Adventures in Dystopia
1.71K subscribers
509 photos
49 videos
7 files
283 links
Download Telegram
Forwarded from Telegram
Через час после окончания сегодняшней акции приглашаем собрать те самолетики, которые Вы найдете у Вашего дома.
🔥13🥰7😢665👍3🤔3👏2🎉1🙏1🤝1
RCE on Github.com
Source: X (via Kirill)
🔥976👍5🙏4😢3👏1😁1
Each git commit remember me @toberg
❤‍🔥6👍6🥰53🙏3👏22🔥1🤔1🎉1
👍32🔥10❤‍🔥75🤔21
Funny fact: in Moscow, it is hotter than in Tehran.
👍87🔥53😢2🙏2👏1
Where is it?
👍22🔥10❤‍🔥54😢3🙏3👏2🤮2🤡1🤣1😭1
👍12🤣31👎1👏1🤮1🤡1
Telegram does not need to have its message encryption broken for users to be tracked at the network layer.

Telegram sends MTProto over unencrypted TCP, exposing auth_key_id - a long-lived identifier tied to the client’s authorisation key. An ISP, hotel WiFi operator, mobile carrier, transit provider, or surveillance system on the network path can see that identifier if they can observe the traffic. It can remain stable across app restarts, IP changes, VPN use, network switches, and location changes.

Secret Chats protect message content, but this leak is below that layer. That makes the attack passive.

The risk is in retroactive correlation. Think a journalist using Telegram from different networks for months, then joining hotel or corporate WiFi under a real name.

That one identity anchor could make old logs searchable for the same auth_key_id.

The fix is simple - mandatory transport encryption for all MTProto connections, with no unencrypted fallback. Telegram chose not to do this.

Source: @kaepora symbolic.software/pdf/gnmx-01.pdf

P.s.: Long life, global passive observer
8👍8😭4👏3🔥1😁1
Awesome and memorable! Black and dirty smm in action.
🤣97😁4😢2🙏21
This media is not supported in your browser
VIEW IN TELEGRAM
Did you prepare yourself for it?
👾55😁4👍1