Terms of Service for Telegram Peer-to-Peer Login Program
telegram.org
external-link
Users sign up and log in to Telegram by receiving a verification code (“OTP”) that is sent via SMS. These messages are sent…

What do you think of this from privacy POV?

southsamurai
link
fedilink
33M

At least it’s opt in. But fucking hell, that’s a horrible idea

@LWD@lemm.ee
link
fedilink
53M

removed by mod

umami_wasabi
link
fedilink
7
edit-2
3M

For whatever reason, ppl need SMS OTP. While Telegram is using SMS operators (like Twilio), it can’t covers all users globally (which the truth is more about cost and regulations), thus this program is born to cover (bypass) it.

It uses your number to sent the OTP code to random numbers on Telegram behalf, up to 150 per month including international SMS, where you bear the cost and aknowledging your number will be seen by who recieve it. In return, if your monthly send SMS reaches the quota, Telegram will reward you with a monthly Telegram Premium Subscription (which cost almost nothing to them).

What a joke program.

Edit: express in more clarity (they -> Telegram)

Such feature should never be in a consumer IMS because it can be activated accidentally. If you want to let your users become relays, do it at least like the registration for Ubuntu Pro

They could just stop requiring phone numbers, which would be a lot more privacy friendly.

But unfortunately it would make spamming much easier

Isn’t that an inherent fault of Telegram though?

I use SimpleX, and unless I join one of the large discussion groups there cannot be any spam. You cannot just join anything except open groups. If you spam you get booted by whoever started the group.

It’s doing an absolutely terrible job of stopping spammers.

Terrible, of course. Especially since they are aiming the service to improve sign-up reliability in countries that block telegram, acting as a relay exposes yourself. Carriers in China (where I live) and other questionable countries are actively snooping around, and since SMS are generally unencrypted, the simplest heuristic would figure out what you’re involved in and start a very serious investigation.

On top of that, phone numbers in many countries are also unique logins to a number of services (again, here in China you need it for literally everything, it’s THE number one digital footprint), and attackers could use the information for bruteforce/wordlist attacks on known services, or use them for social engineering.

As much as I like the idea of helping others sign up who don’t have the means to acquire a foreign phone number, I would never willingly commit to that.

@LWD@lemm.ee
link
fedilink
63M

removed by mod

riccardo
link
fedilink
2
edit-2
3M

Especially since they are aiming the service to improve sign-up reliability in countries that block telegram

It’s mainly to offload the cost of sending verification codes via sms to users, which is one of the costs that Telegram wants to cut. As far as I remember, it amounts to, like, 7% of all their annual expenses (I will source this later). A couple of years ago they decided not to send sms verification codes when you sign in from a third-party app, and just send the code to active session. This sounds like recipe for moderation headaches and privacy disasters, but also good way to boost their premium metrics :)

Crazy. Become a telegram sms relay… Doesn’t seem like a great idea for the user.

Clot
creator
link
fedilink
03M

They are rewarding you with premium (i.e. some extra features in the app) for relaying sms and exposing your phonenumber to strangers ig?

deleted by creator

I send thousands of SMS per month with a cost of zero. Even international.

It’s all included in my $40/mo plan.

deleted by creator

riccardo
link
fedilink
53M

You can decide to send sms codes only within your country. You decide whether the tradeoff between costs, privacy and features is worth it. Sending 150 sms a month (or a magnitude more) would cost me 0 €. I find some of the premium features worth paying for. But I would never relay OTP codes for telegram

@jet@hackertalks.com
link
fedilink
1
edit-2
3M

For now… Giving this capability to a app seems foolish.

If you value premium enough, I’m sure lots of people will agree to it.

Clot
creator
link
fedilink
33M

I think if its opt-in, then kinda fine…, else it’s a nightmare.

riccardo
link
fedilink
33M

It’s opt-in, of course

Opt-in for the SMS recipient too?

riccardo
link
fedilink
23M

I’m still trying to figure it out, but I guess not. The only thing I’m sure about is that you will know whether the OTP code has been sent by Telegram or a P2PL relay

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 84 users / day
  • 537 users / week
  • 1.5K users / month
  • 6.58K users / 6 months
  • 1 subscriber
  • 2.31K Posts
  • 53.4K Comments
  • Modlog