Live data from Hacker News

Hackers accessed Telegram messaging accounts in Iran – researchers

reuters.com

11–20 of 66 posts

Re: Hackers accessed Telegram messaging accounts in Iran – researchers

#12
post #11
post #8

two step verification would be guard of this Achilles' heel

You mean Two Factor yeah? Because telegram already relies on two step.

SMS is the first factor in the case of Telegram. The 2-step authentication Telegram provides is through email.

Re: Hackers accessed Telegram messaging accounts in Iran – researchers

#13

> widely used in the Middle East, including by the Islamic State militant group I understand the risk associated with rogue people using such a service, but is not the ability to determine who exactly is using the service counter productive? I.e. for journalists and personas non grata under oppressive regimes.

Are you sure it's being "determined", in a SIGINT sense? Perhaps ISIS have made public mention somewhere of their usage of the service. Or perhaps others (e.g. opposing forces) have just shoulder-surfed some ISIS members using it, or looked through their phones.

Re: Hackers accessed Telegram messaging accounts in Iran – researchers

#14
post #2

Clickbait title. The correct title would be 'Exclusive: Hackers accessed Telegram messaging accounts in Iran - researchers' which itself already hides the fact that the problem lies not with Telegram infrastructure, but the interception of SMS by state telcos.

If Telegram relies on SMS for its authentication system, wouldn't the SMS network be part of its infrastructure, if indirectly?

Re: Hackers accessed Telegram messaging accounts in Iran – researchers

#15
One might suppose that because login relies on the cellular network it's implicitly part of the app's infrastructure. In that sense the technical failing of Telegram was relying on one method of authentication (when multi-factor should be the default). I think it far-fetched to extrapolate that into 'Telegram got hacked', though.

I understand the want to share the article, but a concerted effort to amend the original title to reflect the actual content would have been appropriate here, methinks.

Edit: fixed some speling.

Re: Hackers accessed Telegram messaging accounts in Iran – researchers

#16
post #3

Authentication via SMS considered harmful.

Well, a lot of MFA is done through SMS. I believe sides like Tumblr and Twitter do that? At least I am asked to do SMS authentication for those sites. Maybe it's a setting I checked off.

Re: Hackers accessed Telegram messaging accounts in Iran – researchers

#18
post #16
post #3

Authentication via SMS considered harmful.

Well, a lot of MFA is done through SMS. I believe sides like Tumblr and Twitter do that? At least I am asked to do SMS authentication for those sites. Maybe it's a setting I checked off.

NIST says SMS is not secure enough for 2FA

http://www.cnet.com/news/nist-set-to-ban-sms-based-two-facto...

Re: Hackers accessed Telegram messaging accounts in Iran – researchers

#19
post #2

Clickbait title. The correct title would be 'Exclusive: Hackers accessed Telegram messaging accounts in Iran - researchers' which itself already hides the fact that the problem lies not with Telegram infrastructure, but the interception of SMS by state telcos.

If Telegram relies on SMS for its authentication system, wouldn't the SMS network be part of its infrastructure, if indirectly?

Facebook relies on SMS. Whatsapp relies on SMS. VK relies on SMS. Viber relis on SMS.

Are we going to say that all of those have been breached too?

Re: Hackers accessed Telegram messaging accounts in Iran – researchers

#20

Earlier quoted context omitted.

If Telegram relies on SMS for its authentication system, wouldn't the SMS network be part of its infrastructure, if indirectly?

Facebook relies on SMS. Whatsapp relies on SMS. VK relies on SMS. Viber relis on SMS. Are we going to say that all of those have been breached too?

Potentially.

Of course, you won't see it too often in the headlines..

Post reply on HN