This is insane: TeleGuard, a 'secure' chat app downloaded more than a million times, uploads users' private keys, meaning the company can decrypt messages.
-
This is insane: TeleGuard, a 'secure' chat app downloaded more than a million times, uploads users' private keys, meaning the company can decrypt messages. And anyone can get anyone else's private key by just sending the user ID to the API. Possibly worst ever https://www.404media.co/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless/
-
This is insane: TeleGuard, a 'secure' chat app downloaded more than a million times, uploads users' private keys, meaning the company can decrypt messages. And anyone can get anyone else's private key by just sending the user ID to the API. Possibly worst ever https://www.404media.co/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless/
@josephcox this is so insane it almost feels like a honeypot setup by the police.
-
This is insane: TeleGuard, a 'secure' chat app downloaded more than a million times, uploads users' private keys, meaning the company can decrypt messages. And anyone can get anyone else's private key by just sending the user ID to the API. Possibly worst ever https://www.404media.co/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless/
@josephcox who wants to bet the words "vibe" and "coded" were involved?
-
@josephcox this is so insane it almost feels like a honeypot setup by the police.
As someone who looked at teleGuard and ALWAYS assumed honeypot. This fucking tracks.
-
This is insane: TeleGuard, a 'secure' chat app downloaded more than a million times, uploads users' private keys, meaning the company can decrypt messages. And anyone can get anyone else's private key by just sending the user ID to the API. Possibly worst ever https://www.404media.co/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless/
@josephcox Let me guess. It was vibe coded, right?
-
@josephcox Let me guess. It was vibe coded, right?
@Sempf @josephcox It launched in 2021, so perhaps a bit too soon for that.
-
R relay@relay.infosec.exchange shared this topic