Telegram's Peer-to-Peer Login system is a risky way to save $5 a month
theverge.com
theverge.com
What is the risk exactly? If someone wanted to spam/harass/etc people, he can do that by just mashing 10 random digits in the dialler UI and repeat until he gets a successful call/text through, or lookup their country's number range allocations to narrow down to a specific carrier/etc.
It’s still a much too high risk in my view, given the sensitivity of a long-term historical communications log that’s on the other side of that authentication.
I’m also not sure that these are effective deterrents: The people trying to brute-force my Instagram password certainly don’t care about sending me a warning email and locking my account once per day, for example.
I’m not convinced this is more insecure than sending it though conventional means - telecoms are well and truly compromised and don’t give a shit about it. If you’re gonna get dubious security anyway, at least you can save some money by not having to pay for it.
Locking your Insta account means they’re effectively only getting a couple attempts per day - the rate-limit is working at thwarting targeted attacks towards your account. The reason it keeps going on anyway is because they aren’t targeted attacks and are hoping to win the lottery and get into any account by sheer luck (just to spam - this is not a targeted attack and they’d have no interest in your chat history).
> I’m not convinced this is more insecure than sending it though conventional means - telecoms are well and truly compromised and don’t give a shit about it. If you’re gonna get dubious security anyway, at least you can save some money by not having to pay for it.
The telco is still in the loop, though, so this still increases the number of parties with potential access to the verification messages.
I could see it as a second factor, but as the only factor (by default), it's outright scary.