Live data from Hacker News

Ask HN: How do we know Signal or Telegram don't store our data on their servers?

news.ycombinator.com

131–140 of 241 posts

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#131

It's important to note that Telegram does store all your data by default as they do not enable E2EE for everything like Signal does. So if you're under the assumption that they don't, this is incorrect. Telegram, for all intents and purposes, is about as secure as using Facebook. The best you can do with Telegram is hope they don't sell out or get compromised at some point in the future, because all your private comm…

What I don't get is people are trusting unverifiable builds of Signal, Telegram, WhatsApp, etc as "secure" on each of their E2EE implementations when that part of the binaries we install on our phones isn't even verifiable by code and compilable by ourselves. But what I do like about Telegram is their good user experience and Bot API developer experience. It's soooooooooo fucking good I'm telling you. It just works,…

> At this point who the fuck knows if Durov can be trusted (hell we all wish, right, no harm in that).

It's a threat model decision. If you're someone who wants privacy from the US or other Western governments (think Antifa on the left side, or corona-deniers, qanons and other conspiracy nuts on the right side), Telegram is the best option since the Western governments can't hold them accountable. If you're a Russian or Chinese dissident, or opposition in countries aligned with them (e.g. Serbia) Whatsapp and Facebook are your best bet.

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#132

It's important to note that Telegram does store all your data by default as they do not enable E2EE for everything like Signal does. So if you're under the assumption that they don't, this is incorrect. Telegram, for all intents and purposes, is about as secure as using Facebook. The best you can do with Telegram is hope they don't sell out or get compromised at some point in the future, because all your private comm…

Yea, I believe telegram "secret chats" are E2EE and also have auto-destruct capabilities.

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#133

It's important to note that Telegram does store all your data by default as they do not enable E2EE for everything like Signal does. So if you're under the assumption that they don't, this is incorrect. Telegram, for all intents and purposes, is about as secure as using Facebook. The best you can do with Telegram is hope they don't sell out or get compromised at some point in the future, because all your private comm…

Yep and also keep in mind that FBI/DOJ capitol breach presser yesterday the FBI dude basically said “it’s hard to tell who is shit posting and who isn’t so it takes some elbow grease” which I take to mean that it’s OK to shit post. Just you know, don’t use computers for anything you want to keep secret.

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#134
post #98

Signal’s claim to fame here is that they were subpoenaed in 2016 and could only supply account creation and last connection times: > The American Civil Liberties Union announced Tuesday that Open Whisper Systems (OWS), the company behind popular encrypted messaging app Signal, was subpoenaed earlier this year by a federal grand jury in the Eastern District of Virginia to hand over a slew of information—"subscriber na…

I think this discussion should also mention that Signal is a non-profit organization, dedicated to enabling secure and private communications. Yes, it's not strong proof, but it should be taken into account when comparing the goals and motivations of organizations developing various other communicators. The organization behind your communicator app could be in the business of gathering data about you and selling it i…

I prefer to look at the history of who founded and continues to run the Signal Foundation... Moxie Marlinspike. Moxie has a long history of improving security in all kinds of tech and fighting for privacy.

The Signal app itself is opensource as well various pieces of the tech stack. You can audit yourself what is being sent and how their protocols work. The protocol itself has won awards due to its security and elegance.

There is a lot of good things to say about Signal and you can easily find it all. They have made some annoying or less than ideal features that are opt-out instead of opt-in but they're not sacrificing privacy for them.

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#135

Earlier quoted context omitted.

What did you switch to?

I’ve been using Mullvad since the past few years and I’ve no complaints. The fact that the recent Mozilla VPN is based on Mullvad makes me more confident in my decision.

Do you get decent speeds from Mullvad? Friends were reporting that they moved back to PIA due to worse speeds on Mullvad. That and the lack of a chrome extension (which is occasionally useful) has prevented me from switching away from PIA even if I'm unhappy about being in business with Karpeles and Kape.

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#136

Earlier quoted context omitted.

No, it does. In some cases (think dictatorship) - you not only want the secret police to not read your messages - you don't want them to know at all, who are you talking to(and how often and when!). Otherwise you might all go to jail (or worse), if they are after one contact of yours. And then you can try to feel save, that they don't know your encryption password. https://xkcd.com/538/

here https://www.deccanherald.com/national/north-and-central/jk-a... not allowed to use VPNs because national security issues. https://www.aa.com.tr/en/asia-pacific/india-launches-fresh-c... "social media muisuse" i remember last year this word was so much used, "misuse" which translates to criticizing the ruiling dictator government. it still is, https://thenextweb.com/in/2020/01/08/kashmirs-police-want-pe... here.…

Well, if a government goes authorian, than it does not matter much, what service you use, if you have to assume your phone has spyware on it.

If the main danger is, police scanning the phone for compromised material (without a police spyware on it), then there are some ways to deal with it technically, by using services that don't leave a trace. Telegram for example has a "secret chat" function, which won't save the messages, meaning someone scanning your phone later, won't find them.

