Just In
- 1 hr ago
Amazon Headsets Fest Offers You Can Get On Headphones, Earphones, Truly Wireless Earbuds And More
- 9 hrs ago
RedmiBook 13 With Intel Core i5/i7 Announced For Around Rs. 43,500
- 12 hrs ago
Airtel Launches VoWiFi Service In Delhi-NCR: List Of Compatible Smartphones
- 13 hrs ago
Vivo U20 Launched With 8GB RAM In India: Price And Offers
Don't Miss
- Sports
Salzburg 0-2 Liverpool: Keita and Salah see Reds through in thrilling clash
- Movies
Shahid Kapoor To Commence Shoot Of ‘Jersey’ On December 13 Despite Being Severely Ill
- News
Senior Shiv Sena leader hints at patch-up with BJP, says 'Uddhav will take decision at right time'
- Finance
Yes Bank Defers Decision On Allotment Of Shares To Citax; Braich's Bid Under Discussion
- Lifestyle
This Viral Video Of Chimpanzee Carefully Washing A T-Shirt Will Leave You Surprised
- Travel
7 Beautiful Churches in India For The Perfect Christmas Holiday
- Automobiles
Orxa Mantis Electric Performance Motorcycle Revealed At India Bike Week 2019
- Education
TOEFL Go! Global: A Mobile App From ETS To Stand Out In Exam
Telegram Passport is vulnerable to brute-force attacks: Report
Telegram Passport is a useful tool, however, due to its security flaws, the feature might lose its popularity among the users.
Telegram has launched the Telegram Passport feature recently for its platform. The Telegram Passport app allows a user to store their real-world documents and IDs online. This tool allows the sharing of IDs or documents with the services which require a user to prove their real identity. The feature surely comes handy while registering on a new website, however, the data privacy had been a concern among the users from the beginning.
Now, some new reports are suggesting that the Telegram's personal identification authorization tool is vulnerable to brute force attacks, which is a major concern for the users. The report comes from the cryptographic software and service developer Virgil Security, Inc. The report suggests that a user's data is stored on the Telegram cloud by using an end-to-end encryption. However, the data is now moved to the decentralized cloud which is unable to decrypt the personal data and identifies the data as "random noise".
Also read, Russia asks Apple to take down Telegram from its App Store in the country
Telegram currently utilizes SHA-512 which is a hashing algorithm. The SHA-512 is not designed to hash the passwords and it is said to leave the password vulnerable to the brute force attacks despite the fact that they are salted. For our readers who are unaware of the sale process, we would like to add that a salt is a random data that is added as an extra secret value and it extends the length of the original password. This, in turn, provides some additional protection to the data.
"It's 2018 and one top-level GPU can brute-force check about 1.5 billion SHA-512 hashes per second. That means that ten such GPUs (a small cryptocurrency mining farm) can check each and every 8 char password from a 94 char alphabet in 4.7 days! That's $135/password in the worst-case scenario, using US average electricity costs for the calculation. In practice though, this number can go down to $5/password or even less, given people's choices of password complexity.
To cut it short, the Telegram Passport is a useful tool, however, due to its security flaws, the feature might lose its popularity among the users. The report from Virgil Security, Inc, also mentions that "the security of the data you upload to Telegram's Cloud overwhelmingly relies on the strength of your password since brute force attacks are easy with the hashing algorithm chosen".
Recently, Telegram has also introduced a new update for its mobile app for Android and iOS platforms. The new update brings a number of updates for both the platforms; however, a couple of features are exclusively available for the Android platform, read the complete story here.
-
22,990
-
29,999
-
14,999
-
28,999
-
34,999
-
1,09,894
-
15,999
-
36,990
-
79,999
-
71,990
-
14,999
-
9,999
-
64,900
-
34,999
-
15,999
-
25,999
-
46,669
-
19,999
-
17,999
-
9,999
-
22,160
-
18,200
-
18,270
-
22,300
-
33,530
-
14,030
-
6,990
-
20,340
-
12,790
-
7,090