Settings

Theme

Telegram leaks username in TLS header

twitter.com

45 points by ifqwz 3 years ago · 5 comments

Reader

BeefWellington 3 years ago

~~It's a false alarm from the thread.~~ See Below.

The link they're opening is a telegram vanity link that looks like:

    https://username.t.me
This then forwards to:

    https://t.me/username
This isn't Telegram, this is how TLS works.

Edit: Though, it's worth pointing out if this is how the official Telegram app works, and it loads this from your account and other users, it will leak not just your account but the other users you're browsing too. Not quite a false alarm if that's what the default app does, but other users are failing to reproduce in thread (I also don't see it).

  • Lockal 3 years ago

    So indeed, instead of using ESNI, Telegram is trying to hide yet another spy channel by using insecure addition to the TLS protocol.

  • WilTimSon 3 years ago

    > if this is how the official Telegram app works

    Doesn’t look like it. Both Telegram android and desktop are resolving the username links (in any format) using in-app logic for me.

rany_ 3 years ago

Telegram's response: https://twitter.com/telegram/status/1580564448011784194

stjohnswarts 3 years ago

Is this for Russian FSB monitoring? the post is very very low information. Who doesn't post how they got to seeing the leak in wireshark? Even twitter has enough characters for that.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection