Telegram publishes users' locations online
blog.ahmed.nyc
blog.ahmed.nyc
This is a imperfect solution. There's two possibilities: the offset (aka "random number") is dynamic, or it's fixed. If it's the former all you have to do is sample enough times to get through the noise. If it's the latter, it's not vulnerable to the previous attack, but if you have a known point of reference (so you can deduce what the offset is), then you can still stalk them (forever?). IMO the only way to do is "properly" is to quantize people into map cells, like how apple does it with their coarse location feature[1].
[1] "Apple doesn't reduce the accuracy of location fixes by adding noise. Instead, they've carved up the world into regions, allowing approximate locations to preserve the user's current city when possible." https://radar.io/blog/understanding-approximate-location-in-...
It sounds like this approach could be prevented by having a random fixed offset for each user, so that you have no point of reference unless you already know where that specific user is. [Removed bit about regenerating this offset infrequently.]
EDIT: You could even do this in conjunction with the quantization mitigation, which sounds like it would shore up the slight weaknesses with that approach (where being on a quantization boundary makes it obvious where you are in that dimension) for the best of both worlds, as long as you're okay with further decreasing accuracy.
(i.e. you're unlikely to most of the time be in the middle of a lake, farm field etc)
Something like:
reported_position = true_position + hash(secret + true_position)
>[...] but if you have a known point of reference (so you can deduce what the offset is) [...]
Furthermore, if a person uses multiple services, and each service has its own cell layout, you can check all services a user is member of and then find the intersection. Ideally services would standardize to one single cell layout. So Apple's idea of doing this cell partitioning at the OS level is really good.
I think the boundary concern can be resolved by some inertia system, so a person doesn't switch cells unless they are deeply enough in the new cell, at which point they won't switch back unless they have moved back deeply enough.
Hmm yeah I meant overlapping cells then, not inertia based ones.
- smooth region borders (based on distance to one or multiple region centers with some the client being reluctant to report you in a new region until you are far enough from your current regions center point(s) to not "jump" back and force.)
- smoothing of reported regions on the client side (might incur some delay)
- user setting of region size (show that I'm in <large city> or show that I'm in <region of large city> or <small km² grid in region in large city>)
- white list which users can see the position (allow all, potential with 2 or 3 groups of precision).
I think by combining all of this a reasonable system can be created, but I would never go with a system which can report (explicit or implicit) the exact position (without a lot data and work) or which doesn't allow you to whitelist who can see you tbh.
Anyway this also means that the area would need to be calculated by the client (phone) and then send to the server which then might apply further smoothing/filtering based on the regions it's put in relation with.
> It might be tempting to think that reduced accuracy locations are simply your true location with some noise added in.
> But that is not the case. Simply adding some random noise on top of the user's true location is actually not that secure against someone who might wish to disambiguate the true location. Instead it's better to think of what happens under the hood as a quantization of sorts. Let me explain further.
> Let's look at an example area. Consider different users going on a drive in the vicinity of El Paso, Texas and Juarez, Mexico. Note that this is near an international boundary, with the US being in the northern half of the map, and Mexico being in the southern half, bordered by this pink line you see here. The true position of the user is represented by the cars while the reported position, that is to say what an app would see if it had reduced accuracy, will be shown by a circle. Again as I mentioned earlier in this presentation, these reported locations will contain the user's true location.
> As these users drive down Interstate 10 the location snaps to within different quantize regions of varying sizes. Both the red and yellow users are going to be quantized or "snapped" into the same regions as they drive along the road.
> But the amount of snapping will vary. In denser urban areas, this amount of quantization can be a couple of kilometers, but in less dense places like rural areas, it can be 10 kilometers or a bit more. A typical value for this quantization radius is around five kilometers. Note that despite the cars continuously driving along the road the region to which the true position quantities will not continuously update. This is because Reduced Accuracy locations are recomputed about 4 times per hour. So depending on exactly how fast these cars are moving there might be some lag between quantized snaps. The actual semantics of the quantization are intended to replicate what the user would expect to hear if they were to ask for an approximate answer to the question "Where am I"? We tried to ensure that the resultant reduced accuracy location is still going to be somewhere that the user actually expects to be. We use a location we have for you to place your approximate location on the appropriate side of the border here.
