What do you think of this from privacy POV?

  • viking@infosec.pub
    link
    fedilink
    arrow-up
    20
    arrow-down
    2
    ·
    9 months ago

    Terrible, of course. Especially since they are aiming the service to improve sign-up reliability in countries that block telegram, acting as a relay exposes yourself. Carriers in China (where I live) and other questionable countries are actively snooping around, and since SMS are generally unencrypted, the simplest heuristic would figure out what you’re involved in and start a very serious investigation.

    On top of that, phone numbers in many countries are also unique logins to a number of services (again, here in China you need it for literally everything, it’s THE number one digital footprint), and attackers could use the information for bruteforce/wordlist attacks on known services, or use them for social engineering.

    As much as I like the idea of helping others sign up who don’t have the means to acquire a foreign phone number, I would never willingly commit to that.

    • LWD@lemm.ee
      link
      fedilink
      arrow-up
      6
      ·
      9 months ago

      There’s some incredible insight here.

      On top of that, phone numbers in many countries are also unique logins to a number of services (again, here in China you need it for literally everything, it’s THE number one digital footprint)

      This is one reason I particularly dislike companies that require phone number “verification” either immediately when registering, or sometime after. Services like Microsoft, Twitter, Discord, Facebook, all find a reason to request it at some point. And that request often seems to be related to whether or not they can pin down your actual identity or not…

    • riccardo@lemmy.ml
      link
      fedilink
      arrow-up
      3
      ·
      edit-2
      9 months ago

      Especially since they are aiming the service to improve sign-up reliability in countries that block telegram

      It’s mainly to offload the cost of sending verification codes via sms to users, which is one of the costs that Telegram wants to cut. As far as I remember, it amounts to, like, 7% of all their annual expenses (I will source this later). A couple of years ago they decided not to send sms verification codes when you sign in from a third-party app, and just send the code to active session. This sounds like recipe for moderation headaches and privacy disasters, but also good way to boost their premium metrics :)

      • Cheradenine
        link
        fedilink
        English
        arrow-up
        7
        ·
        9 months ago

        Isn’t that an inherent fault of Telegram though?

        I use SimpleX, and unless I join one of the large discussion groups there cannot be any spam. You cannot just join anything except open groups. If you spam you get booted by whoever started the group.

  • LWD@lemm.ee
    link
    fedilink
    arrow-up
    5
    ·
    9 months ago

    Can somebody explain in simple terms with this is even supposed to do? Do you end up sending an SMS message on Telegram’s behalf to random phone numbers that request it?

    I’m pretty sure this practice, no matter how lightweight it might be, would be considered against many carriers’ TOS. And I wasn’t aware Android now allowed people to send text messages in apps besides the default one, suppressing that ability was considered a huge deal a while back.

    • umami_wasabi@lemmy.ml
      link
      fedilink
      arrow-up
      7
      ·
      edit-2
      9 months ago

      For whatever reason, ppl need SMS OTP. While Telegram is using SMS operators (like Twilio), it can’t covers all users globally (which the truth is more about cost and regulations), thus this program is born to cover (bypass) it.

      It uses your number to sent the OTP code to random numbers on Telegram behalf, up to 150 per month including international SMS, where you bear the cost and aknowledging your number will be seen by who recieve it. In return, if your monthly send SMS reaches the quota, Telegram will reward you with a monthly Telegram Premium Subscription (which cost almost nothing to them).

      What a joke program.

      Edit: express in more clarity (they -> Telegram)

  • jet@hackertalks.com
    link
    fedilink
    English
    arrow-up
    5
    ·
    9 months ago

    Crazy. Become a telegram sms relay… Doesn’t seem like a great idea for the user.

    • Clot@lemm.eeOP
      link
      fedilink
      arrow-up
      3
      arrow-down
      3
      ·
      9 months ago

      They are rewarding you with premium (i.e. some extra features in the app) for relaying sms and exposing your phonenumber to strangers ig?

      • jet@hackertalks.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        9 months ago

        For now… Giving this capability to a app seems foolish.

        If you value premium enough, I’m sure lots of people will agree to it.

        • riccardo@lemmy.ml
          link
          fedilink
          arrow-up
          5
          ·
          9 months ago

          You can decide to send sms codes only within your country. You decide whether the tradeoff between costs, privacy and features is worth it. Sending 150 sms a month (or a magnitude more) would cost me 0 €. I find some of the premium features worth paying for. But I would never relay OTP codes for telegram

        • BearOfaTime@lemm.ee
          link
          fedilink
          arrow-up
          2
          arrow-down
          1
          ·
          9 months ago

          I send thousands of SMS per month with a cost of zero. Even international.

          It’s all included in my $40/mo plan.

  • GolfNovemberUniform@lemmy.ml
    link
    fedilink
    arrow-up
    3
    ·
    9 months ago

    Such feature should never be in a consumer IMS because it can be activated accidentally. If you want to let your users become relays, do it at least like the registration for Ubuntu Pro

  • southsamurai
    link
    fedilink
    arrow-up
    3
    ·
    9 months ago

    At least it’s opt in. But fucking hell, that’s a horrible idea