this post was submitted on 26 Sep 2023
168 points (91.6% liked)

Technology

58143 readers
5215 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] jet@hackertalks.com 18 points 11 months ago (12 children)

Telegram has open source their client code. Not their server code. It's even on f Droid.

[–] smileyhead@discuss.tchncs.de 9 points 11 months ago* (last edited 11 months ago) (8 children)

But it's starting to get worse. Now they won't send you an SMS code for registration unless you are using official build of the app. Even chat app under libre licence must connect with something...

[–] atkdef@lemmy.world 3 points 11 months ago (1 children)

This actually is not a bad thing. If an unofficial client MITM the whole registration process, it's much harder for the true account owner to prove that he/she is the legit one.

Also, it doesn't really require a client to register; Telegram can be accessed from a browser.

[–] smileyhead@discuss.tchncs.de 0 points 11 months ago (1 children)

If unofficial app can MITM registration, it can the same way MITM login later.

doesn't require a client A side note, JavaScript app in the browser is as much an app as Java/Kotlin on Android. But I know websites and web-based applications are now so mixed together it sometimes can confuse me too.

And browser version of Telegram does not allow registering new accounts also.

[–] atkdef@lemmy.world 1 points 11 months ago* (last edited 11 months ago) (1 children)

Compared to login, MITM on registration means the culprit knows the IP address and the time of the registration, which is usually significant on claiming the account back.

I don't have a spare number to test, but I'm pretty sure entering a phone number in the web sends a SMS code. Do you have concrete evidence that it really doesn't work?

[–] smileyhead@discuss.tchncs.de 1 points 11 months ago

Unfortunetly not, I must test it also.

load more comments (6 replies)
load more comments (9 replies)