Telegram's location feature opens users up to hackers

Telegram's location feature opens users up to hackers

Telegram's "People Nearby" feature can find the exact location of those whose feature is enabled. Bounty hunter and researcher Ahmed Hassan detected the rarity and reported it to the messaging app's security. Hassan had noticed a similar problem with the Line app a few years ago and took it up with Telegram. However, when reporting it, Telegram said that this was not a problem and that there was no bug bounty. Hassan's concern is that this feature essentially allows anyone to find his exact location, which is incredibly dangerous. This is especially true of Telegram which, while a normal messaging app on its own, is preferred by extremist groups and hackers.

"People Nearby" Operation

In a blog post, Hassan explained how the entity distance model can be used to triangulate the exact location of a user. If a user's Telegram has the "People Nearby" option turned on, she can go in and see how far away people are from her location. In the list of nearby people, she will tell you how far away they are. This allows someone to "fake" the exact location of others at three points and use them to draw three triangulation circles according to Hassan. While attempting to falsify a user's address, Hassan discovered that he could find the exact address of his home simply through this process.