Hacker News new | ask | show | jobs
by PlasticTank 2336 days ago
I don't know of any directly related to it's encryption but multiple protest organizers were identified and arrested by the Hong Kong Police Force through Telegram, I'm not 100% sure but I believe they just added lists of suspected phone numbers onto their phones and looked in Telegram see which one's matched to Group admins.
3 comments

What happened in Hong Kong was that the authorities created Telegram accounts and added thousands of phone numbers to their contact lists. From that, they got to know which numbers are using Telegram and then were able to do some more tracing. This flaw exists in WhatsApp and Signal too, where anyone who has your number in their contacts list (though you may not have their number in your contacts) will know the moment you join those platforms and will be able to see you on it.

When this design flaw came to be known, Telegram released a newer version where the user has more control on who can know that they're on Telegram. With that change, even if you had someone's number in your contacts list, you wouldn't know if/when they join/are available on Telegram unless they choose to make themselves visible.

That theory is quite possible. If the police join the group, they know the usernames of all of the people in the group, they can then start adding numbers to their contacts and if any of the usernames from the group show up they can then look up who owns the phone number in the government database.
It surprises me that they don't require both of you to have each others phone numbers in your contacts lists before giving away identifiable information.
Telegram released a new version with that exact same requirement to enable visibility. The settings in Telegram have also been expanded for this. On the other hand, this same vulnerability exists (and continues to exist) in WhatsApp and Signal.
There were also claims of android keyboardd being used to log messages on Signal (and maybe Telegram), by Naomi Wu and others. No proof for this though.