this post was submitted on 03 Apr 2026
62 points (100.0% liked)

Opensource

5865 readers
187 users here now

A community for discussion about open source software! Ask questions, share knowledge, share news, or post interesting stuff related to it!

CreditsIcon base by Lorc under CC BY 3.0 with modifications to add a gradient



founded 2 years ago
MODERATORS
 

This is why we install from FDroid.

top 9 comments
sorted by: hot top controversial new old
[–] Pika@sh.itjust.works 4 points 2 hours ago

PSA on anyone who used this. Terminate your session via active sessions on another telegram app after you "log out"

This app ALSO doesn't properly invalidate your session token like most apps do, so even though it "logs out" on the UI, the auth token to the telegram stays active.

While there hasen't been any evidence that it transmits auth tokens, since it was confirmed AND admitted that they logged phone numbers, it's better to be safe than sorry.

[–] lemmysmash@beehaw.org 2 points 3 hours ago

Being honest, I would be surprised if there wasn't malware there. The whole Telegram platform is kind of a nesting ground for it.

[–] CumbrianCucumber@lemmy.world 3 points 9 hours ago

Hasn't Telegram being Russian spyware been known for years now?

[–] Kissaki@programming.dev 2 points 9 hours ago* (last edited 9 hours ago)

So, assuming good faith, they used two Telegram bots for some service functionality

these two bots are used to resolve username from user id, eg tg://user?id=25

Obviously, that should never happen silently. But these findings don't necessarily mean data has been compromised [beyond the scope of the app itself].

I get they may be very frustrated and annoyed at the negative blowback after their FOSS efforts, but dismissing concerns isn't a good way to respond.

[–] Pika@sh.itjust.works 4 points 23 hours ago* (last edited 21 hours ago)

Well shoot. That was a good messenger too.

Edit: Looking into it. It looks like the dev even admitted to it as well. So that's surprising.

Link may require telegram

[–] inari@piefed.zip 8 points 1 day ago (1 children)

Would an F-Droid release have found this issue? 

[–] artyom@piefed.social 12 points 1 day ago (1 children)

No but it would have avoided it since its compiled from source.

[–] inari@piefed.zip 18 points 1 day ago

Yeah... one of the criticisms levied at F-Droid is that you need to trust them over the app developers but as we can see in cases like this, I think that's a feature, not a bug.

It's one reason I'll never use something like Obtainium for instance.