> Again though remember that the center point does not represent the location of the user. It only represents the center of a region where they approximately are. Approximate location snapping however might put you in a neighboring city especially if there are cities close together. To reiterate the bit about quantization around borders, let's see what happens to someone driving on the other side of the border in Juarez and what they might expect to see.
> Note that the blue car is quantized into regions whose centers are on the Mexican side of the border.
Cool!
We're right back to the neofeudalist setup: Apple will protect your privacy from everyone except Apple (and the US military, to whom they are legally obliged to provide the data without a warrant).
https://locusmag.com/2021/01/cory-doctorow-neofeudalism-and-...
I’m also using the app on iOS, the operating system asks periodically if I want to continue sharing location in the background (in case I forget to turn it off) or I can just choose to enable it while using the app (which is what I usually do).
This is a non-issue, this guy "Ahmed" is just fishing for attention with an incendiary title.
"approximate location, don't worry we have thought a bit about security",
i think.
Telegram can be criticized for certain things, but this isn't one.
User explicitly shares location to all people nearby, discovers it is accessible to all people. Feature is disabled by default, and user must find this and enable it. They are not even prompted to enable it unless they seek it.
Unless Telegram does some extra steps to prevent exact locations (see other threads here), they should name it "share my location" instead of "show nearby users".
People nearby.
Quickly add people nearby who are also viewing this section and discover local group chats.
Please allow on location access to enable this feature.
"Allow in settings" (a button)
Then you see a system location access dialog. iOS allows to choose between (always, when in use, nope) and optionally to turn off "high precision" setting (not sure how much, but it covers entire city when off).Then you may tap another button named "Make myself visible". I didn't, but a list of nearby users/groups was populated regardless.
In my own products I fix this by aggressively rounding/adding noise before the distance calculation is performed, and then rounding again afterwards, or quantizing into ranges (e.g. '0-10 miles'). Other solutions can be storing locations imprecisely to begin with, using pre-defined geobuckets, and so on, although remember that randomness by itself can be bypassed with enough queries since it will average out. It's rare that you need to know exactly how far away someone is from you rather than a rough approximation. Telegram is definitely not the only product with this issue, but hopefully they fix it even so.
If you want to be extra safe, quantize the user's lat/lon before computing the distance, and then quantize the distance again.
(Quantizing only the distance can theoretically allow an attacker to travel in one direction until they see the transition from one bucket to the other which would tell them exactly when they are precisely 10 miles from the target.)
https://gis.stackexchange.com/questions/17344/differences-be...
Gay Dating Apps Promise Privacy, But Leak Your Exact Location
Quickly add people nearby who are also viewing this section ...
If a user is not specifically on that page, they are not listed in the section. The user most likely wants the world (or strangers) to know his position.
This case shows precise localization can be a double-edge sword. But instead of fuzzing the returned location, we should educate the people on privacy implications of showing their position to the public.
I'm consistently seeing some of the people nearby across multiple times opening the page, some of which weeks apart.
That's part of the problem, all those you listed have poor to terrible UX and are just not great chat clients, Telegram is just better - in terms of speed ( compared to FB Messenger), features such as location sharing("where are you?", "Next to Restaurant XX " or "On the corner of A and B street" sucks, you can just share precise location via Telegram - a friend even sent me the location of a beautiful lake while on vacation because i was going in the area soon after), polls ( great for groups), message editing, search, stickers, gif integration, bots. I've used FB Messenger and Whatsapp extensively and Telegram is absolutely much better than both of them.
Telegram is better in every way... except security.
Which is why anyone bothers with these type apps in the first place, I'd like to say I'm dissapointed with the sentiment towards Signal, especially given how many here work in tech and understand how leaky these apps are designed to be and how hard development can be with a bare bones team (I experienced this first hand), but it never fails to bank on the notion that convenience will always win against security. regardless of expectation(s).
