Post B6R2Hg0nYHYtbOnhgG by rysiek@mstdn.social
(DIR) More posts by rysiek@mstdn.social
(DIR) Post #B6R2HfgEmj7CZdBHdI by rysiek@mstdn.social
0 likes, 1 repeats
Independent audit confirms my analysis of Telegram's protocol from last year:https://istories.media/en/stories/2026/05/18/independent-review-confirms-critical-telegram-vulnerability/The audit was ordered by one of the main characters of IStories' investigation into Telegram's network infrastructure, man called Vedeneev. My analysis was done in connection with that journalistic investigation.Presumably, Vedeneev ordered the audit in order to discredit my analysis and Istories' investigation. Instead, the report confirms my findings. :blobcatcoffee: #Telegram #InfoSec
(DIR) Post #B6R2Hg0nYHYtbOnhgG by rysiek@mstdn.social
0 likes, 0 repeats
You can find my original analysis here:https://rys.io/en/179.htmltl;dr: for every device, Telegram generates a long-term identifier, auth_key_id, that is then prepended *cleartext* (or at best, trivially obfuscated) to every encrypted packet; this allows anyone with sufficient visibility into global Telegram traffic to spy on its users.
(DIR) Post #B6R2HgIAVhSMTGvZku by rysiek@mstdn.social
0 likes, 0 repeats
And you can find IStories' reporting from last year here:https://istories.media/en/stories/2025/06/10/telegram-fsb/tl;dr Telegram seems to be using a single networking provider globally, and that provider seems to be connected to FSB.Which would provide the FSB just the kind of visibility into global Telegram traffic that would be needed to be able to spy on users using the long-term identifier.