Telegram Desktop vulnerability allowed any user's file to be stolen (beaksec.github.io)
388 points by g-b-r 19 hours ago
farhanhubble 8 hours ago
I once read The Bugs We Have to Kill: https://www.usenix.org/publications/login/aug15/bratus and one particular thing that has stuck with me forever:
“Any sufficiently complex input format is indistinguishable from bytecode; the code receiving it is indistinguishable from a vir- tual machine.”
goodmythical 6 hours ago
Did you really name your son Robert'); DROP TABLE Students;-- ?
Forgeties79 5 hours ago
Ah yes little Bobby tables.
bita_nidir 6 hours ago
Related: could we please stop, by default, allowing software to:
a) access all your files, and
b) roam the internet at will.
That was somewhat OK in the 80s, but it hasn't been since.nikolay 5 minutes ago
In 2026, we still don't have a major OS that sandboxes everything.
hollerith 2 minutes ago
Googlebooks, which start shipping this month, will run a fork of Android 17, which sandboxes every app.
Also, some people use an iPad Pro connected to a USB hub connected to a monitor, keyboard, etc, as their daily driver.
celsoazevedo 5 hours ago
I wouldn't mind, but there needs to be a way to remove the "training wheels".
I don't want my computer to always be as closed and restrictive as an iPhone. That's good sometimes and perfect for some users, but not for everyone or all the time.
g-b-r 2 hours ago
Ironically, the closed and restrictive iOS and Android go then out of their way to make restricting Internet access hard
classified an hour ago
bita_nidir 5 hours ago
Of course, I was just saying "by default". You should be able to allow any access as you want, give it your old socks or granny. Just not by default.
zargon 4 hours ago
These days, most things that I run that aren't from my distro's repos get their own bubblewrap. On top of this, I use opensnitch. Even if I trust the application (uncommon), I never trust npm, pypi, etc. any longer. It's tedious to set this up and OSes should be helping make this easy.
drnick1 2 hours ago
Agreed. Programs like Zoom, Steam, and other closed source "apps" should always run either in a separate user account or in a bubblewrap.
MomsAVoxell 4 hours ago
The problem is, peoples files are too valuable - even to the OS vendors - and also, there are simply too many valuable people on the Internet without the willpower to know how to manage their own filesystem.
If the OS vendors are motivated to harvest peoples data, why on Earth would they be motivated to make sure nobody can harvest peoples data?
pizzafeelsright 6 hours ago
I am in agreement. I am always curious as to the solution because VMs are not the solution and zero knowledge is helpful but not quite there.
g-b-r 2 hours ago
VMs can help a lot, see what Qubes OS does
aucisson_masque 22 minutes ago
macOS does it pretty well, right ?
fsflover 2 hours ago
Yes, this is exactly how Qubes OS works.
jonathanstrange an hour ago
Not if I have anything to say about it. I want programs on my computing device to be able to access files and roam the internet at free will. In fact, I insist on it.
unethical_ban 2 hours ago
Agreed. I mean, AppArmor and SELinux exist to control file access, perhaps OSes should put more effort into user-friendly overlays to control processes and have audits to warn users when a piece of software has full system access.
As far as network control... We have open-source blacklists for various malicious websites. Perhaps we should also have "known-good" site whitelists and have OS-level blocking for that by default. Like, OSes running DNS-sinkholing of StevenBlack malware lists, and the option to enable "known-good" whitelists as well. Having a hosts file of 450,000 entries to sinkhole can bog down an interface coming up reliably... that process needs optimized.
There's a lot of money in the enterprise world doing similar things.
crossroadsguy 9 hours ago
One of the challenges with Telegram is - they regularly re-enable settings inside the app/account that you had specifically disabled. So at any point you don't know what is happening and what is not. Meaning, even if you didn't see a thing, a malicious file might be sitting all warm and fuzzy on your computer - among possible other things. I used to like the snappiness of this app (and it is still snappier than almost all other IM apps combined, by a margin), but after a while I realised it was a ticking time-bomb (to keep it installed on the desktop) and possibly a scammer safe haven, nothing else.
axegon_ 7 hours ago
A lot of companies do this but I always get a ton of hate for saying this: Telegram is the worst offender I've seen. If you start digging through their apps, you see a ton of security practices that are anything but secure. And one of the hundreds of reasons I treat Telegram as the plague: get it away from me and burn it with fire.
MajorTakeaway 3 hours ago
I've never seen a legit good hearted person ever use Telegram. It's usually what grifters and scammers prefer to use. Or Signal.
drnick1 11 minutes ago
unethical_ban 2 hours ago
esseph 3 hours ago
g-b-r 2 hours ago
BeetleB 2 hours ago
jminnl 8 hours ago
All big companies pull these kind of tricks. Another variation is to retire the old setting and introduce a new one with a deceptive name that is default on again.
boltzmann64 4 hours ago
Can you please tell me what settings get auto re-enabled? I use Telegram as my primary messenger app. I just want to make a more informed decision if I should switch to Signal or something.
drnick1 5 minutes ago
You absolutely should use Signal instead.
maqp 33 minutes ago
bluebarbet 8 hours ago
Presumably the risk is mitigated somewhat with the Flatpak version (`org.telegram.desktop`)?
crossroadsguy 6 hours ago
Not on Linux. But if that is a safe variant then yeah great. Also, I see https://flatpak.org (is this the one you meant?) has Telegram has one of the showcases apps on the homepage so I guess they would have done their due dilligence.
gvfsa 4 hours ago
This hasn’t happened to me absolutely ever in 10+ years.
pixl97 3 hours ago
In the distant past this meant more. Vendors shipped one option for everyone. Now with things like A/B testing and other application 'smart' behavior which ends up meaning we all have different experiences.
g-b-r 2 hours ago
For example?
SpacePortKnight 14 hours ago
I think it is one of the reasons why I am always hesitant to install any software on my windows pc. Web versions are often more than good enough.
modeless 13 hours ago
Yes. I'm constantly annoyed by the dark patterns Zoom and Slack use to trick you into downloading their desktop apps. The web experience is practically indistinguishable and much more secure.
freehorse 13 hours ago
> The web experience is practically indistinguishable
The web experience is actually better, as eg there I can do web searches when right clicking sth with my default search engine without slack highjacking the options to force me onto google.
nkrisc 10 hours ago
sdcfgy 9 hours ago
For me I just refuse to run another damn browser for each app. You can have a tab. That is it.
miroljub 13 hours ago
Slack web app experience on mobile phones is abysmal.
gvfsa 13 hours ago
palata 9 hours ago
> Web versions are often more than good enough.
Except when you want actual end-to-end encryption, in which case web versions fundamentally cannot guarantee it today (and there are no plans to get there).
People using Telegram don't care so much about end-to-end encryption, so there maybe it makes sense to use the web version indeed.
olalonde 9 hours ago
You should be more specific about what you mean here because you can absolutely do E2EE in the browser.
palata 5 hours ago
thadt 7 hours ago
perching_aix 9 hours ago
Why couldn't they?
palata 6 hours ago
emilfihlman 7 hours ago
The lack of TOFU in browsers is an extreme pain point.
I'm going to go out on a limb and say that it is on purpose, and not a good purpose. The trust model of the web is fundamentally broken.
palata 5 hours ago
Eueudhsbsj32 13 hours ago
When I really need to run an app on my Linux laptop, it always gets its own bubblewrap container.
drnick1 5 hours ago
This, especially commercial apps like Zoom, Steam and others. Sometimes a separate user profile is easier though.
monster_truck 13 hours ago
Don't let yourself be fooled into thinking this is enough. Plenty of examples of, especially through wasm, being able to reach far beyond what they're supposed to.
It gets buttoned up fast and is always getting better, but its absolutely not a silver bullet.
Fethbita 11 hours ago
If you enable lockdown mode on your iPhone and Mac, WASM is disabled through Safari. If absolutely needed, an alternative browser like Firefox can be used for those sites.
prophesi 9 hours ago
Don't most things people use day-to-day for both work and entertainment require use of the actual app these days, or at least make it very difficult to do so?
Razengan 13 hours ago
Even on Mac, where apps like Dropbox showed you a FAKE DIALOG to STEAL YOUR ADMIN PASSWORD:
radicaldreamer 4 hours ago
Look at who is on the board of Dropbox and ask yourself what the value of a file syncing service having accessibility (and previously kernel extension) privileges on your machine are.
Not to mention that Dropbox has never been E2E protected and had that Lenovo credential free access bug on web not too long ago.
Dropbox should be considered untrustworthy at this point, especially since iCloud Drive offers E2E encryption and so do other competitors.
Kwpolska 12 hours ago
Is this a fake dialog, or just the standard system sudo dialog, which used to allow app developers to show an arbitrary reason string?