(which I head is also a main reason for many people to join telegram, because so they can chat with their affairs and not have their wifes read it)

Then there are simply private tabs of chrome or ff, from where you can use chat-services without trace. (if the chat services are not cooperating with the police, or are decentralised by default, I think in that scenario I would use matrix)

Anyway, you live in kashmir?

I know mainly of the conflict by reading Shalimar the Clown, from Rushdie. Just curious about your opinion, if you know the book. I heard it was not well received in Kashmir itself? I think it was very well written, but I don't know how accurate it is.

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#137

Earlier quoted context omitted.

I’ve been using Mullvad since the past few years and I’ve no complaints. The fact that the recent Mozilla VPN is based on Mullvad makes me more confident in my decision.

Did you consider NordVPN? I like the fact that I get to login from anywhere in the world. My default choice is Sweden since they have the most lax copyright laws in the world, so subpoenaing any Swedish server gonna be tough. They also offered me unavoidable discount.

NordVPN may have good intentions but they were hacked.

https://techcrunch.com/2019/10/21/nordvpn-confirms-it-was-ha...

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#138
post #53

Signal’s claim to fame here is that they were subpoenaed in 2016 and could only supply account creation and last connection times: > The American Civil Liberties Union announced Tuesday that Open Whisper Systems (OWS), the company behind popular encrypted messaging app Signal, was subpoenaed earlier this year by a federal grand jury in the Eastern District of Virginia to hand over a slew of information—"subscriber na…

Is it possible that they could in fact produce this data but were prevented from publicly saying so due to a gag order? I'm asking specifically because I remember Private Internet Access, a VPN provider, also being tested in court in the past [1], and because of this I've chosen to trust them despite them falling under Five Eyes jurisdiction. [1] https://torrentfreak.com/private-internet-access-no-logging-...

They were bought by an adware tech company last year AFTER the events of the article you linked. I would suggest mullvad as a good alternative. I've had better speed and as good ease of use.

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#139
post #122
post #98

Earlier quoted context omitted.

I think this discussion should also mention that Signal is a non-profit organization, dedicated to enabling secure and private communications. Yes, it's not strong proof, but it should be taken into account when comparing the goals and motivations of organizations developing various other communicators. The organization behind your communicator app could be in the business of gathering data about you and selling it i…

> a non-profit organization > should be taken into account when comparing the goals and motivations of organizations developing various other communicators. Business or funding models can change for both for- and non-profit organizations. Especially as people move to options that are believed to have better user-privacy, the idea that they do not sell/monetize collected user data today does not indicate what they wil…

Whenever I see an ad flaunting privacy guarantees, I ask myself "How would a honey pot for gathering user's information be advertised?" Exactly the same way.

That said, at the end of the day you have to trust SOMEONE if you want to use digital communications. And there's certainly a difference between facebook and GPG email encryption.

It's just a matter of balancing convenience and privacy for your personal use case.

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#140
There's a lot about Signal in particular that they get right. AFAIK:

(1) All Signal messaging is E2EE; (2) they don't store messages on their servers; (3) the client code is open source, and it seems like a good portion of the server code is open source.

Where I think Signal could go further on being the most secure, useful, and privacy-conscious messaging app/company in the world:

1. Open source ALL of the server code. They have something called Signal-Server (https://github.com/signalapp/Signal-Server) on their Github, but it's unclear if this is the server they use, or simply a server one could theoretically use to run a private Signal server.

2. Open source all server-side services/infrastructure code that doesn't compromise security in some way.

3. Better features. Signal is currently the most secure and privacy-conscious of the messaging apps, but solidly the worst overall user experience. It's not that it's bad, it's just that the other apps are much better. People like gifs and giphy and emojis and a fast-feeling interface. This is important, because it's hard to be a privacy-conscious individual when all your friends want to text on other apps. At least in my social circle, Signal is still the thing that people jump over to when they want be extra super sure they're not leaving a paper trail, but not the default messaging app they use.

4. Introduce a user-supported business model. This probably makes a lot of people uneasy, and while I appreciate the current grant and donation-based business model (the Wikipedia model), that model comes at great cost of efficiency. By operating effectively as a non-profit, you are inherently in a less competitive position relative to your competitors (the best product and engineering people are more likely to go competitors who can pay more), and you're persistently in fund-raising mode (again, see: Wikipedia). There are lots of ways to skin this cat, maybe the easiest is to ask power users to pay like $5/mo. Or just give people the option to pay with absolutely zero obligation. Some non-zero cohort would inevitably take them up on this.

Most of these suggestions, of course, especially 1-3, are very very hard and come at an enormous cost. Building in public as an open source business seems to massively slows things down and introducing a huge amount of community management overhead. That said I'm sure there are ways to manage/mitigate those costs.

Post reply on HN