Telegram Geeks
23.5K subscribers
556 photos
5 videos
3 files
346 links
🚀 Join the Telegram Army!
______________________

🌐 telegramgeeks.com
👨‍👩‍👦‍👦 @geeksChat
Download Telegram
✳️ TELEGRAM | SECURITY ✳️

▶️ Security researchers have found a vulnerability that could allow attackers to send massive messages on Telegram bypassing its limitations.

Due to a programming error, a sender can gain control of the size of messages and send them with arbitrary length: Ghaf and his fellow researchers were able to send a message with 30000 bytes, exceeding the 4096 byte limit, and another which was empty breaching the one byte minimum.

You can see the Proof of Concept messages at @poc_sadghaf channel: That includes the 30000 bytes long text message and a second one empty.

🎥 Youtube: Proof of Concept
💡 Original Source: Sad Ghaf Security Team

#security #telegram #researchers #vulnerability

ℹ️ @geeksChannel
Pavel Durov's answer to the vulnerability:

They started talking about it (the vulnerability) recently after being quiet for some time, but couldn't show any proofs or something that confirms vulnerability.

There has always been server restriction for sent messages. Their outcoming message looked big only because their client app showed it that way. If you look at it in another app, both sender and recipient will see this message cut.

They though that they were sending megabytes.
When in reality they found a way to send 35 KB instead of 16 KB which didn't affect anything. (You cannot really overload anything this way).

Our two cents: Seems that Sad Ghaf Security Team never sent more proofs to Telegram. We tried to reach them via Telegram but we got no answer...

🇷🇺 Answer in russian (from vc.ru)
🌐 Google Translate version
UX (User Experience) would be even better with this little improvements

ℹ️ @geeksChannel
It's Telegram's birthday today

The iPhone app hit the store exactly three years ago: August 14, 2013.

ℹ️ @geeksChannel
💡 How old is Telegram?

Telegram for iOS was launched on August 14, 2013. The alpha version of Telegram for Android officially launched on October 20, 2013. More and more Telegram clients appear, built by independent developers using Telegram's open platform.

ℹ️ @geeksChannel
Congrats! 😎

ℹ️ @geeksChannel
Yesterday, many users complained about lots of accounts (without alias and named '0_0 8_8') joining public groups in order to collect data.
Crawling Telegram channels/groups and collecting public data is not so difficult due to the open ecosystem of Telegram: Anyone can run their own modified tg-cli.

Telegram needs to think about this, a fix could be something like the websites' robots.txt: An option to disallow crawler robots on the channel or group. But this will only work when good-intentioned developers flag their accounts as crawlers.

Another solution could be allowing the community to have an option to flag or report crawlers.

Maybe this little crawlers and robots are not going to hurt us right now, but how can we sure that the NSA, other agencies or corporations will not try to collect public communications and users data in order to log everything?

#crawlers #privacy

ℹ️ @geeksChannel
We want to share with you this interesting text wrote by Jochem (a member of @geeksChat):

When you join a public group and post there: keep in mind that anyone can read this, even without joining the group. There is a minimal expectation of privacy in public groups, as they are essentially open to the outside world (this even includes scary entities like the NSA, because they also live on our planet).

The openness of Telegram's clients and API allows anyone to write a third-party tool to download and store chat history of any public and private groups they can access. While private groups are usually not accessible to anyone without an invite or invite link, public groups can be crawled easily without anyone noticing.

This does not mean the NSA is spying on Telegram users, and all anyone potentionally could see are: Your profile pictures; Your first and last name; The messages you and others posted in public groups. Private groups and chats are safe as always, as long as invite links are kept private. Secret chats can't be touched by crawlers.

#privacy #crawlers
France & Germany seek to force WhatsApp & Telegram to unlock encrypted messages

France and Germany this week called on the European Union to adopt a law that would require app companies to make encrypted messages available to law enforcement, as part of Europe's ongoing efforts to thwart terrorist attacks.

Sources: RT - Independent - The Verge

#privacy #encryption #telegram #security

ℹ️ @geeksChannel
✳️ WHATSAPP | PRIVACY ✳️


Facebook to start using WhatsApp data for targeted advertising

WhatsApp will also explore ways for businesses to send messages using its platform over the next several months, it said in a blog post.

Source: Reuters

#privacy #whatsapp #facebook

ℹ️ @geeksChannel
✳️ WHATSAPP | BUSINESS ✳️

businesses are coming to WhatsApp, take a look at this words from WhatsApp's blog:

But as we announced earlier this year, we want to explore ways for you to communicate with businesses that matter to you too, while still giving you an experience without third-party banner ads and spam. Whether it's hearing from your bank about a potentially fraudulent transaction, or getting notified by an airline about a delayed flight, many of us get this information elsewhere, including in text messages and phone calls. We want to test these features in the next several months.


#whatsapp #business

ℹ️ @geeksChannel
how Facebook tracks you across the web


Change these settings to stop Facebook tracking:
zdnet.com/article/to-stop-facebook-tracking-you-across-the-web-change-these-settings/
Time to move to Telegram 😎

ℹ️ @geeksChannel
Did you know how Telegram decide name's color on chats?

ℹ️ @geeksChannel
✳️ TELEGRAM | TIP ✳️

Color generation of Display Names

Telegram apps have a fixed set of colors. App is choosing the color based on the chatid and the userid. On Github you can see that e.g. our Android version has 8 fixed colors. So it could be that the name of the contact appears red in group chat A and in the group B in blue.

#tip #telegram #color #names
WhatsApp will add an official chat (with a verified check) to notify new changes to users.

Channels coming to WhatsApp? 😶

ℹ️ @geeksChannel