Razengan 11 hours ago
yard2010 12 hours ago
Something about reading this blog post knowing every letter and screenshot done manually with no LLM gave me the chills
Razengan 11 hours ago
usr1106 16 hours ago
I don't use Telegram Desktop or Windows. But that's exactly the reason why I run Firefox in a firejail sandbox on Linux. The browser has only access to my Downloads folder. I know that it's considered untrusted and don't keep any files there for a long time.
freebsd_lovefes 15 hours ago
Or the reason to run Firefox in a FreeBSD jail to get server-grade security. But the question is can an attacker get access to the Firefox profile data? Because you cannot block that from Firefox, obviously.
usr1106 15 hours ago
Sure, to some degree you must trust your browser. In the extreme case you could open a new, non-persistent browser session for every page you visit. Could be slightly inconvenient...
bmacho 12 hours ago
fsflover 10 hours ago
barrkel 15 hours ago
I guess it also has access to the cookies for all your logins.
crossroadsguy 8 hours ago
You mean a website A can have login/auth cookies of website B, D, Z, HK… etc? SOP doesn't work? Or is there some sort of exploit on top of third party cookies? (Just curious. I don't know anout browser dev/etc).
By the way, they don't have just one web apps. They have A, they have K, and apparently a Z – subdomain is webz, or maybe that's actaully A. Not sure.
usr1106 15 hours ago
Yes, it has access to the internal storage mechanisms of the browser.
I used to use Cookie Auto Delete for years. But when I last checked it seemed unmaintained. I log out of all somewhat important services anyway every time I am done.
For important stuff like banking I use Firefox containers.
Yeah, all of them could have their weaknesses and vulnerabilities. I just hope no attacker hits exactly the stack I use...
eddythompson80 14 hours ago
maqp 15 hours ago
The little I have to run Telegram Desktop for, I run in a VM. I'd never let the little oligarch's code touch my desktop OS.
lifeisloving 15 hours ago
I dont write off software because where the person that made it was born. I personally think thats the same thing as refusing to eat at a black owned resturaunt because of the owners skin color.
Seems like many people do this when it comes to russian tech. Im American and I certainly trust my data in the hands of a foriegn government/entity (which is not even the case for telegram), than my own. Even if it was a russian op (its not the Ukrainian military literally used telegram for years), the russian government cant touch me.
maqp an hour ago
ornornor 14 hours ago
g-b-r 14 hours ago
iririririr 15 hours ago
interesting you mention. because Firefox doesn't have a way to disable the single instance functionality which was used on this telegram vulnerability.
one long time Firefox contributor have been for a couple years now removing every part of the --noremote option. even botching (Ooops!) the console notice that the flag was no-op some time ago.
yjftsjthsd-h 15 hours ago
> removing every part of the --noremote option
What's this now? I'm using that to handle multiple profiles and haven't noticed anything breaking
iririririr 3 hours ago
lxgr 13 hours ago
Which Firefox functionality was used in the Telegram vulnerability? Isn’t this all about the desktop app?
iririririr 3 hours ago
g-b-r 12 hours ago
Narushia 11 hours ago
It's great that this writeup was published, but unfortunately the text is full of claudisms and made me close the tab pretty quickly.
g-b-r 7 minutes ago
It is? I did suspect it could have been written and maybe found with AI, but I didn't notice many claudisms
xg15 10 hours ago
It's annoying, yes, but I think in this case, the information is important enough that people should jump over their shadow and read it.
You wouldn't ignore a zero-day announcement either because the formatting is ugly.
jcul 8 hours ago
I'm just a bit jaded from Claude's tone of voice, so it made me not want to read it.
I did skim over the important bits though.
xg15 7 hours ago
victor_pudeyev 6 hours ago
Yes, just close your eyes, don't worry! Close the tab...
Kinrany an hour ago
When criticizing Telegram, I wish people focused on the actual smoking guns and didn't include random fluff one has to cut through.
As a Telegram user, my current impression of the platform is that they are a tiny elite team, they focus very heavily on creating a polished product, and are somewhat arrogant about all of that.
The most common criticism that I see and understand is the lack of E2EE by default. But I'm not aware of a messenger that provides a good UX for that. For most people, losing access to the account is a much greater risk. (The trade-off has changed somewhat now that everyone is getting hacked by AI and thus Telegram's whole dataset leaking becomes a concern.)
The criticism that I agree the most with is phone numbers being used for authentication. Even if Telegram still wants to know everyone's phone numbers for growth reasons, as far as I'm aware for authn phone numbers are strictly worse than emails.
On the positive side, they still have a proper API, open source their clients and allow third-party clients. All of which seem non-optional for any messenger that claims to prioritize security.
