Are we going to say that all of those have been breached too?
Are we going to say that all of those have been breached too?
Applications should not rely on SMS for authentication or login, or on the phone number for identity.
(Disclaimer: Threema dev)
I have a couple SIM cards since I live on the US/Canada border. WhatsApp and Telegram won't let me send messages when I switch SIMs and there is no other way to verify my identity.
Anyways the simple fix that might work somewhat is "alert the user". Telegram could tell the old user they have added a device. Or even require some time period where they wait for a response from the existing device, perhaps calibrated to their usage.
After registering a new device, a warning can be displayed to contacts for the first few messages. Maybe old messages are not accessible or something.
There are ways to limit the impact of an SMS hijack.
However, allowing for a reverse-lookup of a phone numbers through its API is a privacy—and security—problem Telegram is directly responsible for, IMHO.
If you have an existing Telegram device (registered before target registered), then how do they register? And wouldn't both devices get notified? Also how would they know which numbers to register?
Just fundamentally seems like the software can notify you of how many devices have access, and make that visible on any change and when installing on a device. Perhaps even offering to kill existing devices.
Of course, you won't see it too often in the headlines..