Skip to main content

Ten minutes that make your account much harder to steal

Most compromised messaging accounts are not broken into — they are handed over, one login code at a time. Six settings and a little scepticism close that door.

Telegram two-step verification screen with password, recovery email and active session list
Two-step verification plus a recovery email: the highest-value ten minutes you will spend in settings.

The six-step hardening pass

  1. STEP 012 min

    Turn on two-step verification

    Privacy and Security → Two-Step Verification. Set a password and add a recovery email in the same visit. From then on, an intercepted SMS code alone is not enough to sign in as you.

  2. STEP 021 min

    Audit active sessions

    Devices lists every authorised client with its location and last activity. End anything unfamiliar, and end sessions on computers you no longer use even if you recognise them.

  3. STEP 032 min

    Hide your phone number

    Privacy and Security → Phone Number → Nobody, then allow the specific contacts who should see it. Set Who can find me by my number to My Contacts at the same time.

  4. STEP 041 min

    Tighten last seen and profile photo

    Both can be limited to contacts or nobody, with exceptions. Note that hiding your last seen also hides everyone else's from you.

  5. STEP 052 min

    Set an app passcode

    On mobile, add a passcode lock backed by Face ID or a fingerprint so a borrowed or lost phone does not expose the chat list.

  6. STEP 062 min

    Decide on auto-delete

    Individual chats can clear themselves after a day, a week or a month. Useful for conversations that contain addresses, codes or documents you do not want sitting around.

Three kinds of conversation, three security models

Confusion about this is the source of most arguments about Telegram's security. The trade-off is deliberate: cloud chats buy convenience and multi-device sync, secret chats buy secrecy and give up both.

Conversation typeStored whereEncryptionPractical effect
Cloud chatsEvery device you sign in onEncrypted in transit and at rest on the serverHistory survives a lost phone and syncs everywhere. This is the default and covers groups and channels too.
Secret chatsOnly the two mobile devices involvedEnd-to-end encrypted, no server copyNothing syncs, nothing is recoverable if the device is lost, and screenshots can be flagged. Optional self-destruct timers.
Voice and video callsThe two devices on the callEnd-to-end encryptedBoth sides can compare emoji fingerprints to confirm the connection is not relayed through anyone else.

How to spot a tampered installer

Check the file size against the published figure

The Windows installer is around 48.6 MB. A 2 MB "installer" is a downloader for something else; a 300 MB one has been repackaged with extras.

Be suspicious of bundled offers

The real setup never proposes toolbars, system cleaners or a second browser. If a checkbox offers you something extra, stop and delete the file.

Refuse anything that demands a password up front

An archive that needs a password to extract exists to defeat scanners. There is no legitimate reason for a chat client to ship that way.

Never enter your login code into a website

The code authorises a device. Anyone asking for it — by chat, by phone or in a form — is asking to become you.

Telegram data and storage settings limiting automatic media downloads
Limiting automatic downloads is a security measure as much as a data one: nothing arrives on disk unasked.

If you think an account is compromised

End every session except the one you are using, change the two-step password, then check Privacy and Security for forwarding or auto-delete settings you did not choose yourself.

Installers and their published sizes are listed on the download page, and the setup guides show where each of these settings lives on every platform.