TG Telegram Group Link
Channel: Telegram (非官方)香港支援頻道
Back to Bottom
#SecurityAdvisory

The security incident mentioned earlier before was patched on August 5, 2019 by 2350 Hong Kong Standard Time.

Telegram Users are not required to proceed any actions to apply the fix.

The sequence of time for this incident are as follows in Hong Kong Time:
1) 0934 - Developers of @hexuniverse found the vulnerability
2) 0943 - They find several more users to confirm the situation
3) 1041 - Incident report including steps to reproduce are sent to Telegram Officials
4) 1111 - The (Unofficial) Telegram Support Group of Hong Kong were tipped off by the lead developer from @hexuniverse
5) 1112 - Pantry Manager @lifehome have directed a Emergency Response Team to confirm the incident.
6) 1600 - Incident has been reproduced on all Telegram platforms with June 23 update and later TL Layers
7) 1632 to 1645 - Security advisory were released on both channels @tlgrmHK_ch and @hexuniverse
8) 2150 - Telegram officials responded that a reproduction of vulnerability is success and a patch will be online soon.
9) 2320 - Telegram officials responded that the server-side patch was online then.
Telegram 5.11 (14576) Beta 版本已推出!

大家在新版本中,可以選擇誰能透過電話號碼找到你的 Telegram 帳號~再也不怕尷尬的某位可能在 Telegram 中再找到你!
#溫馨提示
如果 iOS 用家需要享受 Telegram Beta 嘅功能,可以透過訂閱頻道 https://hottg.com/tgslots 獲得 TestFlight 名額空出通知~

#warmReminder
Should iOS users feel the need to test out Telegram Beta, you may join the channel @tgslots for extra TestFlight slots notification.
回應有關公共頻道被 Telegram 官方關閉的查詢

就近日有大型公共 Channel 懷疑因爲被 Telegram 官方標籤爲鼓吹暴力的緣故,而被以「違反服務條款」理由關閉 Channel 的對外顯示權限,Telegram (非官方) 香港支援工作小組在此重申:

使用 Telegram 服務時,敬請不要濫發訊息或進行詐騙活動,此等行爲將會成爲官方首要處理目標;其次,於公共群組(group/supergroup)、頻道(channel)、機械人(bot)等渠道發放色情內容,均會被官方納入爲長期處理目標,敬請大家不要在上述渠道發放色情內容。

最後,Telegram 並不容許暴力言論於公開的 Telegram 渠道發放,此舉包括但不限於設有用戶名稱(username)的公共頻道(public channel)。

如果大家認爲某些內容不適合公衆傳閱,或需要進行內部公告等動作,可以考慮停止設定頻道(channel)或超級群組(supergroup)的用戶名稱(username);Telegram 自身的邀請連結功能已經很足夠中小型團隊,作爲加入對話的媒介。
Response to inquiry on public channel being closed by Telegram Officials

In view of a local, large public-channel being suspended by Telegram officials, and labeled as violated Terms of Services, the (Unofficial) Telegram Support Group of Hong Kong hereby reiterates the following:

When using services of Telegram, please do not spam or enact scam activities, since these are primary targets of the Telegram officials to “process with”. Second, in small groups, supergroups, bots and other means of conversation over the platform of Telegram, it is prohibited for pornography to be shown/visible publicly, those who spread materials like these will be seen as a direct violation of Terms of Services, and will have high possibilities result in immediate account termination.

Last but not least, Telegram does not allow violence speech to be shown/visible publicly, this includes but not limited to public channels with username.

The (Unofficial) Telegram Support Group of Hong Kong suggests if there are materials that has to be shared over the platform of Telegram, one could choose to stop configuring a public username for their channel or supergroup. Moreover, the invitation link feature of every group, supergroup and channel is very suffice, for members of small and medium team to join and read the conversation.
小編偷跑話你知:

@SilentServiceBot 已經靜雞雞封測啦,如果你都想有個 bot 可以自動清理系統訊息,例如唔想見到有人彈出彈入,呢隻 bot 都可以幫到你手~!

如果有問題,歡迎大家嚟 @tlgrmHK 回報喔~
#服務公告

目前 Telegram DC 5 服務正受影響,大家於使用 Telegram 服務時會感受緩慢速度,敬請見諒。

#ServiceAnnouncement

Currently the Pan-Asia Telegram Server is in very slow response, and you may experience slow or unable to use Telegram service in Pan-Asia regions.
#服務公告

目前 Telegram 亞洲區服務大致回復正常;有關於香港區服務間歇緩慢,主要因為本地網絡營辦商往來 Telegram 伺服器的路由並非最佳路線,以致服務有所影響,詳情請向相關營辦商查詢。

#ServiceAnnouncement

Telegram services in Pan-Asia is now recovered in full speed. However, users in Hong Kong region may still suffer slowness or high latency, this is due to the local Internet Service Provider is not using an optimal internet routing path to Telegram servers, you may make enquiries to your ISP with regard such situation.
#tlgrmHK的人和事

