Telegram has a security leak: uncovered passwords and documents
Telegram has a security leak: uncovered passwords and documents
The Telegram Passport app does not support cyber attacks
Earlier in the week, Telegram opted for a new Telegram X app to get around censorship and improve security on its platform, one of its strengths against its competitors. However, the application of the Durov brothers also has problems.
The development of Telegram Passport has opened a door to cyber attackers that allows access to passwords and official documents stored on the platform.
The vulnerability lies in the SHA-512 password protection system used by Telegram Passport, which uses an algorithm that is not intended for the storage of this type of keys and is vulnerable, as the cybersecurity company Virgil Security has warned through your web
On July 26, Telegram integrated in its application the new Passport tool, an authentication method for online services to which users can upload their official documents such as passports, driving licenses and bank details, and identify with them.
The developer of Telegram explained when announcing the function that protected the security of files and keys through end-to-end encryption mechanisms, also present in the messages of the app.
Passport uses a password as the only protection mechanism to identify itself in external services. Due to the encryption protocol used, cyber attackers can use high-performance graphics cards such as those used to mine cryptocurrencies to automatically generate combinations of random characters.
By means of this mechanism it is possible to find out any password of eight characters in length in 4.7 days. In this way, a brute-force attack could guess any Telegram Passport password with an electricity cost of between 5 and 135 dollars (from 4.3 to 116 euros, at the change), according to experts in cybersecurity.
Comments
Post a Comment