If you can reroute SMS auth codes, it's game over.
It's too bad that most 2FA rely on this method (or use it as a fallback).
I don't see how it is directly related to telegram, though.
If you can reroute SMS auth codes, it's game over.
It's too bad that most 2FA rely on this method (or use it as a fallback).
I don't see how it is directly related to telegram, though.
Except it's absolutely trivial to do so, just bribe a low ranking employee of the phone company, and it's done. This has been done thousands/millions of times, usually targeting Bitcoin holders. Just google "Simjacking"
I absolutely loathe when companies make me use SMS as 2FA. I flat out refuse to use the service if they force SMS for account recovery, because at that point you might as well just be sending plaintext passwords over the internet, because you clearly don't care about your customers safety.
Oh, and the amount of hoops you have to jump through to make Gmail NOT use SMS for account recovery is insane.
One million requires: 10 000 contacts spread across phone operators around the whole world, each enabling 100 sim swaps over time. I suspect this doesn't take so long to fulfill.
That said, Telegram isn't very secure at all. You can make it secure by sacrificing all kinds of conveniences (i.e. not taking part in group chats) but the platform is just too unreliable.
It's a shame their apps work so well because the underlying protocol and security are behind on all of their competitors. From iMessage to WhatsApp and from FB Messenger to XMPP, encrypted group chats can be enabled easily. Only SMS/MMS is a less secure way to group chat.
GMail is as I understand it just your Google account, and so simply telling Google not to use the Phone for account recovery, by deleting that option if present, or not adding it when Google suggests you might want it, ought to be enough. Does that not work ?
Additionally, if you take over somebody‘s WhatsApp account, you can send and receive new messages in their name and very visibly kick them out of their account themselves.
With Telegram, the legitimate owner stays logged in (so you can see what they write and read in addition to sending your own messages), and you get their entire chat history on top of that.
Do not let sms 2fa slide for anyone.
[1]: https://fragment.com/numbers?sort=price_asc&filter=sale