On 2021-07-09 at ~19:30 Greenwich time many users of this forum have received multiple malicious notifications in their Telegram clients. See the screenshot.
This was surprising to say the least, but after reading the text it became clear that it's a troll who cleverly altered his (user)name and left comments in the forum, triggering notification system for thousands of people.
Very important:
A) Notification came from official Telegram Security Notification System (the same one that sends you 2FA-codes and login attempts!)
B) The (user)name was clickable and transferred users to a channel.
This is possible thanks to the following security flaws:
Using Telegram Security Notifications for forum posts is a BAD idea. There should be, and should always have been, a dedicated official channel or bot for this.
This is a usability issue as well: users who actively participate on this forum can get “spammed” with replies day and night. The only way to stop this is to mute the Telegram Security Notifications. Which in itself constitutes a second security issue:users missing real security notifications (like remote login attempts) because their Security Notifications System is muted.
Forum notifications should not include clickable text other than link to the forum, where you can read comment and interact with it safely outside Telegram client.
Names and usernames should not be able to contain clickable elements (like @usernames, http://links and #hashtags) within them anywhere in and outside the platform.
To be honest, I have anticipated something like this would happen from the very first day that this forum went online with current notification system implemented. So I am happy that this came to light in form of harmless trolling, because it could have been used maliciously. I believe that, as long as the above issues are not addressed, they can be exploited again in a bad way.
Yes, I have reported this as an "Issue" as well. But security issues are hidden from the forum. Since this particular issue is not new and of public knowledge, I have reposted it in Suggestions section for documentation and discussion purpose.
PJ
4.5 years and about 2000 SPAM and SCAM messages later, this issue is finally solved, the bug is fixed, solution is implemented. Exactly as in OP and exactly als should have been FROM DAY ONE.
@admindog Please close this shameful thread as [FIXED].
@admindog Please close this shameful thread as [FIXED].