I’m submitting a new suggestion to improve security on the platform. The proposal focuses on the active sessions feature.
At present, a user can delete any session easily by tapping the “Delete all sessions” button, leaving only the current session active. That works well, but the security of sessions could be strengthened further if you added an option that requires a password, PIN, or 2‑FA code before the other sessions can be removed. Which authentication method you implement is up to you, based on what you consider most appropriate.
This would increase the security of active sessions on the account and on the devices the owner uses, preventing anyone from deleting the other sessions. For example, if a device is lost or stolen, an unknown user would not be able to delete the remaining sessions without knowing the access credentials. Thus, the owner could tell if someone is using the account on the missing device, provided they still have an active session on another device linked to the same account.
I hope my suggestions are helpful and are not dismissed for future updates. Note: the only change needed is to add the option to enter a key in order to delete the other sessions, without altering the existing settings.
Kind regards to the entire Telegram development team.