Adventures in Dystopia
1.92K subscribers
514 photos
50 videos
7 files
287 links
Download Telegram
๐Ÿ‘15โค10๐Ÿ”ฅ7๐Ÿ‘6๐Ÿ™6๐Ÿ˜ข5๐Ÿ’ฏ2๐ŸŽ‰11
๐Ÿ‘16โค5๐Ÿคฃ44๐Ÿ”ฅ3๐Ÿ‘2๐Ÿ˜2๐Ÿ™2๐Ÿ‘Ž1๐Ÿคฎ1๐Ÿคก1
Telegram does not need to have its message encryption broken for users to be tracked at the network layer.

Telegram sends MTProto over unencrypted TCP, exposing auth_key_id - a long-lived identifier tied to the clientโ€™s authorisation key. An ISP, hotel WiFi operator, mobile carrier, transit provider, or surveillance system on the network path can see that identifier if they can observe the traffic. It can remain stable across app restarts, IP changes, VPN use, network switches, and location changes.

Secret Chats protect message content, but this leak is below that layer. That makes the attack passive.

The risk is in retroactive correlation. Think a journalist using Telegram from different networks for months, then joining hotel or corporate WiFi under a real name.

That one identity anchor could make old logs searchable for the same auth_key_id.

The fix is simple - mandatory transport encryption for all MTProto connections, with no unencrypted fallback. Telegram chose not to do this.

Source: @kaepora symbolic.software/pdf/gnmx-01.pdf

P.s.: Long life, global passive observer
โค13๐Ÿ‘11๐Ÿ‘7๐Ÿ”ฅ4๐Ÿ˜ญ4๐Ÿ˜2๐ŸŽ‰2๐Ÿ™2๐Ÿ˜ข1๐Ÿคฎ1
Awesome and memorable! Black and dirty smm in action.
๐Ÿคฃ12๐Ÿ‘7๐Ÿ˜7๐Ÿ™77โค6๐Ÿ˜ข4๐Ÿ’ฏ3๐Ÿ”ฅ2๐Ÿ‘Ž1๐Ÿ‘€1
This media is not supported in your browser
VIEW IN TELEGRAM
Did you prepare yourself for it?
๐Ÿ‘137๐Ÿ‘6๐Ÿ™5๐Ÿ‘พ5โค4๐Ÿ˜4๐ŸŽ‰4๐Ÿ”ฅ3๐Ÿ˜ข3๐Ÿ˜ญ1
Following a NYT report that the US and Israel discussed a potential post-war role for Mahmoud Ahmadinejad, some Iranian hardliners began accusing the former president of being an Israeli asset, despite no public evidence supporting the claim.

(Source: https://www.nytimes.com/2026/05/19/us/politics/iran-israel-us-leader-ahmadinejad.html)
โค12๐Ÿ‘7๐Ÿ‘65๐Ÿ˜ข3๐Ÿ”ฅ2๐Ÿ˜2๐ŸŽ‰2๐Ÿ‘Œ2๐Ÿค”1๐Ÿ˜ญ1
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ‘8๐Ÿ‘5๐Ÿ”ฅ4โค2โšก1๐Ÿค”1๐Ÿคฉ1๐Ÿ™1๐Ÿ’ฏ11
MTONGA? Steps? Great again?

Someone airdropped undeletable NFTs to each TON wallet that made a transfer. The NFTs contain NSFW content; when you try to delete them, they burn and immediately recreate with a new NSFW picture.

The NFTs contain a link to @nft_burn as a removing solution.

Users who followed instructions from @nft_burn should pass a verification check through sign-in using their Telegram account. That account would then be drained.

I tried to report @nft_burn three times to different people. The last time, I got a reply that moderators already knew about the problem.

So, for three weeks, @nft_burn has still been available, and as I understand it, continues draining and stealing Telegram accounts.

MTONGA? They do not give a fuck about users' problems until you do not have tits.
๐Ÿ‘13๐Ÿ”ฅ5โค4๐Ÿค44๐Ÿ™3๐Ÿ‘2๐ŸŽ‰2๐Ÿ‘Œ1๐Ÿ˜1๐Ÿ’ฏ1
Adventures in Dystopia
MTONGA? Steps? Great again? Someone airdropped undeletable NFTs to each TON wallet that made a transfer. The NFTs contain NSFW content; when you try to delete them, they burn and immediately recreate with a new NSFW picture. The NFTs contain a link to @nft_burnโ€ฆ
MTONGA? What about spam on Telegram?