Shrug... I like Signal more: and I think Telegram has many useless features that are not of any interest to me and only create needless bloat at the expense of security/privacy which is untenable, so while I hope some bugs get sorted in Signal as I run both I know why I side with Signal.
I also understand that Signal runs on a thin donation based hacker budget and Moxie Marlinspike's podcast on Joe Rogan is a really cool watch that made it clear to me it's just a hacker project that scaled really well and is in need of funding and staff. I think Joe revealed himself to be a part of the money-centric Corpo class to Moxie's dismay when he refused to have that rock, paper, scissor match and you could see the disappointment in his eyes when Joe reacted almost offended at the idea that Moxie had anything worth his stake and could so quickly ascribe a dollar value to it.
It reminded me that it's okay to care about the messenger (guest) that his podcast attracts rather than Joe or the brand he's created around himself, even though I agree with may of his points I struggle to think its nothing more than hook or gimmick most times. I don't really enjoy any of his standup and find a lot of his quips to be childish and immature reactions to what seem like feckless attention grabbing that can derail a guest's conversation or train of thought, much like uninvited fart jokes would amongst otherwise fascinating discussion and in depth arguments: then again he is a comedian first and foremost.
With all that said, donate to help get those fixes on Signal sorted here [0]!
For my part, I find it fully amusing when a add another parent to my contacts, and they come up in Signal. <3
What I thought was the funniest part (strangest) is that Moxie walked back to "I'll give you a suggestion of people and you don't even have to have any of them on" and Joe still treated it like Moxie could dictate who was going to be on the podcast. But what's the difference between that and any other guest being like "hey, you should check out ________!" which happens all the time. It was literally a nothing bet. I do think Moxie forcing the week's lineup is a bit much. A single person? Not that bad, but I could see it being used against Joe (though unlikely). But "hey you should check these people out" is nothing. Guests suggest guests all the time and so does his fanbase.
As far as Signal goes, they've almost completed every major feature I've wanted. Usernames look like they're rolling out in a few months or less and group calling works (just needs to scale). Only issues I have are that sometimes there's some latency (this seems to be more related to 1. specific peoples' phones' battery optimization settings and 2. when there are large upticks in user enrollment. So neither of these are that big of an issue for me) and I can't use markdown (essentially a non-issue). Only things I want are fairly fluffy and features I would use fairly irregularly anyways. I don't understand the distaste of UI and it hasn't been properly explained to me yet. UI looks almost identical to WhatsApp except WA is far more busy in the background (which I actually dislike) ¯\_(ツ)_/¯
Maybe, but I saw it more as a way to try to have a little fun in what had been a stalled conversation due to Joe's lack of understanding on why cryptology has become vital and the implications of its need in modern Society.
I wish Joe had done some basic research and mentioned the first crypto wars himself and the fallout with Zimmerman had with PGP and Moxie would have probably opened more about how that pertains to erosion of privacy and security on the internet and the implications of the Surveillance Economy that has grown like a deadly tumor on Society since the Patriot Act and why Signal was created in the first place. He's had Snowden, Glenn Greenwald and Andreas Antonopolous on several times now, there is no excuse for not being some what informed given his general curiosity on the topic by now and making the most of those podcasts and having Moxie speak on such a large platform.
Honestly, I wish he had let him request Laura Poitras to come on as she can bring the topic to the massess in a relatable manner better than anyone I've seen so far--hell I remember first seeing CCC and Defcon videos being totally overwhelmed by the speakers so much I couldn't follow any of it. This may be because she comes from a non-technical background as a film maker that has been around Cypherpunks for decades now but has also been at the center of so much of the polemics (Assange, Snowden, Wikileaks, Intercept etc...) of it all and likely saw how valuable it is in life and death situations very quickly.
