Live data from Hacker News

‘I will show you how safe Telegram is’

twitter.com

31–40 of 206 posts

Re: ‘I will show you how safe Telegram is’

#31

I monitor Russian war channels and some people there insist on using Telegram only for Russian military people. If you use Whatsapp, Ukrainian officers will get all chats from NATO. Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. My takeaway is that for truly private chat one should write his own software using simple crypto without all those fancy clients. Ideally ju…

> My takeaway is that for truly private chat one should write his own software

That's the only way to make sure you're using software you trust, but rolling your own crypto implementations is often not so secure (because of the many pitfalls).

Re: ‘I will show you how safe Telegram is’

#32
post #22

Earlier quoted context omitted.

In Telegram the first is available opt-in, an equivalent to the second is available opt-in (key change = shows up as a different chat), and the third is equally true.

We know from experience that most users never change defaults. For that reason alone, Telegram‘s "secure chat" is anything but.

I agree Telegram is a worse choice for security, but I think it’s important to know specific differences and not just simplify to “not secure”, because that approach’s flip side - believing simply that “Signal is good and secure” - leads to mistakes like applying the law of defaults only to Telegram, not Signal.

Re: ‘I will show you how safe Telegram is’

#33

I monitor Russian war channels and some people there insist on using Telegram only for Russian military people. If you use Whatsapp, Ukrainian officers will get all chats from NATO. Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. My takeaway is that for truly private chat one should write his own software using simple crypto without all those fancy clients. Ideally ju…

> Telegram accounts of opposition were hacked by belarus police as well. It's known and documented.

No, not really _hacked_. You give your phone unlocked to the police, and they access your Telegram account. You can't refuse, and you probably can imagine why.

Re: ‘I will show you how safe Telegram is’

#34

Isn't this a weakness in all SMS based verification? If you can reroute SMS auth codes, it's game over. It's too bad that most 2FA rely on this method (or use it as a fallback). I don't see how it is directly related to telegram, though.

> If you can reroute SMS auth codes, it's game over.

Except it's absolutely trivial to do so, just bribe a low ranking employee of the phone company, and it's done. This has been done thousands/millions of times, usually targeting Bitcoin holders. Just google "Simjacking"

I absolutely loathe when companies make me use SMS as 2FA. I flat out refuse to use the service if they force SMS for account recovery, because at that point you might as well just be sending plaintext passwords over the internet, because you clearly don't care about your customers safety.

Oh, and the amount of hoops you have to jump through to make Gmail NOT use SMS for account recovery is insane.

Re: ‘I will show you how safe Telegram is’

#35

I monitor Russian war channels and some people there insist on using Telegram only for Russian military people. If you use Whatsapp, Ukrainian officers will get all chats from NATO. Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. My takeaway is that for truly private chat one should write his own software using simple crypto without all those fancy clients. Ideally ju…

If you and your group chat friends can meet up in person once to input an agreed upon a ~1Gb one-time-pad then you can exchange uncrackable text messages for years on any insecure channel I’ve long felt that this is the ideal solution for anything super super secret

Re: ‘I will show you how safe Telegram is’

#36

Isn't this a weakness in all SMS based verification? If you can reroute SMS auth codes, it's game over. It's too bad that most 2FA rely on this method (or use it as a fallback). I don't see how it is directly related to telegram, though.

> If you can reroute SMS auth codes, it's game over. Except it's absolutely trivial to do so, just bribe a low ranking employee of the phone company, and it's done. This has been done thousands/millions of times, usually targeting Bitcoin holders. Just google "Simjacking" I absolutely loathe when companies make me use SMS as 2FA. I flat out refuse to use the service if they force SMS for account recovery, because at…

millions of times?

Re: ‘I will show you how safe Telegram is’

#37
post #5
post #2

So, the twitter post alludes to SS7, but it is not clear how it is (ab)used to do the Telegram-related exploitation. Presumably, SS7's design flaws are being used intercept Telegram's registration verification messages, placing the resulting Telegram accounts under control of the bad actors while appearing to be real, independent users (and so aiding in establishing their credibility, which leads to other things), bu…

Telegram allows logins per SMS code (they will be rolling out changes in two days). So as long as you knew the number of your victim and have the ability to re-route SMS, you were able to login to other people’s accounts. Of course this can be easily mitigated by setting a “cloud password”, but I guess most people don’t do that.

> Of course this can be easily mitigated by setting a “cloud password”, but I guess most people don’t do that.

I have a faint memory of being forced to set said cloud password, or at least not finding a way to skip the set password screen. So I've always assumed it wasn't entirely uncommon.

Re: ‘I will show you how safe Telegram is’

#38

Better to link to the actual story (Guardian in partnership with a few others): https://www.theguardian.com/world/2023/feb/15/revealed-disin... Covered already on HN: https://news.ycombinator.com/item?id=34800157 https://news.ycombinator.com/item?id=34803779 Etc

Speaking of the actual story, how come they put all of this effort into unmasking this guy, discussing the consequences of his actions to the integrity of democracies... but then he says "I hack into Telegram accounts by using an SS7 vulnerability", and they just copy and paste that verbatim into the story, not even bothering to explain it in the slightest?

Obviously it's because they themselves don't know what it means, so it just gets filtered by their brain as nonsense tech words. But is it really that hard for them to reach out to a tech person and ask them "hey, what does it mean that they use an SS7 vulnerability to hack into Telegram accounts?", so that they can explain "Oh, that means they're impersonating your phone number, so that when Telegram sends you an SMS to verify that it's you, they receive that SMS on your behalf and can log in to your Telegram account"?

It baffles me, because it would take so little effort for them to provide this additional context into how the actual hacking is done, in a way that is understandable and interesting for the average non-tech person, and yet... they just don't bother to?

Somehow this seems to only be acceptable for tech stuff. If when they found out that this guy was involved in the Nigerian elections, the reporter shrugged and said "Huh, Nigeria. I wonder what a Nigeria is. Anyway, not worth Googling it or checking whether it has any relevance to the story whatsoever" then everyone would agree he's doing a disservice to the story and to the public. Yet somehow this is routinely done with technical terms, the public is worse off because basic things are hidden to them behind inscrutable acronyms by lazy reporters, and no one bats an eye.

Re: ‘I will show you how safe Telegram is’

#40
post #36

Earlier quoted context omitted.

> If you can reroute SMS auth codes, it's game over. Except it's absolutely trivial to do so, just bribe a low ranking employee of the phone company, and it's done. This has been done thousands/millions of times, usually targeting Bitcoin holders. Just google "Simjacking" I absolutely loathe when companies make me use SMS as 2FA. I flat out refuse to use the service if they force SMS for account recovery, because at…

millions of times?

It's a routine operation for even small-time groups.

One million requires: 10 000 contacts spread across phone operators around the whole world, each enabling 100 sim swaps over time. I suspect this doesn't take so long to fulfill.

Post reply on HN