Telegram is still leaking user IP addresses to contacts | TechCrunch
techcrunch.com
external-link
A security researcher has created a tool that allows someone to find out the IP address of a Telegram contact just by calling them.
Clot
link
fedilink
18M

The way they try to defame telegram lmao

Skull giver
link
fedilink
19
edit-2
7M

[This comment has been deleted by an automated system]

@ink@r.nf
link
fedilink
188M

Telegram not being part of Western Intelligence Toolkit along with facebook, google, apple and others offends people to the extreme, so they make a hill out of moles. P2P is inherently privacy friendly and your IP is most likely going to geolocate to the ISP. Techcrunch seems retarded.

But do keep up the fearmongering going.

Leaking ip’s is meh, however sharing info with feds while mentioning not doing this very thing in their own FAQ is shady AF. Then we have their serverside being proprietary garbage, plus intrusive info collection (like why do they need no know my hostname, device model, desktop environment, etc?). Did I mentioned they started advertising crap based on the channels a user’s subscribed to? Yeah, telegram still sucks when it comes to privacy, and it’s only getting worse over time

Skull giver
link
fedilink
0
edit-2
7M

[This comment has been deleted by an automated system]

Ohh no, Someone on the Internet that I’m communicating with has access to a piece of information that is necessary for communicating with me.

@whale@lemm.ee
link
fedilink
8
edit-2
8M

deleted by creator

Mubelotix
link
fedilink
18M

But I could include an image in this message and get your IP address easily. It’s just worthless

@whale@lemm.ee
link
fedilink
1
edit-2
8M

deleted by creator

Should have used the word direct, but their point stands.

@whale@lemm.ee
link
fedilink
-2
edit-2
8M

deleted by creator

We’re not directly communicating. A phone call over IP is direct.

@whale@lemm.ee
link
fedilink
0
edit-2
8M

deleted by creator

Is it a leak if it’s a necessary technical part to a functionality?

The main issue is that it’s not obvious to non-technical users. They can’t asses what sharing IP address means either though.

The reason Telegram leaks a user’s IP addresses during a call is that, by default, Telegram uses a peer-to-peer connection between callers “for better quality and reduced latency,” Telegram spokesperson Remi Vaughn told TechCrunch.

“The downside of this is that it necessitates that both sides know the IP address of the other (since it is a direct connection). Unlike on other messengers, calls from those who are not your contact list will be routed through Telegram’s servers to obscure that,” Vaughn said.

To avoid leaking your IP address, you have to go to Telegram’s Settings > Privacy and Security > Calls, and then select “Never” in the Peer-to-Peer menu, as shown below.

Telegram defaults to using p2p for calls, for contacts only.

It’s not a thorough privacy default, but otherwise seems fine to me. If you want p2p it needs to be enabled, and if you don’t it needs to be disabled. No-contacts and no-calls receive no IP.

Here’s a professional security researcher/pentester explaining in depth why “leaking” IP is blown out of proportion

The relevant gist is

  1. The information is usually not identifying beyond general geographic regions (at best)
  2. if your threat model is that strict, there are other ways you should be obfuscating your IP than relying on VPNs, ISPs, and the apps/servers you’re accessing/using.
poVoq
link
fedilink
38M

Usually it is the town, or nearby town. If you live in a more rural area that can narrow it down to a few hundred people.

Also in some less-developed countries the data protection by ISPs is very weak. Basically if you know someone in the police (or pay a bit under the table) you can easy get the exact name and address of the account owner if you have an IP.

@PipedLinkBot@feddit.rocks
bot account
link
fedilink
38M

Here is an alternative Piped link(s):

Here’s a professional security researcher/pentester explaining in depth why “leaking” IP is blown out of proportion

Piped is a privacy-respecting open-source alternative frontend to YouTube.

I’m open-source; check me out at GitHub.

@whale@lemm.ee
link
fedilink
2
edit-2
8M

deleted by creator

I agree. This requires the user to actually save the attacker phone number as contact in order for this the IP address to “leak”

There’s still a chance that your contacts would have been hacked, and one could be vulnerable. But it all comes back to your risk profile. If you require hiding your IP address, you should turn this off or even use a VPN for all your traffic.

Thanks for this, I was unaware.

Calls turned off completely now.

AutoTL;DR
bot account
link
fedilink
78M

This is the best summary I could come up with:


The popular messaging app Telegram can leak your IP address if you simply add a hacker to your contacts and accept a phone call from them.

TechCrunch verified the researcher’s findings by adding Simonov to the contacts of a newly created Telegram account.

Simonov then called the account, and shortly after provided TechCrunch with the IP address of the computer where the experiment was being carried out.

The fact that Telegram leaks your IP address to people in your contacts during a voice call has been known for years, but it’s likely that new, less technical users may not be aware.

Simonov, who founded the cybersecurity firm T.Hunter, told TechCrunch: “Telegram focuses on security and privacy, however, in order to stay safe you need to be aware of the nuances of how the messenger’s voice calls work.”

To avoid leaking your IP address, you have to go to Telegram’s Settings > Privacy and Security > Calls, and then select “Never” in the Peer-to-Peer menu, as shown below.


The original article contains 414 words, the summary contains 167 words. Saved 60%. I’m a bot and I’m open source!

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 57 users / day
  • 383 users / week
  • 1.5K users / month
  • 5.7K users / 6 months
  • 1 subscriber
  • 2.43K Posts
  • 57.3K Comments
  • Modlog