6 ms·
A Telegram bug that disclose phone numbers of any users in public groups
- yaro2015 7y agohttps://www.zdnet.com/article/telegram-voicemail-hack-used-against-brazils-president-ministers/ https://www.zdnet.com/article/telegram-voicemail-hack-used-a...
- hmnom 7y agoIt could be argued you already had the phone number of your victim. If mobile numbers in your country are in the 2________ range, how feasible is it to add millions of phone numbers to your contact list to find out the number of someone? I think this is nonsensical.
- dchest 7y agoIt could be argued you already had the phone number of your victim. But you have no correlation between it and Telegram user. This bug is about this correlation.
- tialaramex 7y agoRight, the key trick here is that Telegram is easily used as an Oracle. Telegram has essentially agreed to tell you whether any phone number is correct, so you can just guess all the phone numbers. Never allow this unless the thing an adversary has to guess is both _completely random_ and from a _very large keyspace_ (128-bits is where you can start to feel safe). If you find you're cornered into doing this (e.g. typical email + password login) aggressively rate limit it, so the adversary has to work harder/ longer to take advantage and maybe they'll give up. Phone numbers are neither random nor from a large key space, it's maybe 10^12 worldwide or something? Much too small.
- fcbrooklyn 7y agoThe impact is specifically related to Hong Kong, where the protesters are using telegram to coordinate, and where, according to the bug report, the telephone number range is limited.
- emrhzc 7y agothey say that they managed to add 0.1 million people at once. If you're after a group of people and getting only one of them is enough, the limits look pretty feasible to me, even more possible especially in small communities.
- marcinzm 7y ago>If mobile numbers in your country are in the 2________ range, how feasible is it to add millions of phone numbers to your contact list to find out the number of someone? I think this is nonsensical. If you're a state actor probably pretty easy. Get a couple thousand rooted remote controllable android devices (which you probably already have for other projects) and have them automatically add 10k phones numbers each. Then have them join public telegraph lists and check for matches. Now you have gone through 10 million phone numbers. Run it in a loop 10 times and you have 100 million. Might take a few days to setup and run. I don't see why this is infeasible in any way to do if you have a moderate budget (ie: state actor). edit: And if your target is in your jurisdiction then you probably have a good mapping of names to phone numbers already.
- aasasd 7y agoI don't think you need a single device. Just bots with virtual numbers.
- nyxxie 7y agoAll this to get an app to make "do any of my contacts also use signal" requests? You could probably just figure out what endpoint the mobile client calls and imitate them yourself to avoid all the overhead of setting up the mobile devices. If you have to register to make the request, just provision a bunch of VOIP numbers and go to town. Point being, if "who is using signal" is a question you want answered, it's far more trivial than having to acquire actual devices. Your oppressive regime could go from zero to black bag list in an afternoon.
- MikusR 7y agoThe way cellphone telephones work, is by registering to a cell. so all they have to do is look what phones were in vicinity of cell towers in place where they protest.
- aasasd 7y agoThere's apparently at least one private company that gathered a database of account-to-number correlations precisely by adding over ten million numbers to Telegram's address books. Here's an article in Russian where one account is deanonymised: https://meduza.io/feature/2019/08/10/kto-takoy-tovarisch-mayor https://meduza.io/feature/2019/08/10/kto-takoy-tovarisch-may... Dunno if this is patched by Telegram in any way now. However, I don't see why it would be difficult for a program to add numbers to the contact list incrementally. To my knowledge, computers so far were pretty good at incrementing numbers. And if the contact list length is limited, the question is just how many phone numbers a company can buy.
- anthony_barker 7y agof*ck no wonder I get so many robo calls
- techntoke 7y agoNah man, you can thank the FCC for that.
- 22c 7y agoWhilst not the same as mentioned in TFA, I noticed in Signal that if you allow it access to your contacts it will tell you how many of your contacts are already on Signal. I understand this is useful from a usability/discoverability aspect, but from a privacy perspective I have no reason to be made aware of the fact that one of my old bosses who's number is in my phone is on Signal and neither should they know that I am on Signal for the same reasons (or lack thereof). What's worse is there seems to be no way to opt-out of this behavior. I can deny Signal access to my contacts, thereby not knowing which of my contacts are on Signal, but that doesn't stop the other party from knowing if I am on Signal if they have given Signal access to their contacts. It's not farfetched to consider a world where an oppressive regime may outlaw the use of something like Signal, Telegram or even WhatsApp and they'd be able to easily determine if you're using such a service through passive techniques such as these. As far as I know, Wickr is a bit more privacy focused, but it doesn't tick the open source box for me (although the supposed source code is published[1] for public review). [1] https://github.com/WickrInc/wickr-crypto-c https://github.com/WickrInc/wickr-crypto-c
- interfixus 7y agoWe are not really supposed to talk ill of the holy Signal here on HN, and we usually get severely trounced if we do. But of course you are absolutely right - this has been one gaping hole in Signal privacy since forever. Another thing Signal likes to do is to broadcast the fact every time you shift it to a new device. I have seen enough changing round from a couple of correspondents to deduce a pattern in their hardware habits. A third stunt it likes is to make it non-obvious what actually happens when you set up groups. One friend did, believing it to be just a personal way of organising contacts, thereby of course immediately exposing parts of his contact list to the rest of us and vice versa. Also terrible user experience (like using heavily license restricted software). I no longer use the thing.