My issue is with the dropped calls and poor call quality, but given how few people use the voice based calls they because Signal knows how vital to optimize for low bandwidth things like messages given its prime demographic in places with real reasons to use this app for its intended purpose. Again, totally understandable to me and something that they will eventually get to.
Aside from that, it's really gotten pretty good. I've been running it since the red phone days or what ever that app was called before signal.
I use Signal on iOS, and it's pretty much flawless. Extremely rare for me to even hear friends (many of which I communicate with using Signal) talking about problems, I vaguely recall having something go wrong a long time back, but can't even recall what it was now, only that it went away and started working properly fairly quickly/easily.
(I disagree with Moxie's choice to use real phone numbers as an underlying hard requirements, and also with the choice to notify people when other people from their contact lists start using Signal - but I understand why he made those choices (to piggyback pre existing social graphs) and respect how he implanted it without needing to grab my contact list and have it vulnerable on their servers...)
On Android it's flawless.
The way they inform which users in your contacts have signal should be opt.
If I open signal on my laptop sometimes it does this ridiculous “time lapse” where it strolls through messages one at a time.
Sometimes all the messages just randomly wiggle on my screen. No idea why.
I get that security verification thing all the time. All the time.
Got a new phone late last year and it wouldn’t sync.
Sticker packs will rearrange themselves at random.
I could go on for ages. It is hilariously buggy.
Thats all I need to know to make a choice given the track record of the robotic buffoon class that believe everything that momentarily scales up needs to be monetized asap to shit out one mindless billionaire here and there.
For more than 7 years since its launch, the slick app, servers that instantly synchronize non-secret chats, and basically unlimited file storage were provided for free to use. Really free, no ads, no paid services. If you think about the amount of money that it all cost, it’s _insane_. So it begs the question: are Telegram’s founders really that kind of people willing to donate hundreds of millions for people’s messaging privacy with an additional option of maybe returning some of these money 7 years later with ads, or Telegram is just an elaborate FSB honeypot?
I guess we’ll never know for sure, but I’m more cautious about services that offer too much for free, not too little.
(I haven't used the disappearing messages feature, though, so I can't speak to any possible bugs there.)
This should be obvious if you look at most popular chat apps:
* Facebook Messenger
It's like... a who's who of the worst privacy violators.
Works on tablets and desktops too. Just set it up as a linked device.
They owned feature phones so they've been blocked. Telegram paired just fine and works on any number of devices without linking them together and worrying about connectivity/battery for the main device.
> your number is only visible to people who you've added to your address book as contacts
Means they already have my number.
There is still a tiny difference. I can pick a username and chat with people who have my phone number (without them knowing it is me). It's a very small difference.
I don't have anything against Signal itself, but this aggressiveness and arrogance is really putting me off.
Has this became some kind of religion? Do you people realize that you are not the exclusive bearer of Truth, and that maybe, just maybe people that use Telegram chose to do so for a reason and are not poor clueless persons that need to be indoctrinated?
To be extra clear, my complaint is about whoever insists on spreading the falsehood that Signal is objectively better than anything else [and maybe also adds a bit of compassion on top ("it's a shame") for the rest of us unenlightened].
I would have no problem, and would actually be more inclined to switch to Signal, if you tried something a bit more modest and honest. Dunno, for example something along the lines of "If you would like an alternative to Telegram that has E2E enabled by default and on all chats, you could maybe be interested in Signal!". But what kind of discussion can we have if the argument is always "Signal is so much better, it's a shame that you people don't realize it" ?
Telegram has been implicated in a number of privacy scandals, and then their responses critique the authors of the indictment rather than actually criticizing the arguments themselves. Signal, even up to the recent critiques by Cellebrite, immediately responds and them discusses the merits of the claim.
https://github.com/LibreSignal/LibreSignal/issues/37#issueco...
I can’t create a new group, but my friends can.
I don’t see friends that join Signal until I search for them manually by phone number, even though I allow Signal access to my contacts.
”So much better”?!?
So yeah, @arthurcolle has used Signal, and likes it.
