1 min read

Telegram not really anonymous? Researcher reports bug that leaks IP addresses

Luana PASCU

October 01, 2018

Telegram not really anonymous? Researcher reports bug that leaks IP addresses

Encrypted messaging app Telegram is dealing with a major anonymity fail possibly affecting their brand reputation and customer trust. Last week, security researcher Dhiraj Mishra detected some vulnerabilities in the Telegram desktop application and Telegram for Windows that leaked both public and private IP addresses online during voice calls, revealing user location.

Telegram normally asks users to use peer-to-peer (P2P) connection, setting that can be changed from settings to keep it private. However, this option was not available in the desktop and Windows applications. A later edit reads that even the Android application will leak addresses, unless the settings are changed.

Source: Dhiraj Mishra

For detecting and reporting the bug, the researcher received €2,000 from Telegram. The bug was patched immediately in all Telegram versions. Users can now disable peer-to-peer calling by accessing settings > Privacy and security > Calls > peer-to-peer, and are advised to update their apps as soon as possible.

Since the company has been boasting about its end-to-end encryption and fighting governments” requests to release user data in the first place, this could be a blow to their image. In the past, countries such as Iran demanded the app be blocked accusing it was a security threat, while Russia asked for user data and then tried to block the app when their request was denied.

tags


Author



Right now

Top posts

Watch Out for These Ongoing Bank of America Phishing Campaigns Targeting Customers in the US

Watch Out for These Ongoing Bank of America Phishing Campaigns Targeting Customers in the US

July 16, 2021

3 min read
How to protect yourself against cyberstalking

How to protect yourself against cyberstalking

July 06, 2021

2 min read
The Top Five Security Risks Smartphone Users Face Today

The Top Five Security Risks Smartphone Users Face Today

July 02, 2021

4 min read
Phishing Alert: Scammers Use Fake SharePoint and DocuSign Messages to Steal Users’ Login Credentials

Phishing Alert: Scammers Use Fake SharePoint and DocuSign Messages to Steal Users’ Login Credentials

July 02, 2021

3 min read
Your Doxxing Dossier Will Keep Growing Thicker Until You See the Danger

Your Doxxing Dossier Will Keep Growing Thicker Until You See the Danger

June 30, 2021

2 min read
Mobile security threats: reality or myth?

Mobile security threats: reality or myth?

June 13, 2021

3 min read

FOLLOW US ON

SOCIAL MEDIA


You might also like

Fraud Family cybercrime ring under the spotlight as arrests made in the Netherlands Fraud Family cybercrime ring under the spotlight as arrests made in the Netherlands
Graham CLULEY

July 23, 2021

3 min read
Homoglyph domains used in BEC scams shut down by Microsoft Homoglyph domains used in BEC scams shut down by Microsoft
Graham CLULEY

July 22, 2021

3 min read
China Sets Up New Worrying Vulnerability Disclosure Rules China Sets Up New Worrying Vulnerability Disclosure Rules
Silviu STAHIE

July 20, 2021

1 min read