Telegram leaks username in TLS header

by ifqwzon 10/13/2022, 11:10 AMwith 5 comments

by BeefWellingtonon 10/13/2022, 1:52 PM

~~It's a false alarm from the thread.~~ See Below.

The link they're opening is a telegram vanity link that looks like:

    https://username.t.me
This then forwards to:

    https://t.me/username
This isn't Telegram, this is how TLS works.

Edit: Though, it's worth pointing out if this is how the official Telegram app works, and it loads this from your account and other users, it will leak not just your account but the other users you're browsing too. Not quite a false alarm if that's what the default app does, but other users are failing to reproduce in thread (I also don't see it).

by rany_on 10/14/2022, 12:13 PM

Telegram's response: https://twitter.com/telegram/status/1580564448011784194

by stjohnswartson 10/13/2022, 1:27 PM

Is this for Russian FSB monitoring? the post is very very low information. Who doesn't post how they got to seeing the leak in wireshark? Even twitter has enough characters for that.