| domain | rys.io |
| summary | This document details investigations into Telegram's behavior regarding the visibility of an `auth_key_id`. Across multiple PCAPNG files, the `auth_key_id` was consistently observed, regardless of the connection method (Tor, blocked IPs, or joining a channel in a different location).
Specifically, the investigations showed the `auth_key_id` was visible during:
* Background Telegram sessions using Tor. * Blocking and unblocking Telegram IPs. * Joining a Telegram channel while physically located in Poland instead of Iceland.
The presence of all-zero `auth_key_id` values, followed by new values, suggests the implementation of Perfect Forward Secrecy and the negotiation of temporary authorization keys.
The document raises questions about the role of Newag (the train manufacturer) and the identical 21-day stationary condition across two separate systems, and suggests a potential need for collaboration with Dragon Sector to investigate unauthorized software modifications in train controllers. |
| title | Songs on the Security of Networks |
| description | a blog by Michał "rysiek" Woźniak |
| keywords | telegram, have, software, people, more, mastodon, there, using, protocol, even, service, does, telegrams, time, social, like, same |
| upstreams |
blogroll.org |
| downstreams |
|
| nslookup | A 95.217.113.34 |
| created | 2024-11-29 |
| updated | 2025-08-05 |
| summarized | 2025-12-10 |
|
|