Telegram Feature Exposes Your Precise Address To Hackers (arstechnica.com) 45
Telegram has no plans to fix a vulnerability that makes it easy for hackers to find your precise location. The problem stems from a feature called People Nearby, which is disabled by default, but allows users who are geographically close to you to connect. Ars Technica reports: Independent researcher Ahmed Hassan, however, has shown how the feature can be abused to divulge exactly where you are. Using readily available software and a rooted Android device, he's able to spoof the location his device reports to Telegram servers. By using just three different locations and measuring the corresponding distance reported by People Nearby, he is able to pinpoint a user's precise location. Telegram lets users create local groups within a geographical area. Hassan said that scammers often spoof their location to crash such groups and then peddle fake bitcoin investments, hacking tools, stolen social security numbers, and other scams.
Telegram lets users create local groups within a geographical area. Hassan said that scammers often spoof their location to crash such groups and then peddle fake bitcoin investments, hacking tools, stolen social security numbers, and other scams. A proof-of-concept video the researcher sent to Telegram showed how he could discern the address of a People Nearby user when he used a free GPS spoofing app to make his phone report just three different locations. He then drew a circle around each of the three locations with a radius of the distance reported by Telegram. The user's precise location was where all three intersected.
In a blog post, Hassan included an email from Telegram in response to the report he had sent them. It noted that People Nearby isn't enabled by default and that "it's expected that determining the exact location is possible under certain conditions." People Nearby poses the biggest threat to people using Android devices, since they report a user's location with enough granularity to make Hassan's attack work. The recently released iOS 14, by contrast, allows users to divulge only a rough approximation of their location. People who use this feature aren't as exposed. Fixing the problem -- or at least making it much harder to exploit it -- wouldn't be hard from a technical perspective. Rounding locations to the nearest mile and adding some random bits generally suffices. When the Tinder app had a similar disclosure vulnerability, developers used this kind of technique to fix it.
Telegram lets users create local groups within a geographical area. Hassan said that scammers often spoof their location to crash such groups and then peddle fake bitcoin investments, hacking tools, stolen social security numbers, and other scams. A proof-of-concept video the researcher sent to Telegram showed how he could discern the address of a People Nearby user when he used a free GPS spoofing app to make his phone report just three different locations. He then drew a circle around each of the three locations with a radius of the distance reported by Telegram. The user's precise location was where all three intersected.
In a blog post, Hassan included an email from Telegram in response to the report he had sent them. It noted that People Nearby isn't enabled by default and that "it's expected that determining the exact location is possible under certain conditions." People Nearby poses the biggest threat to people using Android devices, since they report a user's location with enough granularity to make Hassan's attack work. The recently released iOS 14, by contrast, allows users to divulge only a rough approximation of their location. People who use this feature aren't as exposed. Fixing the problem -- or at least making it much harder to exploit it -- wouldn't be hard from a technical perspective. Rounding locations to the nearest mile and adding some random bits generally suffices. When the Tinder app had a similar disclosure vulnerability, developers used this kind of technique to fix it.
good old triangulation (Score:5, Insightful)
Re: (Score:2)
Yep.
If you're shocked that a "People Nearby" feature lets people find you then you need to reexamine your life choices.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Easy fix... (Score:3, Interesting)
Re: (Score:1)
Re: (Score:1)
Even easier fix: consider the implication of using a feature, and don't enable it unless you know what you're doing.
Re: Easy fix... (Score:2)
Re: Easy fix... (Score:2)
Re: (Score:2)
Compromised app is bad??? (Score:1)
Re: (Score:1)
What encryption? (Score:2)
Telegram uses no end-to-end encryption by default.
Last time I checked, you had to go into a special mode first. And that only worked if both sides were online. Meaning Telegram currently having an incoming port open. So, in practice, never. In there, it didn't keep a history, and messaging would not work if the other person wasn't online.
So painfully useless. Because the dev hasn't figured out how to safely keep a history and safely use a push server.
AFAIK, Moxie is the only one who figured out encrypted gr
Re: (Score:1)
Telegram has precisely jackshit to do with the Russian government, but nice try to spread FUD.
Re: Here is a hacking virus idea (Score:3)
And that'd be bad... how?
Signed,
all non-human life on Earth
What the hell is a 1 bit hole in encryption? (Score:2)
Could you be a bit more specific?
You sound like you're on drugs.
Whatever... (Score:4)
Must be a slow news day. In general, this is a very minor privacy issue compared to the other number of things slurping down everything on your mobile phone. This is a opt in privacy leak, let it be....
Re:Whatever... (Score:4, Interesting)
I think its a feature (Score:2)
Yet another Editor fail, do they even read, bro? (Score:2, Redundant)
...Telegram lets users create local groups within a geographical area. Hassan said that scammers often spoof their location to crash such groups and then peddle fake bitcoin investments, hacking tools, stolen social security numbers, and other scams.
Telegram lets users create local groups within a geographical area. Hassan said that scammers often spoof their location to crash such groups and then peddle fake bitcoin investments, hacking tools, stolen social security numbers, and other scams. ...
Location feature exposes your location! *SHOCK* (Score:4, Insightful)
It is LITERALLY DESIGNED to let people know where you are.
Re: (Score:3)
Re: (Score:2)
Not really. Anyone with a little bit of intelligence could find you without using the triangulation method, just would be a little more difficult.
Locks on doors are a measure to keep people out, but everyone is aware that they are very fallible to a person who wants to beat them. The same applies to locations. If you give someone a general idea of where you are, you have to reasonably expect they will be able to find you, if they try hard enough.
Re: Location feature exposes your location! *SHOCK (Score:2)
How would you know somebody is still inside the definition of "nearby" or not without their precise location?
If you think about it, it's just not actually possible to know the former without the latter, as all edge cases would become "not sure", and if you exclude them most people nearby would not be found, and if you include them, you'd also include more people not actually nearby than people nearby, due to simple geometry.
In any case, you would still know that people nearby are nearby. ("[Old redneck town
Re: (Score:2)
Who pays these security researchers (Score:1)
Re: Who pays these security researchers (Score:4, Funny)
Doesn't look like something that needs payment.
More like somebody did it in his free time.
Also, can you Ferengi literally only think in money?
Re: (Score:1)
Telegram is not a privacy-enabled messenger (Score:5, Interesting)
I repeat: Telegram is not a privacy-enabled messenger
It just gets confused for one.
The fact that you have to enable a special mode, to send end-to-end encrypted messages, says it all. It should not be possible to send unencrypted messages, unless you very specifically say so.
The fact that it's closed source, by itself, already maked that abundantly clear too. Might aswell use WhatsApp, and have FacebookNSA spy on you rather than TelegramFSB.
Just use Signal. The bots are not worth is.
Re: Telegram is not a privacy-enabled messenger (Score:2)
Re: Telegram is not a privacy-enabled messenger (Score:1)
why a rooted phone? (Score:2)
*facepalm* (Score:1)
Re: (Score:2)
Editors? What editors? (Score:2)
Quoting from the summary:
Hassan said that scammers often spoof their location to crash such groups and then peddle fake bitcoin investments, hacking tools, stolen social security numbers, and other scams.
Telegram lets users create local groups within a geographical area. Hassan said that scammers often spoof their location to crash such groups and then peddle fake bitcoin investments, hacking tools, stolen social security numbers, and other scams.
Do the "editors" even read the summaries anymore?