domain | rys.io |
summary | The document provides a detailed analysis revealing that an auth_key_id is consistently used across different sessions involving Telegram mobile applications using Tor for privacy reasons or after blocking/unblocking IP addresses connected by the app.
Key findings include:
1. A persistent long-term auth_key_id (64:0a:8a:ff:3a:83:75:54) was found in numerous .pcapng files related to background sessions of Telegram mobile applications, indicating that this key is part of normal operation even after using Tor or blocking/unblocking IP addresses. 2. The analysis also observed the auth_key_id during a session where someone joined a channel from Poland instead of Iceland; initially different keys were identified before perfect forward secrecy took effect and new authorization keys appeared.
The document questions why if Newag, presumably related to railway technology mentioned as not locking up trains despite certain conditions being met (such as 21 days stationary), the company wouldn't have more involvement in identifying potential modifications or issues with their software. It also speculates about a hidden collaboration between hackers from Dragon Sector and manufacturers like Newag regarding unauthorized changes made by third parties without consent.
The document seems to suggest that there are underlying connections linking these observations, possibly indicating security concerns involving multiple systems such as Telegram's use of Tor for privacy versus railway locking mechanisms in the context of copyright infringement or software tampering. |
title | Songs on the Security of Networks |
description | And the blog by Michał "Rysiek" Woźniak |
keywords | telegram, have, software, people, more, mastodon, there, using, protocol, even, service, does, telegrams, time, social, like, same |
upstreams |
blogroll.org |
downstreams |
|
nslookup | A 95.217.113.34 |
created | 2024-11-29 |
updated | 2025-08-05 |
summarized | 2025-08-20 |
|
|