Comment by defraudbah

12 hours ago

in short, you don't need access to the device, only to the same network

if you are on the same network and manage either intercept key to bruteforce it or guess encryption key with emoji it's possible to decrypt the whole chat. It works because telegram random generator uses time and some device information which is predictable

the study managed to decrypt 500 messages out of 500 on emulator devices. Brutewforcing takes like a few $100 worth of computing power

Honestly, durovs are exceptional people and enterpreneurs, however their encryption and what they say isn't always what it presented as

In a very real sense you do need access to the device to install the backdoored client.

There is no actual cryptographic weakness presented here...