Following the news that Iranian security researchers finding vulnerability in Telegram’s SMS authentication.  Mark Loveless, Senior Security Researcher with Duo Labs commented below.

 Mark Loveless, Senior Security Researcher at Duo Labs:

“Reports suggest that the Telegram accounts in Iran were compromised through what appears to be coordination between attackers and cellphone companies, and taking advantage of the fact that SMS is used to add new devices to existing Telegram accounts. While this implies cooperation by the cellphone companies, this cooperation is often not required. Attackers have been known to social engineer cellphone companies to get the same level of “coordination” or use other more technical means to compromise SMS, leaving all applications that use security measures involving SMS to be vulnerable. This is exactly why NIST recommends against using SMS as a part of 2FA (Two Factor Authentication), and why we always encourage our customers to use the cryptographically secure Duo Push for 2FA.

This is still not an excuse for using a weak or even no password at all on Telegram accounts. Reducing one of your two factors for authentication reveals any weaknesses in the other factor. Always use strong and unique passwords on all accounts – but especially in cases where it is being used to protect secure communications. This also includes email accounts that are used for password recovery.”

Experts Comments

Stay Tuned! Our Information Security Experts Community is responding .....

Submit Your Expert Comments

What do you think of the topic? Do you agree with expert(s) or share your expert opinion below.
Be part of our growing Information Security Expert Community (1000+), please register here.

Write Your Expert Comments *
Your Registered Email *
Notification Email (If different from your registered email)
* By using this form you agree with the storage and handling of your data by this web site.