@kravietz
> group chats can’t be end-to-end encrypted (E2EE), so their contents are readable to at least Telegram operators
Only today this came to me: little is known about it in the rest of the world, but due to sanctions, Russian enterprises and government organizations can't acquire proper security certificates recognised by most widely used browsers.
@kravietz
To avoid the suspiciously looking warnings they have made their own certification authority and are actively encouraging users to install this CA certificate to their systems. With this cert in the system, MITMing anything gets relatively easy.
@ackasaber@mathstodon.xyz
Normally a browser would detect that and refuse to connect giving you a warning or silently fail if such a host is only a source of scripts images, but as I have my own CA, all my computers have its cert installed, all the certificates I sign with it become trusted and it works 😁
It's just something that I realised today (well, yesterday in fact, before Durov got apprehended). There might be other caveats, I'm not a security researcher, otherwise I'd do a proper writeup.
@kravietz