No menu items!

Telegram Corrects Flaw Enabling Other Users to See Deleted Images

RIO DE JANEIRO, BRAZIL – Telegram messaging App has been updated to correct a privacy issue when deleting messages. According to security researcher Dhiraj Mishra, Telegram was not deleting images when the “Delete to [contact name] also” option was used, allowing contacts to easily retrieve supposedly deleted messages.

Telegram rewards specialists who discover security flaws in their service.
Telegram rewards specialists who discover security flaws in their service. (Photo: internet reproduction)

The problem identified by Mishra was corrected in version 5.11. As Telegram rewards specialists who discover security flaws in their service, the researcher received a €2,500 (about R$11,000) reward from the app for his breakthrough.

The function of deleting messages to other chat members was added to Telegram in 2017. The purpose is to allow the deletion of messages to all contacts, whether individually or in groups, in order to protect the content’s privacy. The feature is also useful when a message is sent to the wrong recipient: by removing a message immediately after sending, it is possible to prevent the recipient from reading it.

However, when an image is received in the messenger, it is copied to the “/Telegram/Telegram Images/” folder. Mishra identified that although the message was deleted from the Telegram database, the received image remained intact in the folder. In order to see the supposedly deleted images, all that was needed was to retrieve this folder’s contents.

The flaw was identified on Android, but Mishra speculates that the same behavior may have existed on other platforms, such as Telegram for iOS and Windows.

WhatsApp also has a “delete for all” feature that deletes a message to all participants in a conversation. According to Mishra, unlike Telegram, WhatsApp removes images associated with a deleted message, reducing privacy risks. As such, WhatsApp did not show the same flaw as Telegram.

The function of deleting messages to other chat members was added to Telegram in 2017.
The function of deleting messages to other chat members was added to Telegram in 2017. (Photo: internet reproduction)

Limitations on Message Removal

Apps such as WhatsApp and Telegram take basic measures to ensure the privacy of deleted messages on other contacts’ phones, but there are ways to ensure the preservation of any content supposedly removed.

Even if apps try to discourage or forbid screenshots and copying data to other locations, there are several ways to circumvent these restrictions.

A simple technique is to take a picture of the phone screen with another camera or cell phone. In this case, the record has already been moved to another device and cannot be controlled by the apps installed on the original phone.

In some cases, image backup apps, such as Google Photos, may include the media folders of other apps so that all your content is stored in the cloud.

Connecting these apps to computers makes it even easier to retain these messages by saving images and even text and audio messages to other locations on the computer, beyond the app’s reach.

Source: G1

Check out our other content

×
You have free article(s) remaining. Subscribe for unlimited access.