Hacker News new | past | comments | ask | show | jobs | submit login

I think tptacek was talking about actual takeovers of Telegram accounts. AFAIK there have been documented cases of this in Iran and Russia. See e.g. https://www.fredericjacobs.com/blog/2016/01/14/sms-login/



Nothing in that article proves that the accounts were actually directly hacked or mentions whether they had 2FA enabled or not.


Then it is a serious problem for Telegram and any app that relies on SMS or some phone identity to restore access to an account.


Telegram sends activation code to known devices, no sms (and I don't remember when it happened, maybe 4 years ago, probably for all other competitors). Also creators of telegram told everyone to use secret chats if conversations are secret to ensure p2p and forward secrecy. And to check key fingerprints to identify peers.

As usual, security threads consist of ancient beliefs, non-users and stories of low-conscious people using high-tech software. And there is always someone who mentions whatsapp as an alternative. Things like wickr are not even mentioned here.


Not a problem for Telegram, as you can protect your account with a password.


Private chats and your contact list can't be accessed by accessing your Telegram account though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: