How Greedy Bots Put Telegram Users’ Privacy at Risk
A bit more about Fullyst (English version).
Yesterday, as part of competitor and potential-competitor analysis, I finally got to grep_robot. Like many of its rivals, it only does a subset of what Fullyst can do, in particular deleting words / phrases / links / etc. based on predefined rules.
Since competitor analysis should be comprehensive, I also decided to read the documentation published on the bot’s website. The docs themselves, like the potential competitor, would not have been enough reason to write this post. What caught my eye were the sections:
• 'ChatSearch'. According to the site:
this is a tool for finding similar Telegram groups. For each group it finds, it shows how many members overlap between the found group and the original group.
• 'TgScan':
this is a tool for finding Telegram groups a person is a member of. For each group it finds, it shows the date when the TgScanRobot bot last saw the target user there.
To be honest, this information made my eyes pop. Here is the core of the problem:
When chat admins add this grep_robot, they are forced to give it admin rights and thus access to all user data, messages, and so on.
Some chats deliberately hide their member lists for various reasons. Some want to protect users from spam, others do it for users’ physical safety. Fullyst itself, for example, includes LGBT+ chats from Arab countries.
What do these services do? Exactly. Ignoring such restrictions, they sell, for money, access to lists of chats a person is in, as well as user overlaps between groups. This is a blatant violation of Telegram’s terms of service.
This post is yet another warning:
❗️ Chat administrators: please pay attention to which bots you add to your chat. You are putting your users’ personal data at risk.
❗️ Users: keep an eye on which bots are present in the chats you belong to. Unfortunately, some chats do not care about your safety or the security of your personal data.
More to explore
Startup Taxes Between Estonia and Portugal: A Quick Reality Check
As a tax resident of an EU country who files my own returns, today is my quarterly 'Tax Day'. On this day I set aside a few hours to file social security report…
Saylify Update: Fighting Perfectionism, Refactoring, and Finding the Right Focus
I have not written anything about Saylify for a long time, even though I planned to launch in January. Unfortunately, life likes to throw in challenges you can …
Human-Like Memory for LLMs
TL;DR I wrote a manifesto-style essay about a memory model for LLMs that is as close as possible to human memory and lets the system build a relationship histor…
When Companies Finally Say the Ugly Part Out Loud
Now we are finally fucking talking. Not all that crap like "internal policies", "no explanation needed", "just because".1Office are the first who wrote it plain…