It’s whonix workstation based qube. Cinny flatpak app and matrix server. Previously I registered other account on other server in the same Cinny flatpak app and there was no pop up window. Now when I almost completed registration pressing register button there appeared a pop up window asking account access for some localhost44548. Too bad I had no time and just pressed “continue” and completed registration. It asked profile and contacts info access, messages access and permission to send messages on my behalf.
This Cinny app is flatpak that I just installed in qube, using flatpak install --user flathub in cinny.Cinny after adding flatpak repos in user directory. Also I use Flatseal and removed some permissions for Cinny (don’t remember which ones).
Maybe this is related to Qubes filesystem. Maybe to Flatseal removed permissions. Maybe to user directory installation. I tried to find out if this is normal for matrix account registration but there is nothing about localhost asking some permissions. Literally nothing. Now I have doubts whether I have been hacked. I can easily assume that this was some kind of social engineering hacking designed for matrix noobs like me.
But I installed Cinny and Flatseal from official flathub repos and never visited any suspicious sites in that qube’s Tor Browser. Just whoer and browserleaks sites and maybe flathub.org
Update: I have another guess! I have also Schildi Chat flatpak installed on the same qube. Maybe this way it tries to intercept matrix session?
