<- Back
Comments (236)
- farhanhubbleI once read The Bugs We Have to Kill: https://www.usenix.org/publications/login/aug15/bratus and one particular thing that has stuck with me forever:“Any sufficiently complex input format is indistinguishable from bytecode; the code receiving it is indistinguishable from a vir- tual machine.”
- bita_nidirRelated: could we please stop, by default, allowing software to: a) access all your files, and b) roam the internet at will. That was somewhat OK in the 80s, but it hasn't been since.
- crossroadsguyOne of the challenges with Telegram is - they regularly re-enable settings inside the app/account that you had specifically disabled. So at any point you don't know what is happening and what is not. Meaning, even if you didn't see a thing, a malicious file might be sitting all warm and fuzzy on your computer - among possible other things. I used to like the snappiness of this app (and it is still snappier than almost all other IM apps combined, by a margin), but after a while I realised it was a ticking time-bomb (to keep it installed on the desktop) and possibly a scammer safe haven, nothing else.
- SpacePortKnightI think it is one of the reasons why I am always hesitant to install any software on my windows pc. Web versions are often more than good enough.
- usr1106I don't use Telegram Desktop or Windows. But that's exactly the reason why I run Firefox in a firejail sandbox on Linux. The browser has only access to my Downloads folder. I know that it's considered untrusted and don't keep any files there for a long time.
- KinranyWhen criticizing Telegram, I wish people focused on the actual smoking guns and didn't include random fluff one has to cut through.As a Telegram user, my current impression of the platform is that they are a tiny elite team, they focus very heavily on creating a polished product, and are somewhat arrogant about all of that.The most common criticism that I see and understand is the lack of E2EE by default. But I'm not aware of a messenger that provides a good UX for that. For most people, losing access to the account is a much greater risk. (The trade-off has changed somewhat now that everyone is getting hacked by AI and thus Telegram's whole dataset leaking becomes a concern.)The criticism that I agree the most with is phone numbers being used for authentication. Even if Telegram still wants to know everyone's phone numbers for growth reasons, as far as I'm aware for authn phone numbers are strictly worse than emails.On the positive side, they still have a proper API, open source their clients and allow third-party clients. All of which seem non-optional for any messenger that claims to prioritize security.
- NarushiaIt's great that this writeup was published, but unfortunately the text is full of claudisms and made me close the tab pretty quickly.
- PanzerschrekIt's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file. Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory (like downloads for a browser or Telegram-client).
- robertlane0Telegram and security don't really belong in the same sentence anyways. Say what you will about Signal but they at least have better cryptography and more transparency about what software they're running.
- RachelFIt looks very bad that Telegram took almost 3 months to fix this vulnerability.Reported 25 JuneFixed 16 SeptemberI wonder why it took them so long?
- erelongI thought telegram was flagged as insecure like a decade ago, it's never really been "very secure"Like any number of articles like this: https://hackernoon.com/7-reason-why-telegram-is-insecure-by-...
- itsmeduncanI wonder how much of Apple's announcement around disallowing full system disk access was from this as opposed to Muse, et al.
- wrcoroDoes its official desktop client support "Secret Chats" (E2EE) yet? Last time I used Telegram before moving to more reliable IM platforms that feature was officially unsupported on desktop and there was even some community effort¹ to make a pull request with paid contributions totally ignored by Pavel Durov and his team[1] https://github.com/marcovelon/tdesktop/blob/NoSecretChats/RE...
- Cider9986Telegram is worse than WhatsApp. No E2EE by default in 2026 is insane and Telegram's marketing is so deceptive.
- g-b-rThis link has already been posted with https://news.ycombinator.com/item?id=50019667 , but that post's title ("Telegram Desktop: one-click account takeover") doesn't say that the vulnerability allowed also any user-accessible file on the disk to be stolen.This aspect is also not highlighted much in the article, which weirdly mostly focuses on the account takeover.To me it seems something remarkable enough to warrant reposting the link with a different title.Somewhat astonishingly, the core of the vulnerability comes from an internal url scheme added to Telegram to... help them publish their releases on their channel.The Telegram developers saw no better way to do that than adding an internal tool which uploads any file it's told to.Everyone else publishing their app on Telegram is able to do that with a script, but they had to do it that way.It's true that it was exploitable only in a somewhat convoluted way, but still, it's an obviously dangerous feature.Anyhow, yes, clicking on a link in Telegram Desktop was enough to have any user's file exfiltrated and to access or take over their account.
- skeledrewThis is really good to know. Telegram is my primary means of communication, and a bunch of other things, and even though I'm not exactly exposed (I have password set, and only a few people can yank me into a group), I'm running a bit of a custom-method install that I don't update much.
- sehwI use Signal btw.
- opengrassdoas jexec -U opengrass tellyjail env DISPLAY=:0 Telegram
- anonundefined
- anon_cow1111Imagine if you forgot to update your phone number with your personal bank, and then some random guy was given full access to your account and all of its contents. And even if you dug through the account options and set a 2FA password (normally disabled) he could still just delete your account outright.Last I checked, that's exactly how Telegram works by default. It's laughable to consider a service tied to a phone number secure.
- syngrog66if the user values security and privacy would not be using Telegram
- KingOfCodersIt's not a bug it's a feature.
- buckle8017I am shocked......
- ramesh31I mean it's pretty obvious these things (Signal, et. al) are just honeypots for the three letter agencies, right?
- colordropswell duh
- bibhashBFP[flagged]
- bibhashBFP[flagged]
- GreenLightGo[dead]
- hulitu> Telegram Desktop vulnerability allowed any user's file to be stolenWait till they find out about web browsers. /s
- bashtoniRussian social media app has backdoor. Who would have thought?(Yes, I know they're technically Dubai based now)
- seeknotfindWow, that's pretty bad, but imagine if 50% of software allowed this to happen at any time, and it was discovered on December 1st, 2026. What would happen?