Adventures in Dystopia
1.72K subscribers
509 photos
49 videos
7 files
283 links
Download Telegram
RCE on Github.com
Source: X (via Kirill)
๐Ÿ”ฅ9โค76๐Ÿ‘5๐Ÿ™4๐Ÿ˜ข3๐Ÿ‘1๐Ÿ˜1
Each git commit remember me @toberg
โคโ€๐Ÿ”ฅ6๐Ÿ‘6๐Ÿฅฐ5โค3๐Ÿ™3๐Ÿ‘22๐Ÿ”ฅ1๐Ÿค”1๐ŸŽ‰1
๐Ÿ‘32๐Ÿ”ฅ10โคโ€๐Ÿ”ฅ75๐Ÿค”2โšก1
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ‘438โค7๐Ÿ”ฅ2๐Ÿ‘1๐Ÿค”1๐Ÿคก1๐Ÿค1
Funny fact: in Moscow, it is hotter than in Tehran.
๐Ÿ‘87๐Ÿ”ฅ5โค3๐Ÿ˜ข2๐Ÿ™2๐Ÿ‘1
Where is it?
๐Ÿ‘22๐Ÿ”ฅ9โคโ€๐Ÿ”ฅ5โค4๐Ÿ‘4๐Ÿ˜ข3๐Ÿ™3๐Ÿคฎ2๐Ÿคก1๐Ÿคฃ1๐Ÿ˜ญ1
๐Ÿ‘12๐Ÿคฃ3โค1๐Ÿ‘Ž1๐Ÿ‘1๐Ÿคฎ1๐Ÿคก1
Telegram does not need to have its message encryption broken for users to be tracked at the network layer.

Telegram sends MTProto over unencrypted TCP, exposing auth_key_id - a long-lived identifier tied to the clientโ€™s authorisation key. An ISP, hotel WiFi operator, mobile carrier, transit provider, or surveillance system on the network path can see that identifier if they can observe the traffic. It can remain stable across app restarts, IP changes, VPN use, network switches, and location changes.

Secret Chats protect message content, but this leak is below that layer. That makes the attack passive.

The risk is in retroactive correlation. Think a journalist using Telegram from different networks for months, then joining hotel or corporate WiFi under a real name.

That one identity anchor could make old logs searchable for the same auth_key_id.

The fix is simple - mandatory transport encryption for all MTProto connections, with no unencrypted fallback. Telegram chose not to do this.

Source: @kaepora symbolic.software/pdf/gnmx-01.pdf

P.s.: Long life, global passive observer
โค8๐Ÿ‘8๐Ÿ˜ญ4๐Ÿ‘3๐Ÿ”ฅ1๐Ÿ˜1
Awesome and memorable! Black and dirty smm in action.
๐Ÿคฃ97๐Ÿ˜4๐Ÿ˜ข2๐Ÿ™2โค1๐Ÿ‘Ž1
This media is not supported in your browser
VIEW IN TELEGRAM
Did you prepare yourself for it?
๐Ÿ‘พ55๐Ÿ˜4๐Ÿ‘1