Panzerschrek 16 hours ago
It's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file. Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory (like downloads for a browser or Telegram-client).
simonra 15 hours ago
At the same time the mobile operating systems are vulnerable to vendor lock-in due to the absence of this functionality. It is clearly a worse problem that a user can't give their backup system access to the photos stored by other applications (often social media), or for instance reliably capture media streams to use in for instance a remixing application. Bringing custom clients when the software originally used to create the interesting files starts acting against the users by introducing subscriptions or being abandoned is another example of the user dictating what software accesses what files is critical to secure the users operations. Consumers need security against commercial interests infinitely much more than commercial interests need protections against consumers, and it would be unethical to enable commerce at the expense of individuals like the mobile operating systems do.
lxgr 13 hours ago
There is a lot of middle ground between “every app can do anything as the user” and “no shared file system, no user access to app ‘owned’ files”.
debazel 10 hours ago
yjftsjthsd-h 15 hours ago
> It's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file.
No, it's definitely a Telegram specific vulnerability. It might be worse because of poor defense in depth, but without Telegram itself being vulnerable it wouldn't matter.
nvme0n1p1 16 hours ago
If you don't believe it's a vulnerability, then you must believe that tricking Telegram into uploading your messages database to the attacker, leaking all your private conversations, is A-OK? Telegram owns that file, after all.
Panzerschrek 16 hours ago
I didn't say it's not a vulnerability. It is clearly one. But allowing such vulnerabilities to deal damage beyond data of its host application is an OS vulnerability.
lxgr 13 hours ago
Yes, and there are many ways for apps to opt into this, to limit their own blast radius in a case like this.
Does Telegram do that, or do they consider themselves beyond bugs, just like they consider themselves too clever and untouchable by anyone to need end-to-end encryption?
ShinyLeftPad 11 hours ago
> vulnerability of all modern desktop operating systems allowing any user process to read/write any user file
not true on macos.
parampampam 7 hours ago
Not true for apps installed via AppStore. A lot of popular apps aren’t in AppStore, Chrome/FF for example.
alt227 11 hours ago
I would argue one of the main purposes of OSs is securing files between different users. All modern OSes do this securely if set up properly.
BoppreH 11 hours ago
Or Linux with Flatpaks.
lostmsu 10 hours ago
eviks 16 hours ago
That's broadly-speaking a vulnerable design of all OSes, but strictly speaking it is a bug in Telegram that is now fixed at the app level. Though sandboxes / app isolation solutions exist even in the broadly vulnerable OSes, so apps could use them already today to avoid such issues in the future?
saagarjha 16 hours ago
Telegram is available sandboxed from the Mac App Store on macOS.
lxgr 13 hours ago
It could easily sandbox itself in the non-store distribution as well, yet the developers apparently choose not to.
zorked 15 hours ago
It is also sandboxed in Flatpak.
Saris 10 hours ago
gvfsa 13 hours ago
That is not the same app.
ubercow13 11 hours ago
saagarjha 13 hours ago
nottorp 15 hours ago
> Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory
So how will you spam all the group chats you're on with meme gifs downloaded from facebook then? :)
Panzerschrek 14 hours ago
Download an image from Facebook into browser's private downloads directory, copy it using a file-manager application (one of the exceptional applications having full filesystem access) into Telegram's private directory, upload it into chats you need to post it.
The file-manger application managed above is a single point of failure, of course. So, it should be allowed to use only one provided by OS vendor.
lukan 12 hours ago
yjftsjthsd-h 8 hours ago
Clicking upload opens an OS file picker that lets the user select a file outside the app sandbox. At least flatpak and Android do it that way.
miohtama 10 hours ago
MacOS sandboxes user folders by default. The user need to explicitly give a permission for every application.
parampampam 7 hours ago
It sandboxes some use folders. ~/projects won’t be sandboxed for example.
penskymaterial 16 hours ago
> It's a vulnerability of all modern desktop operating systems
Uhm, OpenBSD would like a word, buddy.
ciupicri 7 hours ago
And Linux would like to present you bubblewrap [1][2][3][4] or the infamous SELinux.
[1]: https://github.com/containers/bubblewrap#usage
[2]: https://man.archlinux.org/man/bwrap.1
[3]: https://wiki.archlinux.org/title/Bubblewrap#Usage_examples
[4]: https://wiki.archlinux.org/title/Bubblewrap/Examples#p7zip
yjftsjthsd-h 8 hours ago
That has the caveat that it only works as far as apps opt into it
ptidhomme 8 hours ago
g-b-r 16 hours ago
It is.
