Live data from Hacker News

Hackers accessed Telegram messaging accounts in Iran – researchers

reuters.com

31–40 of 66 posts

Re: Hackers accessed Telegram messaging accounts in Iran – researchers

#31

Earlier quoted context omitted.

If Telegram relies on SMS for its authentication system, wouldn't the SMS network be part of its infrastructure, if indirectly?

Facebook relies on SMS. Whatsapp relies on SMS. VK relies on SMS. Viber relis on SMS. Are we going to say that all of those have been breached too?

Threema does not rely on SMS for login, the identities are not phone number based and trust can be ensured by manually scanning the public key QR of the peer, leading to a clear visual trust level indicator.

Applications should not rely on SMS for authentication or login, or on the phone number for identity.

(Disclaimer: Threema dev)

Re: Hackers accessed Telegram messaging accounts in Iran – researchers

#32

Earlier quoted context omitted.

Potentially. Of course, you won't see it too often in the headlines..

I know that some people here are suspicious of Telegram because they use their own encryption mechanism, but it's like there's an active campaign against it by the media. In my country the media has been calling it the "ISIS chatting app".

IMO you're unjustifiably downvoted. As a previous reply already said, other services rely on sms auth as well. So why is only Telegram critizised? You can see from previous HN top stories that the mistrust in this service seems especially high.

Re: Hackers accessed Telegram messaging accounts in Iran – researchers

#33

Earlier quoted context omitted.

Potentially. Of course, you won't see it too often in the headlines..

I know that some people here are suspicious of Telegram because they use their own encryption mechanism, but it's like there's an active campaign against it by the media. In my country the media has been calling it the "ISIS chatting app".

It's just media doing the thing it always does. Inducing outrage in any way possible. It's too late to call Facebook Messenger an "ISIS chatting app", but consider that e.g. whenever Facebook adds any kind of even remotely useful feature to their service, they're immediately portrayed as stalker paradise by the media.

Re: Hackers accessed Telegram messaging accounts in Iran – researchers

#34

Earlier quoted context omitted.

If Telegram relies on SMS for its authentication system, wouldn't the SMS network be part of its infrastructure, if indirectly?

Facebook relies on SMS. Whatsapp relies on SMS. VK relies on SMS. Viber relis on SMS. Are we going to say that all of those have been breached too?

Signal notifies you on key changes. Whatsapp has an option (I think) to do so.

Anyways the simple fix that might work somewhat is "alert the user". Telegram could tell the old user they have added a device. Or even require some time period where they wait for a response from the existing device, perhaps calibrated to their usage.

After registering a new device, a warning can be displayed to contacts for the first few messages. Maybe old messages are not accessible or something.

There are ways to limit the impact of an SMS hijack.

Re: Hackers accessed Telegram messaging accounts in Iran – researchers

#36
post #2

Clickbait title. The correct title would be 'Exclusive: Hackers accessed Telegram messaging accounts in Iran - researchers' which itself already hides the fact that the problem lies not with Telegram infrastructure, but the interception of SMS by state telcos.

We changed the title from "Telegram breached" back to the title of the article.

Re: Hackers accessed Telegram messaging accounts in Iran – researchers

#37

Earlier quoted context omitted.

Facebook relies on SMS. Whatsapp relies on SMS. VK relies on SMS. Viber relis on SMS. Are we going to say that all of those have been breached too?

Signal notifies you on key changes. Whatsapp has an option (I think) to do so. Anyways the simple fix that might work somewhat is "alert the user". Telegram could tell the old user they have added a device. Or even require some time period where they wait for a response from the existing device, perhaps calibrated to their usage. After registering a new device, a warning can be displayed to contacts for the first few…

When you add a device, you do get notified a new device was added, and if you have an existing telegram device, all future devices won't use SMS as the authorisation channel. I think the problem here is that the attackers added a device before the "original" person did.

However, allowing for a reverse-lookup of a phone numbers through its API is a privacy—and security—problem Telegram is directly responsible for, IMHO.

Re: Hackers accessed Telegram messaging accounts in Iran – researchers

#38
post #35

Is there a way to know how many devices are linked to an account and which devices they are? That would let people check if they've been eavesdropped and possibly cut off the hacker by removing the extra device. Then add a password.

Yes. It's in the settings screen. You can remove any or all devices (bar the current one), too.

Re: Hackers accessed Telegram messaging accounts in Iran – researchers

#39
post #37

Earlier quoted context omitted.

Signal notifies you on key changes. Whatsapp has an option (I think) to do so. Anyways the simple fix that might work somewhat is "alert the user". Telegram could tell the old user they have added a device. Or even require some time period where they wait for a response from the existing device, perhaps calibrated to their usage. After registering a new device, a warning can be displayed to contacts for the first few…

When you add a device, you do get notified a new device was added, and if you have an existing telegram device, all future devices won't use SMS as the authorisation channel. I think the problem here is that the attackers added a device before the "original" person did. However, allowing for a reverse-lookup of a phone numbers through its API is a privacy—and security—problem Telegram is directly responsible for, IMH…

Yeah didn't Signal spend a bit of work trying to avoid exposing users?

If you have an existing Telegram device (registered before target registered), then how do they register? And wouldn't both devices get notified? Also how would they know which numbers to register?

Just fundamentally seems like the software can notify you of how many devices have access, and make that visible on any change and when installing on a device. Perhaps even offering to kill existing devices.

Post reply on HN