So, the twitter post alludes to SS7, but it is not clear how it is (ab)used to do the Telegram-related exploitation. Presumably, SS7's design flaws are being used intercept Telegram's registration verification messages, placing the resulting Telegram accounts under control of the bad actors while appearing to be real, independent users (and so aiding in establishing their credibility, which leads to other things), bu…
Telegram allows logins per SMS code (they will be rolling out changes in two days). So as long as you knew the number of your victim and have the ability to re-route SMS, you were able to login to other people’s accounts. Of course this can be easily mitigated by setting a “cloud password”, but I guess most people don’t do that.
‘I will show you how safe Telegram is’
11–20 of 206 posts
Re: ‘I will show you how safe Telegram is’
#12You can put a password on your telegram account.
.. can you reset that password? Using a text message?
afaik (maybe I'm wrong) you can only reset a Telegram cloud password with a recovery email address. And you can maybe access that email address through a SMS based recovery.
Having your Telegram account with a cloud password and the recovery email locked with a safe 2FA method "should be safe".
Re: ‘I will show you how safe Telegram is’
#13If you can reroute SMS auth codes, it's game over.
It's too bad that most 2FA rely on this method (or use it as a fallback).
I don't see how it is directly related to telegram, though.
Re: ‘I will show you how safe Telegram is’
#14Earlier quoted context omitted.
Telegram allows logins per SMS code (they will be rolling out changes in two days). So as long as you knew the number of your victim and have the ability to re-route SMS, you were able to login to other people’s accounts. Of course this can be easily mitigated by setting a “cloud password”, but I guess most people don’t do that.
If this is true, then Signal should be subject to the same weakness no ?
First of all, everything's end-to-end encrypted and no chat logs are stored, so even if someone did do that they wouldn't have access to your chat history.
Second of all, if someone tries to impersonate you, your contact gets a notification that your encryption keys have changed, ideally making the recepient slightly more vigilant.
Finally, Signal has built-in (optional and not on by default) protection for these types of attacks which require a PIN after activating the number on a new device, making SIM swap attacks useless without PIN as the second factor: https://support.signal.org/hc/en-us/articles/360007059792-Si...
Re: ‘I will show you how safe Telegram is’
#15You can put a password on your telegram account.
.. can you reset that password? Using a text message?
Re: ‘I will show you how safe Telegram is’
#16Earlier quoted context omitted.
Telegram allows logins per SMS code (they will be rolling out changes in two days). So as long as you knew the number of your victim and have the ability to re-route SMS, you were able to login to other people’s accounts. Of course this can be easily mitigated by setting a “cloud password”, but I guess most people don’t do that.
If this is true, then Signal should be subject to the same weakness no ?
Both services offer to set an additional pin or password to protect your account.
Re: ‘I will show you how safe Telegram is’
#17Earlier quoted context omitted.
If this is true, then Signal should be subject to the same weakness no ?
Nope. First of all, everything's end-to-end encrypted and no chat logs are stored, so even if someone did do that they wouldn't have access to your chat history. Second of all, if someone tries to impersonate you, your contact gets a notification that your encryption keys have changed, ideally making the recepient slightly more vigilant. Finally, Signal has built-in (optional and not on by default) protection for the…
Re: ‘I will show you how safe Telegram is’
#18Earlier quoted context omitted.
If this is true, then Signal should be subject to the same weakness no ?
Nope. First of all, everything's end-to-end encrypted and no chat logs are stored, so even if someone did do that they wouldn't have access to your chat history. Second of all, if someone tries to impersonate you, your contact gets a notification that your encryption keys have changed, ideally making the recepient slightly more vigilant. Finally, Signal has built-in (optional and not on by default) protection for the…
Re: ‘I will show you how safe Telegram is’
#19Earlier quoted context omitted.
If this is true, then Signal should be subject to the same weakness no ?
Nope. First of all, everything's end-to-end encrypted and no chat logs are stored, so even if someone did do that they wouldn't have access to your chat history. Second of all, if someone tries to impersonate you, your contact gets a notification that your encryption keys have changed, ideally making the recepient slightly more vigilant. Finally, Signal has built-in (optional and not on by default) protection for the…
Re: ‘I will show you how safe Telegram is’
#20Isn't this a weakness in all SMS based verification? If you can reroute SMS auth codes, it's game over. It's too bad that most 2FA rely on this method (or use it as a fallback). I don't see how it is directly related to telegram, though.