Not all user processes upload those files somewhere surreptitiously.
Of course operating systems should support that isolation (hopefully in some better way than the hell that smartphones are), but it's not like Telegram can blame the OS for this vulnerability.
Panzerschrek 16 hours ago
> Not all user processes upload those files somewhere surreptitiously.
Only if you have access to full source code, can audit it (including each update) and somehow can prove that it has no vulnerabilities. Otherwise one should assume that any application is potentially-harmful and/or vulnerable.
yjftsjthsd-h 15 hours ago
g-b-r 16 hours ago
robertlane0 5 hours ago
Telegram and security don't really belong in the same sentence anyways. Say what you will about Signal but they at least have better cryptography and more transparency about what software they're running.
RachelF 12 hours ago
It looks very bad that Telegram took almost 3 months to fix this vulnerability.
Reported 25 June
Fixed 16 September
I wonder why it took them so long?
miohtama 10 hours ago
It was reported to a third party platform which the author says is likely clogged up.
k__ 12 hours ago
They are restructuring their companies regularly and keep the core company small.
erelong 17 hours ago
I thought telegram was flagged as insecure like a decade ago, it's never really been "very secure"
Like any number of articles like this: https://hackernoon.com/7-reason-why-telegram-is-insecure-by-...
misiek08 15 hours ago
Still we are using it, because UX kills any other app and people that are (probably) behind it will cause almost no harm to casual, not-interesting people :)
And yes, I know that by default chats are not E2E, that phone number has way too many effects on accounts etc. Still, UX and agencies interested in important people are more welcome than data selling, ad-based companies.
lxgr 13 hours ago
What a bizarre threat model. Why would you rather have your data with who knows who than just your metadata?
And what UX problems exactly is Telegram solving that its many competitors aren’t? I hear this all the time, but I use both Telegram and WhatsApp and I haven’t found anything lacking in the latter, UX wise.
maxgashkov 12 hours ago
Kinrany an hour ago
zahrevsky 8 hours ago
skeledrew 9 hours ago
maqp 15 hours ago
"will cause almost no harm to casual, not-interesting people"
Yeah same can be said for Facebook and WhatsApp that Durov vehemently claims should not be trusted with user's data. Maybe it's a ploy for the Mark Zuckerberg of Russia to get the data of people.
Also, Telegram doesn't have to sell it's users if it's an FSB honeypot.
mschuster91 13 hours ago
lxgr 13 hours ago
It was, but most people will believe what their peers (real or parasocial) say over the collective screams of every security researcher on the planet, so here we are.
g-b-r 17 hours ago
Absolutely, but mostly for their protocols, statements, people and infrastructure.
A file exfiltration vulnerability is still noteworthy.
phoronixrly 16 hours ago
Here's one from Filippo
The Most Backdoor-Looking Bug I’ve Ever Seen - https://words.filippo.io/telegram-ecdh/
TZubiri 15 hours ago
It has this feature where it tells you about other users that are on the platform. I mean it's not a huge leak, but right off the bat it's pretty poor security posture. For an app that competes with other chat apps on supposedly being more secure and privacy aware, it does worse than whatsapp on that end.
lukan 11 hours ago
"For an app that competes with other chat apps on supposedly being more secure and privacy aware"
It mainly competes against facebook and other social media plattforms. The privacy is clearly wrong and only believed by non technical people (which can be amusing, when on TG someone posts a link to FB, or a WhatsApp group and people chime in and lecturing others that they should not use that as it is insecure and owned by a big company who will sell them out).
thenthenthen 9 hours ago
This!! Signal also had this back in the day, very bizarre for an app thats privacy focussed… sadly have to use it because some contacts refuse to use anything meta etc. Sadly it is only big corp stuff that works reliably where i am somehow..
itsmeduncan 6 hours ago
I wonder how much of Apple's announcement around disallowing full system disk access was from this as opposed to Muse, et al.
wrcoro 11 hours ago
Does its official desktop client support "Secret Chats" (E2EE) yet? Last time I used Telegram before moving to more reliable IM platforms that feature was officially unsupported on desktop and there was even some community effort¹ to make a pull request with paid contributions totally ignored by Pavel Durov and his team
[1] https://github.com/marcovelon/tdesktop/blob/NoSecretChats/RE...
fsflover 9 hours ago
I heard Telegram client from aur repository on Arch Linux supports secret chats.
