| ▲ | anon_cow1111 6 hours ago | |
Imagine if you forgot to update your phone number with your personal bank, and then some random guy was given full access to your account and all of its contents. And even if you dug through the account options and set a 2FA password (normally disabled) he could still just delete your account outright. Last I checked, that's exactly how Telegram works by default. It's laughable to consider a service tied to a phone number secure. | ||
| ▲ | sunaookami 2 hours ago | parent | next [-] | |
You would still get a notification inside Telegram that someone else logged in (plus it sends the login code to your session first before you can fallback to SMS) and you can log them out. The "attacker" can't delete your account or log out your sessions because he can't use certain features on a fresh login, there is a downtime. But yeah, he can read all your chats. Same should be true for any app that uses phone number login. That's why there is a password feature. | ||
| ▲ | msh 4 hours ago | parent | prev [-] | |
I guess that’s the idea with phone number based services. Imagine if you could not sign up for telegram/ WhatsApp/ whatever because someone used your number before you. | ||