@hexUniverse 以及 @hexlightning_bot 早於 2018 年已由 Telegram (非官方) 香港支援工作小組全力支持,由功能及翻譯,以致安全事故通報,都一一鼎力支持~

Admin 們敢講,如果缺乏 @hexlightning_bot 嘅存在,港台的 Telegram 群組溝通空間未必能夠有現時嘅安寧🦁😁

要表達對 @hexlightning_bot 的支持?小額贊助按此: https://p.ecpay.com.tw/DAD2F
Telegram 對話內容被擷取的溫馨提示

Telegram (非官方) 香港支援工作小組留意到近日有消息,指 Telegram 對話內容被執法機關從蘋果公司新款裝置中擷取。

本工作小組希望香港市民留意以下幾個要點:

1)任何平臺的官方 Telegram APP 均沒有本地資料庫加密,使用者必須先開啓應用程式鎖,才會使用該程式鎖的密碼作爲主要鑰匙,加密本地資料庫;

2)針對於「只要刪除帳號就可以刪除本機資料」的說法並不完全正確,因爲 Telegram 伺服器需要透過互聯網連接,方可遠端刪除及清空資料庫;

3)感謝友台蘋果園( @appleland_HK )提醒,本工作小組得悉目前的蘋果公司新款手機(泛指具備 64-bit 運算能力裝置)均有系統軟體更新,本工作小組建議以下機種更新到最新的 iOS 版本:
iPhone SE
iPhone 6s & iPhone 6s Plus
iPhone 7 & iPhone 7 Plus
iPhone 8 & iPhone 8 Plus
iPhone X
iPhone XR & iPhone XS & iPhone XS Max
iPhone 11 & iPhone 11 Pro & iPhone 11 Pro Max

4)坊間有傳聞指 Cellebrite 工具能夠擷取任何手機的資料,本工作小組向業內人士查證後,確認目前 12 月份的 XRY、Cellebrite PA 及 UFED 等工具已經能夠透過 checkm8 漏洞,擷取及存取 iPhone X @ iOS 13.3 beta 或以下版本的根系統目錄。業內人士更透露 Cellebrite 有份主動參與 ra1ncheck 等破解的核心工作,並有意於新版 Cellebrite 工具新增符合數位鑑證的功能,以便鑑證人員能夠不更改元系統情況下,完整地將根系統目錄等資料打包。

5)本工作小組明白大家對 Telegram 的信任,但資訊安全並非如「加個密碼」就可以完成的工作,希望大家從今天開始,不要再依賴自己所知道的世界,要多抱着懷疑的心態對待通訊工具,才能夠從同溫層脫離,爲自己增添日常的警覺性。
Warm reminder regarding Telegram chat being retrieved

The (Unofficial) Telegram Support Group of Hong Kong have noticed a recent event, that Telegram chats were retrieved by law enforcement from Apple iDevices.

We would like to remind citizens of Hong Kong on the followings:

1)ALL official Telegram app does not encrypt local storage by default. In order to encrypt, user should enable App Lock, to allow the Telegram app utilize such password as the primary passphrase to encrypt the storage.

2)The saying that goes "by deleting Telegram account can remotely wipe chat history" is not fully accurate. Telegram requires internet connection between Telegram Server and the logged in sessions/devices, for the server to logoff the session and clear the database.

3)Thanks to our affiliate channel "@appleland_HK", we are aware that newer Apple iDevices (of those operating in 64-bit) receive occasional system software update from Apple. We recommend all users of Telegram to upgrade their iDevices to the latest iOS version. Below is a list of devices which is capable to receive iOS 13 updates:
iPhone SE
iPhone 6s & iPhone 6s Plus
iPhone 7 & iPhone 7 Plus
iPhone 8 & iPhone 8 Plus
iPhone X
iPhone XR & iPhone XS & iPhone XS Max
iPhone 11 & iPhone 11 Pro & iPhone 11 Pro Max

4)There are discussions in the public group, saying Cellebrite tools are capable to retrieve data from any mobile phone. We have investigated this saying with our informant in the industry, and confirms that versions starting from December 2019, tools like XRY and Cellebrite PA/UFED are indeed capable to extract root filesystem from iPhone X with iOS version 13.3 beta or below, using the vulnerabilities from checkm8. Our informant further believes that Cellebrite has taken an active and core role in the development of ra1ncheck and other iOS penetration tasks, and Cellebrite is planning to release a sounded version of UFED that implements the ra1ncheck vulnerability, while not touching the evidence itself, making their tool fully compatible with legal requirements.

5)We are feeling an overwhelming trust from the Hong Kong citizens to Telegram, but it is a devious world in the field of cyber security. We urge everyone, starting from today, be skeptical to your communication model. By questioning more, you are then earning awareness to your trust model, and thus becoming more alert on suspicious environments.
#服務公告

@SilentServiceBot 正式上線啦!

