Operational Telegram โ€” Medium

thomwithoutanh's bookmarks 2016-08-10

Summary:

Telegram links an account to a telephone number. The messenger verifies that the phone number is accessible to the user when they register their account (via an authentication code sent over SMS, or via a call.) For an attacker with access to the telco systems (e.g. SS7 injection, or a national telephone operator) hijacking the verification code for the account is straightforward. Simply redirect the SMS/calls to the number to a location that is under attack control/visibility.

Link:

https://medium.com/@thegrugq/operational-telegram-cbbaadb9013a#.uk46vg5tf

From feeds:

Messaging Apps ยป thomwithoutanh's bookmarks

Tags:

telegram thegrucq

Date tagged:

08/10/2016, 06:26

Date published:

08/10/2016, 02:27