Уровень 0 · материалов: 10
В кластер включаются документы о технических уязвимостях и программных ошибках в Telegram, ведущих к раскрытию данных пользователей, и исключаются документы о формальных изменениях в политике конфиденциальности компании.
Общие признаки: утечки персональных данных, деанонимизация пользователей, ошибки в протоколах безопасности, отслеживание местоположения, проблемы синхронизации контактов
Группа выше: Безопасность и приватность Telegram
Смысл: The author discovers a privacy flaw in Telegram where the Telegram X client reveals how many other users have a specific phone number saved in their contacts. This suggests that the platform's contact synchronization can be abused for parsing users and deanonymizing those who use 'anonymous' numbers or privacy settings.
A technical analysis reveals that Telegram X leaks how many users have a specific number saved, enabling mass-parsing and the deanonymization of 'anonymous' accounts.
Смысл: The text highlights a privacy loophole in Telegram where adding random numbers to a phone's contact list can reveal the phone number of a specific Telegram user, posing a security risk for account takeover.
A user demonstrates how to uncover a Telegram phone number by brute-forcing a phone's address book and criticizes Telegram's lack of privacy settings and 2FA alternatives.
Смысл: The main idea is that Telegram's proprietary MTProto 2 protocol contains a design flaw (cleartext transmission of device identifiers) that, when paired with its infrastructure's ties to Russian intelligence, allows for the global tracking and identification of its users.
Security researcher Michal Wozniak argues that Telegram is essentially a surveillance honey pot due to its cleartext device identifiers and infrastructure ties to Russian intelligence.
Смысл: The main idea is that the 'contact discovery' feature in popular messengers creates a systemic security flaw that allows attackers to deanonymize users through phone number crawling, posing a severe risk to privacy and personal safety, especially under state surveillance.
Research reveals that WhatsApp, Signal, and Telegram are vulnerable to phone number crawling, allowing third parties to identify users and map social networks.
Смысл: The main idea is that Telegram's 'Share my contact' feature creates an automatic mutual exchange of phone numbers, which the author considers a privacy vulnerability because it discloses personal information without explicit bilateral consent.
Sharing your contact in Telegram allows the recipient to see your number, and if they add you, you can see theirs, creating an unintended mutual disclosure of private phone numbers.
Смысл: The main idea is that Telegram maintains a permanent, non-clearing history of every contact it has ever encountered on a user's device, leading to the automatic addition of strangers and potential privacy breaches.
Telegram stores a permanent hidden list of all contacts ever detected on a device, causing it to automatically add strangers who join the platform even if they were only temporarily present on the phone years ago.
Смысл: The main idea is that Telegram's 'People Nearby' feature creates a security loophole where distance data can be weaponized via trilateration to track users' precise physical locations without their consent.
Telegram's 'People Nearby' feature can be exploited using GPS spoofing and trilateration to locate users with meter-level precision.
Смысл: The main idea is to expose a critical privacy flaw in Telegram where geolocation data was transmitted in plaintext, rendering 'secret chats' insecure for sharing locations.
An early version of Telegram leaked geolocation data from secret chats via unencrypted TCP sessions, bypassing the app's encryption.
Смысл: The main idea is to point out a contradiction between Telegram's image of privacy and independence and the fact that its Premium voice-to-text feature relies on Google's services, thereby sending user data to a third party.
Telegram's Premium voice-to-text feature sends user voice messages to Google, contradicting the platform's image of independence and user-centric privacy.
Смысл: The main idea is that while Telegram promotes high security through encryption, critical vulnerabilities in how it handles local file storage on Android (specifically in version 1.9.4) can compromise user privacy, as 'secret' files remain unencrypted and persistent on the SD card regardless of deletion settings.
The author reveals that Telegram for Android (v1.9.4) fails to encrypt or delete shared files from the SD card cache, rendering 'secret chat' deletions ineffective against physical access.