Cider9986 7 hours ago
Telegram is worse than WhatsApp. No E2EE by default in 2026 is insane and Telegram's marketing is so deceptive.
g-b-r 19 hours ago
This link has already been posted with https://news.ycombinator.com/item?id=50019667 , but that post's title ("Telegram Desktop: one-click account takeover") doesn't say that the vulnerability allowed also any user-accessible file on the disk to be stolen.
This aspect is also not highlighted much in the article, which weirdly mostly focuses on the account takeover.
To me it seems something remarkable enough to warrant reposting the link with a different title.
Somewhat astonishingly, the core of the vulnerability comes from an internal url scheme added to Telegram to... help them publish their releases on their channel.
The Telegram developers saw no better way to do that than adding an internal tool which uploads any file it's told to.
Everyone else publishing their app on Telegram is able to do that with a script, but they had to do it that way.
It's true that it was exploitable only in a somewhat convoluted way, but still, it's an obviously dangerous feature.
Anyhow, yes, clicking on a link in Telegram Desktop was enough to have any user's file exfiltrated and to access or take over their account.
arjie 16 hours ago
That is such a JiaTan grade feature because it’s an insane way to implement it but also plausibly deniable.
skeledrew 10 hours ago
This is really good to know. Telegram is my primary means of communication, and a bunch of other things, and even though I'm not exactly exposed (I have password set, and only a few people can yank me into a group), I'm running a bit of a custom-method install that I don't update much.
sehw 6 hours ago
I use Signal btw.
opengrass 16 hours ago
doas jexec -U opengrass tellyjail env DISPLAY=:0 Telegram
g-b-r 16 hours ago
Yeah, something like that would not have prevented the account takeover part, though, which relies on Telegram's own files; or the access to cached files.
anon_cow1111 16 hours ago
Imagine if you forgot to update your phone number with your personal bank, and then some random guy was given full access to your account and all of its contents. And even if you dug through the account options and set a 2FA password (normally disabled) he could still just delete your account outright.
Last I checked, that's exactly how Telegram works by default. It's laughable to consider a service tied to a phone number secure.
sunaookami 12 hours ago
You would still get a notification inside Telegram that someone else logged in (plus it sends the login code to your session first before you can fallback to SMS) and you can log them out. The "attacker" can't delete your account or log out your sessions because he can't use certain features on a fresh login, there is a downtime. But yeah, he can read all your chats. Same should be true for any app that uses phone number login. That's why there is a password feature.
anon_cow1111 8 hours ago
You can delete an account if you have the phone number but not the password, it's on a 7-day timer before the account gets deleted. It can be canceled by a logged-in instance.
That still means you have to check it every 7 days.
sunaookami 2 hours ago
msh 14 hours ago
I guess that’s the idea with phone number based services. Imagine if you could not sign up for telegram/ WhatsApp/ whatever because someone used your number before you.
syngrog66 10 hours ago
if the user values security and privacy would not be using Telegram
KingOfCoders 17 hours ago
It's not a bug it's a feature.
iririririr 15 hours ago
was a feature.
technically, this is one agency burning the feature of another agency.
maqp 15 hours ago
The main spy feature that is Telegram collecting 100% of content and metadata is the main feature for every intelligence agency who bothers to ask Mythos to find zero days to pwn the servers.
iririririr 3 hours ago
buckle8017 9 hours ago
I am shocked......
ramesh31 5 hours ago
I mean it's pretty obvious these things (Signal, et. al) are just honeypots for the three letter agencies, right?
maqp an hour ago
Show us the backdoor https://github.com/signalapp/Signal-Android
With Telegram it is very easy: NOTHING is end-to-end encrypted by defaults, and group / desktop chats can't be end-to-end encrypted. So operating a honeypot server that gets access to billion users' data, is the most obvious honeypot out there.
colordrops 15 hours ago
well duh
hulitu 11 hours ago
> Telegram Desktop vulnerability allowed any user's file to be stolen
Wait till they find out about web browsers. /s
bashtoni 15 hours ago
Russian social media app has backdoor. Who would have thought?
(Yes, I know they're technically Dubai based now)
maqp 15 hours ago
Yet the oligarch who supposedly lives in exile has visited Russia over 60 times since https://kyivindependent.com/kremlingram-investigation-durov/
seeknotfind 15 hours ago
Wow, that's pretty bad, but imagine if 50% of software allowed this to happen at any time, and it was discovered on December 1st, 2026. What would happen?
petterroea 15 hours ago
is that a threat or an ai doomsday whataboutism