While you're right, the title is accurate although it comes with bunch of caveats of course, some of them outlined in the article. That's why we read the full article instead of just titles. More caveats are that they are using a smartphone, has GPS location on, are using Telegram, have allowed the app to access the location and finally shared their location in Telegram.
Why add more?
Most folks would be inclined to look under "Settings" rather than "Contacts" for something like this. How strange!
It's mentioned in this changelog item: https://github.com/Telegram-FOSS-Team/Telegram-FOSS/blob/847...
It usually takes some time for Telegram to be published on F-Droid, so the newest version on F-Droid is 7.2.1 while the newest one on Android is 7.3.1. It might contain such a menu on the newer version like in that screenshot. Or the button only appears at that place if you have enabled location sharing.
But I also see a lot of folks on it....so it us concerning if it isn't opt in for non-F-Droid users?
Barring no exploits, you have to press "Make Myself Visible" and then confirm with a popup in order to share your location.
Edit: I turned enabled location sharing under iOS settings for Telegram app and "Find People Nearby" is now showing as the first list item under the Contacts tab.
I think the assurances that this offers (entirely FOSS, reproducible builds, better privacy and security[3]) outweighs being sometimes days or weeks behind the releases they upload to the Google Play Store.
[1] https://github.com/DrKLO/Telegram [2] https://github.com/Telegram-FOSS-Team/Telegram-FOSS [3] https://github.com/Telegram-FOSS-Team/Telegram-FOSS#changes
You can also truncate the data you have on users. 2 digits of Decimal_degrees precision is +/- 1KM. If you're doing an Uber-like service, knowing where a user is down to a few feet makes a different (which side of the street). But if you're just concerned with "Hey people nearby you are using this app too" (which is all too common).. Do you really need to know/save/keep where a user is beyond 1 sq km? No, you don't.
Yes, Apple has a coarse data that does something like this, but take it that one step farther. Don't need the info? Don't collect it (your app doesn't need to send it) and don't store it.
Wouldn't eventually samples of arbitrary precision have their "range donuts" overlap heavily at the user's location?
This could probably be automated to track in real-time someone's position.
I hate it how I cannot make the left bar less wide, for example, and there are a couple of more complains, all of which have been reported a long time ago. They are easy to add/fix!
I also wish the desktop version supported sending audio messages just like the Android version does, similarly to WhatsApp. No need for these fancy audio filters, just let me record and send an audio message from the desktop version!
For all we know Telegram is doing some rounding. Gonna need to test some more to see I guess.
Not sure of the best way to word it, but making it clear that someone in a different continent may be able to see your location and address would at least make the full implications clear. Most users probably assume the risk is limited to people in their city (or a smaller area within it) seeing their location, and also may not necessarily be thinking about the address disclosure (even if that's arguably already obvious to some).
https://www.wired.com/2016/05/grindr-promises-privacy-still-...
Gay Dating Apps Promise Privacy, But Leak Your Exact Location
Researchers in Kyoto demonstrate for WIRED how they can precisely track the locations of people using Grindr, Hornet, and Jack'd despite features meant to hide them.
The mentioned research paper is here: https://arxiv.org/pdf/1604.08235.pdf
I wonder if this will be sufficient?
- Of course this shouldn't be possible, what is up with Telegram? At last make publishing your precise location optional (within that feature) with a good warning!
It seems like it would be rather easy to create an automated tool for triangulating users locations; by spoofing the GPS location of ones phone say 33 times, it should be very easy to triangulate every single person in the 'nearby' section.
Depending on your definition of 'online' this is true of any app you use.
Telegram could at least take a similar approach to Tinder, who have already learnt from a similar mistake.
https://robertheaton.com/2018/07/09/how-tinder-keeps-your-lo...
Telegram will continue to expose its most sensitive users over novel features while they try to capitalize on use of the Signal protocol. The profit motivation predicted this.
Don't trust Telegram.
There is no problem with location sharing being enabled by default because location sharing is not enabled by default.
