This work presents TENET, a purpose-built auditing tool whose design decisions are grounded in the structural properties of the secrets targeted and empirically validated against a ground-truth dataset, and proposes mitigation measures and best practices for both Telegram platform developers and third-party Mini App creators.
Abstract
Telegram, with over 450 million daily active users, has introduced Mini Apps---web-based applications running directly within its client. However, this integration introduces notable security risks. As we demonstrate, many Mini Apps store authentication materials---such as session tokens and wallet mnemonic phrases---in plaintext on client devices, exposing users to unauthorized access, impersonation, and financial exploitation. While insecure client-side storage is a known risk in web applications, the Telegram Mini App ecosystem presents a uniquely dangerous combination of factors absent from prior work: no platform-level security review, no storage access restrictions, a financially motivated user base handling live cryptocurrency assets, and a WebView environment that offers weaker protections than standalone browsers. To investigate this threat, we present TENET, a purpose-built auditing tool whose design decisions---pattern selection, entropy thresholds, and charset validation---are grounded in the structural properties of the secrets targeted and empirically validated against a ground-truth dataset. We screened 61 Mini Apps using a stratified, popularity-weighted sampling strategy based on popularity. Of the 37 applications that met our processing criteria and were analyzed, 30 exhibited security flaws, which we classify into three severity tiers: plaintext storage, recoverable encryption, and replayable tokens. Notably, even Telegram's official Wallet exhibits a severe vulnerability that may lead to full account compromise. Following our responsible disclosure, Telegram implemented two new secure-storage APIs, and our post-remediation verification confirmed that its official Wallet no longer exposes the recovery mnemonic in plaintext. Finally, we propose mitigation measures and best practices for both Telegram platform developers and third-party Mini App creators.
TeleGapper, a black-box dynamic analysis framework, is presented, a black-box dynamic analysis framework to assess the privacy posture of Mini Apps by capturing runtime network traffic, identifying third-party communications, and comparing observed data flows against disclosed privacy information.
This passkey approach is distinctively architecturally more secure against phishing owing to its root binding, public-key cryptography and authenticator domain and proposes Enterprises five-phase migration.
Oğuzhan Kilim· International Journal For Mu...· 0 citations
This paper presents PreAcher, a system architecture that incorporates third-party Content Delivery Networks (CDNs) into the password authentication process and offloads the authentication workload to CDNs without divulging the passwords to them.
Shihan Lin, Yunming Xiao, Aleksandar Kuzmanovic et al.· 0 citations
A low-cost USB passthrough system that operates independently of host-side security software, using a Raspberry Pi 4 as an intermediary security layer between a keyboard and a host computer is developed.
Muhammad Alif Nukman bin Nor Azman, N. M. Salleh, S. R. Selamat et al.· International journal of res...· 0 citations
Mobile money platforms have revolutionized financial inclusion across developing economies, yet they remain
highly vulnerable to sophisticated, automated credential-stuffing and unauthorized access attacks. Traditional static PIN
authentication mechanisms often fail to balance robust security with user experience, leav...
Kazeem O. N., Umar Yahaya, Abdul Kareem Jimoh Mayaki et al.· International Journal of Inn...· 0 citations
The WebAuthn standard enables passwordless authentication using asymmetric cryptography and addresses several well-known vulnerabilities of traditional password-based authentication. Despite the formally proven security of the standard itself, practical implementations often contain server-side flaws that allow authent...
Sven Ulčar, Matevž Pesek· Uporabna informatika· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.