If you try to create a chat on Telegram with two or more participants and share a public link to it, bots will find it after a while and youโ€™ll end up having to delete dozens of spam messages every day.

This doesnโ€™t happen on Instagram, Twitter, Facebook or VK.

Creating small groups on Telegram for local purposes isnโ€™t practical or sensible.

P.S.: @nft_burn is still online
๐Ÿ‘7โค55๐Ÿ”ฅ4๐Ÿ‘4๐Ÿ™4๐ŸŽ‰2๐Ÿ˜1๐Ÿ•Š1๐ŸŽ…1
Adventures in Dystopia
MTONGA? Steps? Great again? Someone airdropped undeletable NFTs to each TON wallet that made a transfer. The NFTs contain NSFW content; when you try to delete them, they burn and immediately recreate with a new NSFW picture. The NFTs contain a link to @nft_burnโ€ฆ
When the owners of @solana lost it and it was snatched up by bots reserving free tags, it was blocked in less than a day, over the weekend. It could have been quicker, but it happened at night.
โค8๐Ÿ”ฅ4๐Ÿ˜ข44๐Ÿ‘3๐Ÿ‘2๐Ÿค”2๐Ÿ˜1๐ŸŽ‰1๐Ÿ™1
โค15๐Ÿ‘86๐ŸŽ‰2๐Ÿ‘1๐Ÿ”ฅ1๐Ÿ™1
This media is not supported in your browser
VIEW IN TELEGRAM
6โค5โšก2๐Ÿ‘1๐Ÿ”ฅ1๐Ÿ˜1๐Ÿค”1๐Ÿ™1๐Ÿ’ฏ1
Russian roofers face up to 20 years in prison in the U.S.

Angelina Nikolaou and Ivan Birskus have been charged with eight counts following their climb up the Empire State Building. They are accused of endangering lives, burglary, intentional property damage, unlawful entry, tampering with equipment, possession of burglary tools, disturbing the peace, and violating local law.

Combined, these charges could result in up to 20 years in prison. In addition, prosecutors claim that the roofers caused $1,500 in property damage. The couple denies the charges.

โ€“โ€“โ€“โ€“โ€“

Would it be possible to see the same news about Jewish roofers? I think they wouldn't have mentioned the nation in that case. Is it racism? Or do I not understand something?

Many windows to go to prison when you aren't a US politician. ๐Ÿซ 
๐Ÿ‘85๐Ÿ˜4๐Ÿ”ฅ3๐ŸŽ‰2๐Ÿ’”2โค1โœ1๐Ÿค”1๐Ÿคก1๐Ÿ’ฏ1
โค14๐Ÿ‘12๐Ÿ”ฅ97๐Ÿ˜5๐Ÿค”5๐Ÿ‘4๐Ÿฅฐ3โšก1๐Ÿ™1๐Ÿ’ฏ1
Forwarded from Neon Market (venom - busy)
This media is not supported in your browser
VIEW IN TELEGRAM
โš ๏ธ Warning: Two Bugs Being Exploited to Steal Telegram Usernames
Recently, certain individuals have been exploiting two serious bugs to hijack usernames belonging to active, long-standing accounts and channels. Sharing this so people are aware:
1๏ธโƒฃ Exploiting Phone Numbers Tied to Old Accounts
Some people use illegitimate methods to obtain phone numbers linked to old Telegram accounts (a year or more old). When they register with that number, Telegram automatically deletes the old account โ€” allowing them to directly seize the old username, even though they were never the original owner.
2๏ธโƒฃ Bug in the Username Protection Mechanism
Normally, when someone changes or removes a username, Telegram applies a protection period before that username can be claimed by anyone else. However, this is a genuine bug: by repeatedly sending username update requests, an attacker can bypass the protection mechanism entirely rather than simply waiting for it to expire.
As a result, the username becomes obtainable long before it should be available, effectively skipping the intended protection period and allowing an attacker to seize the username immediately after it is released.
๐Ÿ“น Attached video shows a real example of this happening, so you can see exactly how the exploit plays out step by step.
Bottom line:
These aren't just clever tricks โ€” they're actual bugs in how the protection system behaves, and they're being used daily to steal valuable usernames from their rightful owners. If you have an old or valuable username, consider enabling two-step verification and make sure your phone number isn't exposed or reused elsewhere.
2โค1๐Ÿคฉ1๐Ÿ˜ญ1