Do not use Telegram’s new “People nearby” feature

Telegram’s new “People Near” feature displays a list of other nearby users and their approximate proximity to you, allowing you to create group chats based on their geographic location. The feature is off by default and must be manually activated by the user, but it’s an idiosyncratic addition to an app that markets itself as an end-to-end encrypted messaging service – and according to security researcher Ahmed. Hassan, this is a security risk.

Users can fake their geographic location on Telegram, exposing them to possible scams. “Many scammers tamper with their location and try to sell investments in fake bitcoin, hacking tools, SSNs used for unemployment fraud, etc. The amount of illegal activity I saw there made Silkroad look like it was run by amateurs, ”Hassan explained in a recent blog post.

Worse yet, Hassan identified a flaw in the People Nearby feature that could allow criminals to triangulate the exact location of other app users using two accounts with fake addresses.

Telegram's new "People nearby" feature

This opens up users to hacking, stalking or worse – and Telegram, as advertised, has no plans to fix the issue. Hassan reported the vulnerability to Telegram, but the company says it will not be patched. In fact, Telegram told Hassan that finding a user’s specific location is an “expected” result of the People Nearby feature in some cases. The answer seems odd for an encrypted messaging app that sells itself on its privacy features. Even adding a more detailed warning that other users might find your exact location would be helpful, but it looks like that won’t happen either.

To be fair, Telegram is generally more secure than other chat apps, and since people nearby are disabled by default, that might not seem like a big deal. However, users may inadvertently activate the feature, believing that they are simply conveying their general proximity to someone else, not their exact location. If you value your privacy, do not use the People Near Telegram feature.

