Talk:Operations security

From RACKWiki

Examples of known vulnerabilities in specific platforms

I originally wrote this up as a new section in "Known Incidents", but upon rereading it I wasn't sure if it would be seen as editorializing too much. I'd welcome any suggestions on if this fits into this page, if so, where; or, if there's a different way to capture it on the RACK wiki. (It perhaps more closely resembles an Incident Report, but these are more like CVE alerts than actual Incidents, so, IDK, doesn't feel particularly right for that format, either).

Known Platform Vulnerabilities

Many social media platforms have unpredictable OPSEC vulnerabilities - for instance, "accounts you might know" recommendations that may allow people to infer the identity of people using alternate accounts from the same device, or exposing a list of who someone follows, allowing an attacker to potentially gain leverage via those social connections.

Some specific examples:

  • Telegram's "Sync Contacts" feature: Telegram is a popular messaging app for members of the kink community. One of its features is the ability to import contacts from your phone book. When this happens, contacts can view each others' Telegram profiles.
    • To avoid this: don't give Telegram permission to access your contacts, and don't choose "Sync Contacts" from within the app. Alternatively, Telegram's in-app permissions can be used to prevent access to specific parts of a user profile.
    • Additional note: Telegram is not typically end-to-end encrypted, meaning that content shared there may be accessible to their employees or via government warrants. Services with end-to-end encryption provide more security for conversation privacy.
  • Instagram's "Share" link account suggestion feature: when content is shared from Instagram, the app provides a URL that includes a tracking parameter identifying the person who shared it. When someone clicks this link, they see a pop-up suggesting they follow that person's Instagram account. The person who shared the content in the first place often does not realize that their account has been publicized.
    • To avoid this: Currently, this behavior can be prevented by removing the part of an Instagram URL that reads igsh= and everything after it. However, Instagram could remove this workaround if they wish. Avoid using the "share" function on Instagram when logged into accounts that require anonymity, and particularly avoid sharing Instagram links on public social media.

Corbeau (talk) 23:40, 23 July 2026 (PDT)Reply[reply]