Schneier on Security's Journal
 
[Most Recent Entries] [Calendar View]

Thursday, January 14th, 2021

    Time Event
    2:05p
    Finding the Location of Telegram Users

    Security researcher Ahmed Hassan has shown that spoofing the Android’s “People Nearby” feature allows him to pinpoint the physical location of Telegram users:

    Using readily available software and a rooted Android device, he’s able to spoof the location his device reports to Telegram servers. By using just three different locations and measuring the corresponding distance reported by People Nearby, he is able to pinpoint a user’s precise location.

    […]

    A proof-of-concept video the researcher sent to Telegram showed how he could discern the address of a People Nearby user when he used a free GPS spoofing app to make his phone report just three different locations. He then drew a circle around each of the three locations with a radius of the distance reported by Telegram. The user’s precise location was where all three intersected.

    […]

    Fixing the problem — or at least making it much harder to exploit it — wouldn’t be hard from a technical perspective. Rounding locations to the nearest mile and adding some random bits generally suffices. When the Tinder app had a similar disclosure vulnerability, developers used this kind of technique to fix it.

    7:49p
    Upcoming Speaking Engagements

    This is a current list of where and when I am scheduled to speak:

    • I’m speaking (online) as part of Western Washington University’s Internet Studies Lecture Series on January 20, 2021.
    • I’m speaking (online) at ITU Denmark on February 2, 2021. Details to come.
    • I’m being interviewed by Keith Cronin as part of The Center for Innovation, Security, and New Technology’s CSINT Conversations series, February 10, 2021 from 11:00 AM – 11:30 AM CST.
    • I’ll be speaking at an Informa event on February 28, 2021. Details to come.

    The list is maintained on this page.

    << Previous Day 2021/01/14
    [Calendar]
    Next Day >>

Schneier on Security   About LJ.Rossia.org