Project ideas from Hacker News discussions.

Telegram Desktop vulnerability allowed any user's file to be stolen

📝 Discussion Summary (Click to expand)

Theme 1 – Telegram’s design is seen as inherently insecure / backdoor‑like
- erelong: “I thought telegram was flagged as insecure like a decade ago, it's never really been 'very secure'”
- maqp: “The main spy feature that is Telegram collecting 100% of content and metadata is the main feature for every intelligence agency …”

Theme 2 – The flaw is rooted in broad OS file‑access; sandboxing is the remedy
- Panzerschrek: “It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file.”
- saagarjha: “Telegram is available sandboxed from the Mac App Store on macOS.”
- zorked: “It is also sandboxed in Flatpak.”

Theme 3 – Users accept the risk for UX, trust, or political reasons
- misiek08: “Still we are using it, because UX kills any other app and people that are (probably) behind it will cause almost no harm to casual, not‑interesting people :)”
- lifeisloving: “I dont write off software because where the person that made it was born.”
- maqp: “The little I have to run Telegram Desktop for, I run in a VM. I'd never let the little oligarch's code touch my desktop OS.”


🚀 Project Ideas

Generating project ideas…

Telegram Desktop Sandbox Wrapper

Summary

  • A lightweight launcher that runs Telegram Desktop inside a strict OS‑level sandbox (Firejail/bubblewrap on Linux, sandbox‑exec on macOS, Job Object restrictions on Windows) limiting file system access to only the Telegram configuration folder and a designated “Downloads” directory, thereby preventing the internal tg:// upload trick from exfiltrating arbitrary user files.
  • Core value proposition: eliminates the file‑exfiltration vector while preserving the full Telegram Desktop UX, requiring no changes to the official client.

Details

Key Value
Target Audience Privacy‑conscious Telegram Desktop users on Linux, macOS, and Windows who want sandboxing without switching to mobile or web clients
Core Feature Automatic confinement of Telegram Desktop to a whitelisted file‑system profile; optional disabling of custom URL handlers
Tech Stack Firejail / bubblewrap (Linux), sandbox‑exec (macOS), Windows Job Objects + MinFilter driver (Windows); Go or Rust for launcher logic; optional GUI built with Electron or Tauri
Difficulty Medium
Monetization Hobby

Notes

  • HN commenters praised sandboxing approaches: “I run Firefox in a firejail sandbox…” (usr1106) and “Telegram is available sandboxed from the Mac App Store…” (saagarjha); this tool brings the same protection to the official desktop build.
  • Provides a practical, immediate mitigation for the disclosed vulnerability while discussion continues on Telegram’s long‑term fixes.

SecureMessenger SDK

Summary

  • A cross‑platform software development kit for building messenger apps that enforces a strict permission model: username‑based identity (no phone number), end‑to‑end encryption by default, file transfers routed through encrypted, app‑isolated storage, and disabling of dangerous internal URL schemes.
  • Core value proposition: gives developers a ready‑made, privacy‑first foundation that avoids the pitfalls highlighted in the Telegram discussion (phone‑number linkage, over‑privileged file access, weak E2EE defaults).

Details

Key Value
Target Audience Indie developers, startups, and open‑source projects seeking to create secure chat applications without reinventing crypto and sandboxing
Core Feature Library providing E2EE (Signal Protocol), username‑based account management, file‑transfer API that writes only to an app‑private sandbox, and URL‑scheme sanitization
Tech Stack libsignal‑protocol‑c (core crypto), SQLite Encrypted Extension for local storage, Qt/QML or Flutter for UI, SELinux/AppArmor profiles generated at build time
Difficulty High
Monetization Revenue‑ready: SaaS hosting tier ($9/mo per app) + optional enterprise support contracts

Notes

  • Commenters lamented Telegram’s lack of E2EE by default (“it’s almost embarrassing in 2026”) and phone‑number reliance (“last I checked… it's laughable to consider a service tied to a phone number secure”); the SDK directly addresses these concerns.
  • Enables rapid creation of alternatives that could capture users migrating from insecure platforms, sparking fresh discussion on HN about usable, secure messaging.

FileAccess Monitor & Blocker (FAMB)

Summary

  • A desktop agent that uses kernel‑level observability (eBPF on Linux, Endpoint Security framework on macOS, MiniFilter driver on Windows) to monitor file read/write attempts by any process and automatically block or alert when access occurs outside a user‑defined allow‑list (e.g., only the app’s own data directory and a designated “Downloads” folder).
  • Core value proposition: provides a generic, OS‑level defense against the class of vulnerabilities demonstrated by Telegram’s internal URL scheme, protecting all applications without requiring per‑app patches.

Details

Key Value
Target Audience Security‑savvy power users, sysadmins, and organizations wanting to harden endpoint devices against data‑exfiltration malware or overly permissive apps
Core Feature Real‑time file‑access policing with configurable whitelists/blacklists, process‑level alerts, and optional quarantine or termination of offending processes
Tech Stack eBPF (Linux via libbpf), Apple Endpoint Security (macOS), Windows MinFilter driver; management daemon in Rust or Go; optional Electron tray UI for configuration
Difficulty High
Monetization Hobby (open‑source) – can later offer paid enterprise dashboard for centralized policy management

Notes

  • HN discussion highlighted that “the vulnerability is… a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file” (Panzerschrek); FAMB gives users a way to enforce stricter isolation regardless of app intent.
  • Quotes like “I run Firefox in a firejail sandbox…” (usr1106) show appetite for such system‑wide controls; FAMB extends that idea beyond a single app.

Read Later