Live data from Hacker News

Introducing Telegram Passport

telegram.org

11–20 of 85 posts

Re: Introducing Telegram Passport

#11
post #3

Would Telegram and others please stop using phone number as a primary source of identity? It's 2018, I have a data only sim and I have no desire to have a phone number.

Agreed that such services should stop using phone numbers. In the meantime, you can get inexpensive numbers from https://jmp.chat/ - useful for 2FA as well.

Re: Introducing Telegram Passport

#12
Wonder if this was influenced in part by the fact that Telegram is the messaging service used by most ICO organizers. Could help in the KYC process that is becoming more commonplace.

Re: Introducing Telegram Passport

#13
post #11
post #3

Would Telegram and others please stop using phone number as a primary source of identity? It's 2018, I have a data only sim and I have no desire to have a phone number.

Agreed that such services should stop using phone numbers. In the meantime, you can get inexpensive numbers from https://jmp.chat/ - useful for 2FA as well.

Yeah I use Google Voice for this purpose, which isn't _really_ 2fa anyway (because it's my google account).

Re: Introducing Telegram Passport

#14
If this is to deliver your ID for the purposes of KYC laws, then that’s somewhat sensible, I suppose.

If, however, this is targeted at the providers who are actually collecting IDs as part of their AML compliance strategy, then there’s a much simpler solution here: just become the ID equivalent of a Certificate Authority. Dedup Telegram accounts by using a unique constraint on accounts’ validated ID documents’ extracted creds; and then allow sites to use Telegram for Single Sign-On. Boom—instant surety that each of your users is a real person, and not fifty bots laundering one person’s money; and no need for anyone besides Telegram to actually see your ID (i.e. a much lower chance of identity theft.)

Plus, if enough sites require SSO through an ID-document verifying identity provider, then even sites that ha d no legal reason to require it can free-ride off the benefit in user-deduplication it provides. Imagine, for example, a Reddit or a 4chan where users are still pseudonymous or anonymous, but where banning a user truly works, permanently, with no routing around it (unless you have the criminal connections required to buy yourself a new real-world identity.)

Re: Introducing Telegram Passport

#15
post #10
post #6

Telegram has a history of including fairly obvious backdoors in their products https://habr.com/post/206900/ Why should anyone trust them for identification or for storing sensitive documents? (And no, that DH behavior cannot be explained away as a simple mistake)

I feel that your post is being a bit dishonest, as it ends with the following: > UPD: The story ended well. Vulnerability is corrected, documentation and applications are updated, treasure hunters of bugs are motivated, which has already yielded results (1, 2). It is necessary to pay tribute to the developers of Telegram, who immediately reacted to the article. It's hard to say that it's not a mistake when the author…

> It's hard to say that it's not a mistake when the author of the article itself describes their response as "immediate".

It is an obvious backdoor.

They justified XORing in arbitrarily string into the key you have established with DH with the fact that your phone may have bad random number generator. But it obviously gains you nothing. If the server is honest, then it does not read your secret chat anyway. And if the server is malicious or compromised, it knows the string.

So even if it is possible to overlook the possibility of XORing in the difference of keys and evading MITM detection, it is very unlikely that no developer (for example, someone who coded it into the server or one of the clients) have seen that it gains you nothing in any scenario you can think about.

When users started to asking developers for the explanation in the comments, W_K (main developer of the protocol, brother of Pavel Durov) stated that they "don't know" who added this feature in its current form. Shortly after, he stopped using his account or answering any questions at all: https://habr.com/users/W_K/

Upd: regarding the remark in the end of the https://habr.com/post/206900/ that "the story ended well", Telegram team is responsive etc.

Keep in mind that they paid this guy. Adding such updates to articles and publicly confirming that the bug was fixed is almost surely a part of the bug bounty agreement.

Re: Introducing Telegram Passport

#16
post #3

Would Telegram and others please stop using phone number as a primary source of identity? It's 2018, I have a data only sim and I have no desire to have a phone number.

I cannot up-vote this more.

Many people don't realise that they don't own their phone number! It is possible to own a phone number but it is not widely available just like domains are. Hence it is a stupid idea to use it as an identity.

Re: Introducing Telegram Passport

#17
post #16
post #3

Would Telegram and others please stop using phone number as a primary source of identity? It's 2018, I have a data only sim and I have no desire to have a phone number.

I cannot up-vote this more. Many people don't realise that they don't own their phone number! It is possible to own a phone number but it is not widely available just like domains are. Hence it is a stupid idea to use it as an identity.

I recently learned this the hard way. I changed my phone number after moving cities, and AT&T just leased my old number to someone else!

Re: Introducing Telegram Passport

#18
I can't help not to trust telegram with my data, just gut feeling. You cannot use their service without giving your telephone nr. Now they like to have your ID's too. How can they honestly advertise "anonymus chat"? And the double ICO, over a billion fetched. So much money and data, where does that lead to?

Re: Introducing Telegram Passport

#19
post #16
post #3

Would Telegram and others please stop using phone number as a primary source of identity? It's 2018, I have a data only sim and I have no desire to have a phone number.

I cannot up-vote this more. Many people don't realise that they don't own their phone number! It is possible to own a phone number but it is not widely available just like domains are. Hence it is a stupid idea to use it as an identity.

With a self-sovereign identity, you are in control. Our IETF draft + running code: https://tools.ietf.org/html/draft-pouwelse-trustchain-01#sec... Our goverment even sponsors this work. Decentral, no need for Russian servers.

Re: Introducing Telegram Passport

#20
post #3

Would Telegram and others please stop using phone number as a primary source of identity? It's 2018, I have a data only sim and I have no desire to have a phone number.

You are forgetting social graph embedded in phone book.

No one else would give you social graph that easily.

Post reply on HN