Telegram is privacy nightmare (personal number leak and OTP hijack)

I’m one, even though I cost them nothing SMS wise because I’m always signed in elsewhere. I know for sure they won’t accept a SimpleLogin address (don’t know whether they do an MX lookup or just block shared SL domains). I understand why they do it, it’s expensive, but their hostility toward users has become palpable lately.

I know someone who used SL. They received the code, but the code is not accepted when they enter it. It says “wrong email”. That makes zero sense. If Telegram is not going to accept an email address, why send the code to them? When a website blocks a domain, it will not let you receive any emails at that domain. That is not how Telegram’s SMS verification works, though.

I also know someone who used a mainstream email provider and still their code was rejected. Their system is really crap.

Lastly, I get that registration fees are expensive, but the fact remains, Signal doesn’t charge their uses for it. Moreover, Telegram has the option to verify your account via 2FA password for existing users. They could also not require phone numbers.

There are plenty of clever ways around it. It’s mostly just a way to get more users to sign up for their Premium plan, I guess. They’ve had perpetually broken OTP code flows for as long as I can remember, so I don’t think it’s malicious. They’re just big and don’t care.

1 Like

Wow. If Signal found an innovative way to make it work, then yeah, this reaffirms that Telegram really doesn’t care.

Curious to find out if the new passkey integration allows users to log into second devices without SMS verification. If not, then this makes then passkeys make little difference for privacy as far as I’m concerned, especially when you consider that Telegram now charges many countries for SMS verification, and that that verification system, whch is P2P, is a privacy and security nightmare.