如果你都好似我咁,唔想知有邊個彈出彈入,搞到成個 group 都好多系統訊息, @SilentServiceBot 就幫到你啦!只要將佢加做 admin,佢就會自動食咗啲系統訊息,方便又快捷~

//================//
@SilentServiceBot
預設私隱設定: 不可以接收群組訊息
所需管理權限: 1個 《刪除訊息》
#服務公告 #緊急維護

由於網絡故障影響關係,@SilentServiceBot 的服務將會暫時停頓。
進一步的資訊將會在 @tlgrmHK 發放,對於所造成的不便,我們深感抱歉。
#服務公告

@SilentServiceBot 服務逐漸回覆正常。
對於服務停頓所造成的不便,我們深感抱歉。
Advisory on recent Telegram security concern

The (Unofficial) Telegram Support Group of Hong Kong have noticed a recent security concern across multiple Telegram channels.

The Support Group would like to remind citizens of Hong Kong on the followings:

1)There is a saying, that Telegram chats are recoverable via the use of forensic software. The Support Group has investigated with an unnamed source in the industry, and confirmed that the forensic suite version by April 2020, including Cellebrite PA and UFED, are indeed capable of retrieving existing and deleted Telegram chats. The source has also confirmed that an unnamed hash algorithm software version by December 2019, is capable to unlock Android and iOS Telegram apps, with app passcode lock activated.

2)The Support Group has communicated with an Information Security Engineer, and found no high-priority CVE exploitations or imminent MTProto security concern. By then, the Support Group believes that the communication between Telegram users are still safe and sound.

3)The Support Group has tested with an Information Security Engineer, and found the exploit number CVE-2019-15514 is still reproducible. This means a number of Hong Kong Citizens have not chosen to hide their personal phone number. In view of current Hong Kong politics and society movements, the Support Group worries this exploitation may be used by rogue entities, attaining unrevealed personal information(NIST CWE-200).

4)The Support Group would like to emphasize that Telegram databases can be easily decrypted by forensic software. Should you feel the need to exchange sensitive messages, please use Signal instead.

Download Signal:
Android // https://play.google.com/store/apps/details?id=org.thoughtcrime.securesms
iOS // https://apps.apple.com/us/app/signal-private-messenger/id874139669
就有關於 Telegram 安全問題的呼籲

Telegram (非官方) 香港支援工作小組留意到近日有消息,指 Telegram 有嚴重安全問題。

工作小組希望香港市民留意以下幾個要點:

1)工作小組近日與不願具名的業界人士溝通後,確認 2020 年 4 月份版本的數位鑑證套裝軟件(包括 Cellebrite PA 及 UFED 等),能夠擷取部分 Android 及 iOS 裝置內,Telegram 的所有現存及已刪除對話內容。另外,業界人士亦確認 2019 年 12 月份版本的散列演算法軟件,已經能夠解開 Android 及 iOS 的 Telegram 客戶端密碼(亦稱 App passcode)。

2)工作小組與資訊安全工程師溝通後,未有發現任何高重要度的 CVE,同時亦未有發現通訊協定有即時的安全隱憂。工作小組認爲目前而言,Telegram 使用者之間的通訊依然安全。

3)工作小組與資訊安全工程師測試後,發現漏洞編號 CVE-2019-15514 依然能夠於部分 Telegram 使用者身上重現,即表示有部分香港市民與使用 Telegram 時候,未有選擇隱藏電話號碼。工作小組憂慮,按照目前香港的政治及社會局勢,這個功能漏洞會被不法分子利用,從而被揭露未曾公開的個人私隱資料(NIST CWE-200)。

4)工作小組亦提醒香港市民,有鑑於 Telegram 的資料庫已經能夠被鑑證軟件輕易破解,如果有需要交換敏感訊息,建議改爲使用 Signal。

Signal 下載地址:
Android // https://play.google.com/store/apps/details?id=org.thoughtcrime.securesms
iOS // https://apps.apple.com/us/app/signal-private-messenger/id874139669
#服務公告 #Bot相關資訊

@SilentServiceBot 性能已經大大改善,並能夠穩定地快速完成刪除動作。
而伺服器方面亦已經完成加強網絡骨幹,大家可以放心使用~

Bot 詳情請看: https://hottg.com/tlgrmHK_ch/22
#服務公告

【tl;dr: 於 2020 年 12 月 1 日, @tlgrmhk 於日本地區提供的 MTProxy 服務將永久停止服務】
--------

由於有伺服器供應商更新合約時,箇中部分條款並未符合本工作小組的價值觀及理念。有見及此,本工作小組決定於舊有合約期滿日(即 2020 年 12 月 1 日)起,停止使用該供應商的伺服器。

以上決定將會影響到現有 MTProxy 服務;而經過工作小組權衡利害關係,以及有見服務使用量日趨下降,我們決定於上述日期(即 2020 年 12 月 1 日)當天,於日本地區停止提供由 @tlgrmHK 營運的公共 MTProxy 服務。

爲免服務因此而受到影響,敬請大家及早切換到其他 MTProxy 服務供應商。

因此帶來不便,Telegram (非官方) 香港支援工作小組謹此致歉。
HTML Embed Code:
2024/05/04 14:20:19
Back to Top