Better protection against session and account hijacks
Steps to reproduce
Telegram session and account hijacks are major issue and most users are not aware of the danger. Hijacking Telegram desktop session, especially in Windows is far too easy and phone number is not protecting account as hijacker can kill all sessions and set up 2FA password and prevent real user from logging in. Here is some suggestions for improving protections against session or account hijacks.
device bound session credentials or binding telegram session to security chip of a PC device. Thus attacker could not just copy-paste telegram user folder to new computer and log in.
pressing "terminate all other sessions"-button should send SMS code confirmation to the registered phone number. If you are in high risk of SIM swap attack then there should be other protection model but for majority of users this is unrelevant attack vector.
there is probably many more ways to prevent these sort of attacks.
Device info
Telegram Desktop 6.5.1 x64, Desktop, Windows 11 x64