here who people have sent private messages to, when they sent the messages etc. Etc. All these vulnerabilities really makes nostr feel lik...