How I Hacked Telegram’s “Encryption”
blog.zimperium.com
How I Hacked Telegram’s “Encryption”
1–10 of 18 posts
Re: How I Hacked Telegram’s “Encryption”
#2Re: How I Hacked Telegram’s “Encryption”
#3I'd say this guy is trying a little too hard to promote his "Zimperim Mobile Security" brand here...
Re: How I Hacked Telegram’s “Encryption”
#4I don't understand how this is a valid exploit/vulnerability? How would any device, Android or not, render the actual picture of the message on the GPU without having the unencrypted string in memory? It's not possible. If you have local memory/code execution, you will ALWAYS have access to the messages any client application is rendering/using.
Re: How I Hacked Telegram’s “Encryption”
#5Re: How I Hacked Telegram’s “Encryption”
#6TL;DR - the author claims to have hacked their encryption by reading the messages in phone memory. I don't understand how this is a valid exploit/vulnerability? How would any device, Android or not, render the actual picture of the message on the GPU without having the unencrypted string in memory? It's not possible. If you have local memory/code execution, you will ALWAYS have access to the messages any client appli…
Re: How I Hacked Telegram’s “Encryption”
#7TL;DR - the author claims to have hacked their encryption by reading the messages in phone memory. I don't understand how this is a valid exploit/vulnerability? How would any device, Android or not, render the actual picture of the message on the GPU without having the unencrypted string in memory? It's not possible. If you have local memory/code execution, you will ALWAYS have access to the messages any client appli…
Yeah, the memory thing didn't impress me. More concerning though is that apparently messages are stored in plain text on disk in that cache4.db file. It's not clear to me whether they are deleted when the app quits or what.
Re: How I Hacked Telegram’s “Encryption”
#8I find it hard to believe that Telegram did not respond to the author. How can one company simultaneously host a $200k security contest, yet not respond to a simple email disclosing a vulnerability?
There's literally no way to defend against this attack. About the best they could do is show a warning like "Warning: The version of Android you are using contains vulnerabilities attackers could use to take control of your phone. Please update your softw... buy a new phone to get the latest version of Android."
Re: How I Hacked Telegram’s “Encryption”
#9Re: How I Hacked Telegram’s “Encryption”
#10Offset 0056e1c, 0x54ba8a1d is unixepoch 1421511197 - which is January 17th, at 16:13:17GMT - which, given that the author is in Tel Aviv (GMT+2), corresponds with the 6:13PM timestamp for 'Shlookiedo' seen in the photos.