- tapoxi 7y ago> Another thing Signal likes to do is to broadcast the fact every time you shift it to a new device. I have seen enough changing round from a couple of correspondents to deduce a pattern in their hardware habits. This is a security feature to ensure you're talking to the same person. Phone numbers are terrifyingly easy to port to another account.
- johnnycab 7y agoThis appears to be a similar attack vector, to the one which might have been used for scamming Swiss Revolut customers, by determining legitimate users via the phone number range, in order to deliver fraudulent SMS messages. https://www.reddit.com/r/Revolut/comments/cu07cv/revolut_scam_swiss_why_did_the_scammer_have_my/exq79mv?utm_source=share&utm_medium=web2x https://www.reddit.com/r/Revolut/comments/cu07cv/revolut_sca...
- mahemm 7y agoThe widespread usage of Telegram in a situation as sensitive as the Hong Kong protests is a failure on behalf of the security industry in educating the public. Even WhatsApp is miles better, but in reality it should be a no-brainer for the relevant people to use Signal or perhaps Threema/Wire. What a shame that charlatans have successfully marketed themselves to the top of this segment with a distinctly inferior product.
- ufmace 7y agoI don't think Signal supports very large groups well (hundreds of users or more). Or things like announcement channels where tens of thousands can subscribe, but only a handful of accounts can post. Sounds to me like they have a superior product.
- rolltiide 7y ago> Sounds to me like they have a superior product. Groups in Telegram are not encrypted. And now its shown that it also reveals phone numbers, and this is not a feature. Whatsapp shows phone numbers by default, so it wouldn't be a criticism of whatsapp.
- ajconway 7y agoWhatsApp does secure group messages with end to end encryption, but what good is encryption in a public protests group where everyone can see your phone number?
- sschueller 7y agocharlatans? You mean like when Facebook claims they have implemented the signal protocol but then scan your messages for keywords in order to disable encryption for governments? There is no way for you to check my claim nor Facebook's as it's closed source. Same goes for threema which will shortly be required by Swiss law to comply with Büpf as they will reach a size requiring it. It's closed source, we can't check what they are doing. Their external security audit was a long time ago. At least with telegram if I install the android version off fdroid it is compiled from source and I can verify that. I can gets users to switch to telegram, I can't get them to switch to signal. There is a trade-off but I would argue telegram over whatsapp anytime.
- chipotle_coyote 7y agoYou know what would be a great way to mitigate this kind of attack vector? Stop insisting on tying identity to phone numbers.
- RichardHeart 7y ago1 point by RichardHeart 44 minutes ago | parent | edit | delete [-] | on: Telegram 0-day vulnerability that can be used to d... "TELEGRAM'S REPLY ZDNet has reached out to Telegram for comment earlier today, and the company has looked into the issue reported by Hong Kong protesters. "We have safeguards in place to prevent importing too many contacts - exactly to prevent the scenario," a Telegram spokesperson said. "In fact, our data shows that the bot displayed on the screenshots got banned from further imports after two seconds - and only managed to successfully import 85 contacts (not 10,000)," it said. "Once you get banned from importing contacts, you can only add up to 5 new numbers per day. The rest of the contacts you add will look like they're not using Telegram - even if they are." However, this ban limit can be bypassed. A determined threat actor like the Chinese state can easily employ multiple bots to exploit this issue, instead of just one, and they'll eventually import the entire phone number sequence they want to cover."
- samat 7y agoTelegram says they block massive contacts imports, says that particular bot was able to add only 85 contacts and then throttled to 5 new contacts per day. My questions is how do they distinguish legitimate imports? I have 2K phone numbers in my address book. Would it take a year for me to be able to message my friends on telegram?
- codedokode 7y agoI assume there are some limits on number of uploaded contacts (probably on order of thousands) but they can be bypassed by creating thousands of accounts each with different contact list. One SIM card here in Russia costs as low as several dollars, and probably cheaper if bought wholesale, so it is not very expensive. Also, here is a quote from an article in Russian [1], where it is claimed that there is a software to de-anonymize Telegram users: > A phone number used by [Telegram] account @silovikicat was discovered using a program titled "Insider-Telegram" developed by the "Center of research of legitimacy and political protest". The head of the "Center" Eugene Venediktov explains: "Currently the database contains over 10 million of numbers. We just go through all possible numbers and check whether they are registered in Telegram: for example, we take all numbers starting with a prefix +7911 and check them. You automatically see all contacts from you address book in your Telegram, don't you? We just have a very "fat" address book with phones of all users from our country." > When a phone number provided by Eugene is added into an address book, Telegram automatically matches it with account @silovikicat («Siloviks' cat»). [1] https://meduza.io/feature/2019/08/10/kto-takoy-tovarisch-mayor https://meduza.io/feature/2019/08/10/kto-takoy-tovarisch-may...