Not now, but mistakes happen and have happened. Thanks for providing such a perfect venue to illustrate my point.
It's a really low-quality article, pay no attention.
The author is basically complaining that GPS works.
Turning this toggle off is a great mitigation for apps who haven’t fixed or clarified how they handle such triangulation attacks.
It implies it's only 'nearby' with a warning about people you don't know messaging you.
Claims the app warns you or the user should know are either everything wrong with IT, or perhaps iOS is different.
They do have access to the metadata, i.e. whom you messaged and when.
--
[0] https://techcrunch.com/2016/04/05/whatsapp-completes-end-to-...
I love Signal and all the work Moxie and his team have put into it and the protocol, so this isn't a diss to them, but just wondering what the disadvantages would be for someone just looking for an E2EE communication app.
One difference I suppose would be that Facebook would have all the message metadata; just not the contents.
Whatsapp still does E2E encryption. (Same as Signal) Facebook can't read your messages. (There's still the scenario of you getting a special version of the app with that functionality disabled of course) You can also enable notification for changed signatures, which I do see changing as people replace their phones.
Personally I use Telegram because they don't mind non-official clients like the FOSS builds. Whatsapp on the other hand is known to ban non-official clients. API access isn't available either unless you are a big corporate user, at which point you need a facebook ads account and cooperate with some API reseller... no joke lol.
I agree that closed source is harder to verify, but that’s not the same as insecure.
I didn’t know that the described functionality even exists, and it is off on my phone. TG is one of the apps that implements 0 dark patterns, imo.
By comparison, whatsapp regularily tries to cloud-ize me by making a backup and re-enter my personal data. I just tap “never”, “done” once a month, but it is annoying af when it happens at the incoming call. It also forced users to enter a status (but there was a bug that allowed to enter empty one). And if you have a sim-less device, it is such pita to install it there. No updates will be available, ofc.
As I have heard, Telegram is unencrypted by default. Both WhatsApp and Telegram are poor at making this 100% clear 100% of the time despite privacy being a major purpose of the apps. I'll admit I really haven't used telegram much but WhatsApp encourages backing up chats to cloud storage. WhatsApp also only provides a single alert that a contact's security code has changed. It also doesn't encourage verifying the security code on the initial contact. i.e if someone out of the blue contacts you on WhatsApp the only security is the phone number.
WhatsApp is end-to-end encrypted by default (using same protocol as Signal) and there’s no way to disable encryption.
On the other hand Telegram chats are by default unencrypted ... you have to specifically start a “Secret Chat” to benefit from end-to-end encryption.
The reason why WhatsApp is more secure is simple: it uses e2ee for all chats, and consequently has issues with multudevice usage and chats syncing, while Telegram just stores all chats in its servers, sans so-called "Secure chats". (I'm yet to see one person who is using them to contact me)
As of source code... do you really need a source code if you can login with just your username/password and instantly see all your chats? For anyone who has some remote understanding of the matter it clearly tells that chat history is stored on servers without meaningful encryption and that server owner can access all chat history at will.
Personally I'd never bother to start a secret chat with a person that I don't trust enough anyway. Neither do I trust an e2e messenger that my country didn't even bother to "pucker" legally.
>users (wrongly) perceive it to be magically more secure
This is claimed often, but I'm yet to see these users. Do they really believe that, is it just tg opponent's agenda that became popular, or both?
I often see these users. Most tend to just blindly trust a vendor. Also, I recall a talk at a Secure Messaging Summit 2020 given by Nikolas Unger [1], where he referred to a study about this (mis)perception.
Perhaps TG should publish an API to allow people to see any users government ID if they are scammed.
While I use telegram, I use it to only communicate essential stuff with family. Same for signal and other stuff.
Matrix is interesting as it does not require a phone number... To think a government ID card would be needed to talk to family....shudders
You didn't learn your lesson. The lesson wasn't that Telegram should require a government ID (then nobody would use it much less the scammer who scammed you). The lesson was that you need to consider the impact of being scammed when you're open to using a channel with no recourse.