|
|
|
|
|
by mr_mitm
658 days ago
|
|
Yes. An employee can impersonate a user by registering a device in their name and intercepting the confirmation code and then read all non secret chats and private groups of that user. At least one employee must have the ability to intercept the code. (Unless the user has 2fa enabled, but that is not the default configuration.) There are probably easier ways if we knew more about how the administrate their infrastructure. |
|
However I think the real question is: even if that's possible, can law enforcement compel Durov or an employee to do so?