Live data from Hacker News

‘I will show you how safe Telegram is’

twitter.com

11–20 of 206 posts

Re: ‘I will show you how safe Telegram is’

#11
post #5
post #2

So, the twitter post alludes to SS7, but it is not clear how it is (ab)used to do the Telegram-related exploitation. Presumably, SS7's design flaws are being used intercept Telegram's registration verification messages, placing the resulting Telegram accounts under control of the bad actors while appearing to be real, independent users (and so aiding in establishing their credibility, which leads to other things), bu…

Telegram allows logins per SMS code (they will be rolling out changes in two days). So as long as you knew the number of your victim and have the ability to re-route SMS, you were able to login to other people’s accounts. Of course this can be easily mitigated by setting a “cloud password”, but I guess most people don’t do that.

If this is true, then Signal should be subject to the same weakness no ?

Re: ‘I will show you how safe Telegram is’

#12
post #3

You can put a password on your telegram account.

.. can you reset that password? Using a text message?

Technically yes but it takes 1 more step.

afaik (maybe I'm wrong) you can only reset a Telegram cloud password with a recovery email address. And you can maybe access that email address through a SMS based recovery.

Having your Telegram account with a cloud password and the recovery email locked with a safe 2FA method "should be safe".

Re: ‘I will show you how safe Telegram is’

#14
post #11
post #5

Earlier quoted context omitted.

Telegram allows logins per SMS code (they will be rolling out changes in two days). So as long as you knew the number of your victim and have the ability to re-route SMS, you were able to login to other people’s accounts. Of course this can be easily mitigated by setting a “cloud password”, but I guess most people don’t do that.

If this is true, then Signal should be subject to the same weakness no ?

Nope.

First of all, everything's end-to-end encrypted and no chat logs are stored, so even if someone did do that they wouldn't have access to your chat history.

Second of all, if someone tries to impersonate you, your contact gets a notification that your encryption keys have changed, ideally making the recepient slightly more vigilant.

Finally, Signal has built-in (optional and not on by default) protection for these types of attacks which require a PIN after activating the number on a new device, making SIM swap attacks useless without PIN as the second factor: https://support.signal.org/hc/en-us/articles/360007059792-Si...

Re: ‘I will show you how safe Telegram is’

#15
post #3

You can put a password on your telegram account.

.. can you reset that password? Using a text message?

The other answer to your comment says that you can't, so it's possible the the feature is broken or something? But you can configure a recovery email, which is supposed to be used, if you forget your password. But I have not used it yet.

Re: ‘I will show you how safe Telegram is’

#16
post #11
post #5

Earlier quoted context omitted.

Telegram allows logins per SMS code (they will be rolling out changes in two days). So as long as you knew the number of your victim and have the ability to re-route SMS, you were able to login to other people’s accounts. Of course this can be easily mitigated by setting a “cloud password”, but I guess most people don’t do that.

If this is true, then Signal should be subject to the same weakness no ?

Yes it is. It’s worse for Telegram though because it gives the attacker access to the chat history too. Telegram does however send a message to all devices when a new device is logging in, so at least you would know. Signal does not do that but your contacts will get a message that your security code changed if they have the option for that enabled, but people generally ignore this message.

Both services offer to set an additional pin or password to protect your account.

Re: ‘I will show you how safe Telegram is’

#17
post #11

Earlier quoted context omitted.

If this is true, then Signal should be subject to the same weakness no ?

Nope. First of all, everything's end-to-end encrypted and no chat logs are stored, so even if someone did do that they wouldn't have access to your chat history. Second of all, if someone tries to impersonate you, your contact gets a notification that your encryption keys have changed, ideally making the recepient slightly more vigilant. Finally, Signal has built-in (optional and not on by default) protection for the…

Indeed, you're right: the worst that can happen is that chat recipients would see a "your security number has changed". But nothing will happen when talking to a whole new person, or when you join a group you've never been in before.

Re: ‘I will show you how safe Telegram is’

#18
post #11

Earlier quoted context omitted.

If this is true, then Signal should be subject to the same weakness no ?

Nope. First of all, everything's end-to-end encrypted and no chat logs are stored, so even if someone did do that they wouldn't have access to your chat history. Second of all, if someone tries to impersonate you, your contact gets a notification that your encryption keys have changed, ideally making the recepient slightly more vigilant. Finally, Signal has built-in (optional and not on by default) protection for the…

In Telegram the first is available opt-in, an equivalent to the second is available opt-in (key change = shows up as a different chat), and the third is equally true.

Re: ‘I will show you how safe Telegram is’

#19
post #11

Earlier quoted context omitted.

If this is true, then Signal should be subject to the same weakness no ?

Nope. First of all, everything's end-to-end encrypted and no chat logs are stored, so even if someone did do that they wouldn't have access to your chat history. Second of all, if someone tries to impersonate you, your contact gets a notification that your encryption keys have changed, ideally making the recepient slightly more vigilant. Finally, Signal has built-in (optional and not on by default) protection for the…

Cool. But are they still closed-source?

Re: ‘I will show you how safe Telegram is’

#20

Isn't this a weakness in all SMS based verification? If you can reroute SMS auth codes, it's game over. It's too bad that most 2FA rely on this method (or use it as a fallback). I don't see how it is directly related to telegram, though.

The only thing worse than SMS-2FA is SMS-1FA, which I believe is Telegram‘s default.
Post reply on HN