Hacker News new | ask | show | jobs
by upofadown 1799 days ago
I am not sure that the user would enjoy waiting x days for message delivery to start again. Perhaps a late message is never delivered to prevent it from being out of order? I guess my problem is understanding exactly what we are trying to prevent in practice.
1 comments

As far as I can understand it (and here the authors clearly state that a lot of this is hypothetically possible, darn near impossible in reality to pull off <<Note: Not Impossible to do>>

So - in a theoretical situation you are looking at what is known as a re-play attack.

Ping the same message to all cell numbers in a block (discovering who does and does not have Telegram installed)

Once you have that, ping a message to a group of interest that has an invite only policy.

Ping that message to all in that group of numbers to see who has read/received that message. You now have a list of active in that group list of numbers.

Once you have that - delay some messages so they appear out of order to some (but not all) users in that group.

Create FUD re security (omg, did we just get hacked??? Coz messages are turning up crazy out of order aka WTF?)

Target group falls back to fall-back comms method.

Profit.