This media is not supported in your browser
VIEW IN TELEGRAM
๐43โค8 8๐ฅ2๐2๐ค1๐คก1๐ค1
Where is it?
๐28๐ฅ13๐10โค7๐6โคโ๐ฅ5๐ข5๐คฎ2๐คก1๐คฃ1๐ญ1
Cognitum
Cognitum.One โ Intelligence for the Real World
๐15โค10๐ฅ7๐6๐6๐ข5๐2๐ฏ2 1
Telegram does not need to have its message encryption broken for users to be tracked at the network layer.
Telegram sends MTProto over unencrypted TCP, exposing auth_key_id - a long-lived identifier tied to the clientโs authorisation key. An ISP, hotel WiFi operator, mobile carrier, transit provider, or surveillance system on the network path can see that identifier if they can observe the traffic. It can remain stable across app restarts, IP changes, VPN use, network switches, and location changes.
Secret Chats protect message content, but this leak is below that layer. That makes the attack passive.
The risk is in retroactive correlation. Think a journalist using Telegram from different networks for months, then joining hotel or corporate WiFi under a real name.
That one identity anchor could make old logs searchable for the same auth_key_id.
The fix is simple - mandatory transport encryption for all MTProto connections, with no unencrypted fallback. Telegram chose not to do this.
Source: @kaepora symbolic.software/pdf/gnmx-01.pdf
P.s.: Long life, global passive observer
Telegram sends MTProto over unencrypted TCP, exposing auth_key_id - a long-lived identifier tied to the clientโs authorisation key. An ISP, hotel WiFi operator, mobile carrier, transit provider, or surveillance system on the network path can see that identifier if they can observe the traffic. It can remain stable across app restarts, IP changes, VPN use, network switches, and location changes.
Secret Chats protect message content, but this leak is below that layer. That makes the attack passive.
The risk is in retroactive correlation. Think a journalist using Telegram from different networks for months, then joining hotel or corporate WiFi under a real name.
That one identity anchor could make old logs searchable for the same auth_key_id.
The fix is simple - mandatory transport encryption for all MTProto connections, with no unencrypted fallback. Telegram chose not to do this.
Source: @kaepora symbolic.software/pdf/gnmx-01.pdf
P.s.: Long life, global passive observer
โค13๐11๐7๐ฅ4๐ญ4๐2๐2๐2๐ข1๐คฎ1
This media is not supported in your browser
VIEW IN TELEGRAM
Did you prepare yourself for it?
๐13 7๐6๐5๐พ5โค4๐4๐4๐ฅ3๐ข3๐ญ1
Following a NYT report that the US and Israel discussed a potential post-war role for Mahmoud Ahmadinejad, some Iranian hardliners began accusing the former president of being an Israeli asset, despite no public evidence supporting the claim.
(Source: https://www.nytimes.com/2026/05/19/us/politics/iran-israel-us-leader-ahmadinejad.html)
(Source: https://www.nytimes.com/2026/05/19/us/politics/iran-israel-us-leader-ahmadinejad.html)
Nytimes
Early War Goal Was to Install Hard-Line Former President as Iranโs Leader
An Israeli strike designed to free Mahmoud Ahmadinejad from house arrest in Tehran, U.S. officials said, was part of an effort to bring about regime change and put him in power.
โค12๐7๐6 5๐ข3๐ฅ2๐2๐2๐2๐ค1๐ญ1
This media is not supported in your browser
VIEW IN TELEGRAM
๐8๐5๐ฅ4โค2โก1๐ค1๐คฉ1๐1๐ฏ1 1