Hackers accessed Telegram messaging accounts in Iran – researchers
reuters.com
reuters.com
Are we going to say that all of those have been breached too?
Of course, you won't see it too often in the headlines..
Applications should not rely on SMS for authentication or login, or on the phone number for identity.
(Disclaimer: Threema dev)
I have a couple SIM cards since I live on the US/Canada border. WhatsApp and Telegram won't let me send messages when I switch SIMs and there is no other way to verify my identity.
Anyways the simple fix that might work somewhat is "alert the user". Telegram could tell the old user they have added a device. Or even require some time period where they wait for a response from the existing device, perhaps calibrated to their usage.
After registering a new device, a warning can be displayed to contacts for the first few messages. Maybe old messages are not accessible or something.
There are ways to limit the impact of an SMS hijack.
However, allowing for a reverse-lookup of a phone numbers through its API is a privacy—and security—problem Telegram is directly responsible for, IMHO.
If you have an existing Telegram device (registered before target registered), then how do they register? And wouldn't both devices get notified? Also how would they know which numbers to register?
Just fundamentally seems like the software can notify you of how many devices have access, and make that visible on any change and when installing on a device. Perhaps even offering to kill existing devices.
That said, SMS isn't a very secure channel for one-time passwords. Enable 2 factor auth.
This is _not_ true for messaging applications that are end-to-end encrypted by default and that do not store plaintext on their servers. This isn't a subtle difference. Lots of comparisons in this thread fall victim to a sort of implied false equivocation.
Using SMS as a form of authentication may be a quality that Telegram shares with other popular messaging applications, but it is uniquely susceptible to all of the associated pitfalls.
https://events.ccc.de/congress/2009/Fahrplan/attachments/151...
http://www.cnet.com/news/nist-set-to-ban-sms-based-two-facto...
https://helpdesk.lastpass.com/multifactor-authentication-opt...
"Telegram's exaggerated security claims gave Iranian users false sense of security, now Iranian secret police have read their messages." isn't quite concise enough.
Me thinks that's more important than someone intercepting an SMS - at least in terms specific to Telegram. Is there more information on this? What evidence is it?
It's part of their contacts API, where you submit the numbers you have in your contacts list and they let you know which numbers already have a telegram account.
They have since added rate limiting to prevent brute forcing it, but it sounds like the API itself is still available.
This is pretty huge, this can put many lives in danger, I know people who are gay and use telegram. If you are any kind of person who government does not agree with you , from now on , government has your personal communication record. For example when you applying for regular job(which 90% of jobs in Iran is related to government , because of state controlled economy)then you have absolute no chance, even if you are much better candidate than some stupid person who spend their lives defending government stupid ideas.
P.S. Replace all "government" with "regime". Government in Iran is actually good (in compare to regime) and Rouhani is our only hope. The problem is Revolutionary Guard.
I understand the risk associated with rogue people using such a service, but is not the ability to determine who exactly is using the service counter productive? I.e. for journalists and personas non grata under oppressive regimes.
I understand the want to share the article, but a concerted effort to amend the original title to reflect the actual content would have been appropriate here, methinks.
Edit: fixed some speling.
There is also a free implementation of the same feature set available called [2]FreeOTP.
[0] https://tools.ietf.org/html/rfc4226
What other systems would people suggest to do this initial setup?
New devices should only be authorised with the use of an authentication token from an existing client device; one needs to decide if the new device should have access to old messages. Ideally it would be clear to all parties as to which devices and identities have joined a chat.