this post was submitted on 26 Mar 2024
282 points (94.6% liked)
Privacy
32130 readers
743 users here now
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
much thanks to @gary_host_laptop for the logo design :)
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
No jokes, I'd like to know. How is it different from sending sms to random numbers?
... people just send SMS to random phone numbers?
No but what exactly stops anyone from doing that? A privacy consideration? I'd think it's just a waste of time at best.
People don't need to get an sms from you to know your number works. There are tons of other ways including just trying to log in into telegram or Whatsapp with a list of many numbers.
The issue here is that you could potentially read the content of a 2FA sms that wasn't intended for you. It makes it easy too break 2FA if you have many devices
Logic suggests OTPs are locked to login sessions of corresponding users and also expire. Besides telegram would be able to tell if OTPs meant to be sent through you tend to not reach the recipients.
Yes but you can login on an account and hope you will be the one selected to send the code
You mean you can try to guess someone's number before they get an OTP through you in order to be the first to log into their account?
Well then you'll also going to need their cloud password in order to find anything worth of your effort.
But anyway this is an improbable scenario, considering how vast the user base is, and if we assume telegram implemented some precautions.
Malicious service providers and cloned sim cards pose a much more serious risk if you ask me.