this post was submitted on 20 Feb 2024
31 points (89.7% liked)

Privacy

30856 readers
828 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 4 years ago
MODERATORS
 

What do you think of this from privacy POV?

all 20 comments
sorted by: hot top controversial new old
[–] [email protected] 18 points 6 months ago (2 children)

Terrible, of course. Especially since they are aiming the service to improve sign-up reliability in countries that block telegram, acting as a relay exposes yourself. Carriers in China (where I live) and other questionable countries are actively snooping around, and since SMS are generally unencrypted, the simplest heuristic would figure out what you're involved in and start a very serious investigation.

On top of that, phone numbers in many countries are also unique logins to a number of services (again, here in China you need it for literally everything, it's THE number one digital footprint), and attackers could use the information for bruteforce/wordlist attacks on known services, or use them for social engineering.

As much as I like the idea of helping others sign up who don't have the means to acquire a foreign phone number, I would never willingly commit to that.

[–] [email protected] 6 points 6 months ago

There's some incredible insight here.

On top of that, phone numbers in many countries are also unique logins to a number of services (again, here in China you need it for literally everything, it's THE number one digital footprint)

This is one reason I particularly dislike companies that require phone number "verification" either immediately when registering, or sometime after. Services like Microsoft, Twitter, Discord, Facebook, all find a reason to request it at some point. And that request often seems to be related to whether or not they can pin down your actual identity or not...

[–] [email protected] 3 points 6 months ago* (last edited 6 months ago)

Especially since they are aiming the service to improve sign-up reliability in countries that block telegram

It's mainly to offload the cost of sending verification codes via sms to users, which is one of the costs that Telegram wants to cut. As far as I remember, it amounts to, like, 7% of all their annual expenses (I will source this later). A couple of years ago they decided not to send sms verification codes when you sign in from a third-party app, and just send the code to active session. This sounds like recipe for moderation headaches and privacy disasters, but also good way to boost their premium metrics :)

[–] [email protected] 17 points 6 months ago (1 children)

They could just stop requiring phone numbers, which would be a lot more privacy friendly.

[–] [email protected] 9 points 6 months ago (2 children)

But unfortunately it would make spamming much easier

[–] [email protected] 13 points 6 months ago

It's doing an absolutely terrible job of stopping spammers.

[–] Cheradenine 7 points 6 months ago

Isn't that an inherent fault of Telegram though?

I use SimpleX, and unless I join one of the large discussion groups there cannot be any spam. You cannot just join anything except open groups. If you spam you get booted by whoever started the group.

[–] [email protected] 5 points 6 months ago (1 children)

Can somebody explain in simple terms with this is even supposed to do? Do you end up sending an SMS message on Telegram's behalf to random phone numbers that request it?

I'm pretty sure this practice, no matter how lightweight it might be, would be considered against many carriers' TOS. And I wasn't aware Android now allowed people to send text messages in apps besides the default one, suppressing that ability was considered a huge deal a while back.

[–] [email protected] 7 points 6 months ago* (last edited 6 months ago)

For whatever reason, ppl need SMS OTP. While Telegram is using SMS operators (like Twilio), it can't covers all users globally (which the truth is more about cost and regulations), thus this program is born to cover (bypass) it.

It uses your number to sent the OTP code to random numbers on Telegram behalf, up to 150 per month including international SMS, where you bear the cost and aknowledging your number will be seen by who recieve it. In return, if your monthly send SMS reaches the quota, Telegram will reward you with a monthly Telegram Premium Subscription (which cost almost nothing to them).

What a joke program.

Edit: express in more clarity (they -> Telegram)

[–] [email protected] 5 points 6 months ago (1 children)

Crazy. Become a telegram sms relay.... Doesn't seem like a great idea for the user.

[–] [email protected] 0 points 6 months ago (2 children)

They are rewarding you with premium (i.e. some extra features in the app) for relaying sms and exposing your phonenumber to strangers ig?

[–] [email protected] 1 points 6 months ago* (last edited 6 months ago) (1 children)

For now... Giving this capability to a app seems foolish.

If you value premium enough, I'm sure lots of people will agree to it.

[–] [email protected] 3 points 6 months ago (1 children)

I think if its opt-in, then kinda fine..., else it's a nightmare.

[–] [email protected] 3 points 6 months ago

It's opt-in, of course

[–] southsamurai 3 points 6 months ago

At least it's opt in. But fucking hell, that's a horrible idea

[–] [email protected] 3 points 6 months ago

Such feature should never be in a consumer IMS because it can be activated accidentally. If you want to let your users become relays, do it at least like the registration for Ubuntu Pro