Live data from Hacker News

Ask HN: How do we know Signal or Telegram don't store our data on their servers?

news.ycombinator.com

151–160 of 241 posts

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#151

Earlier quoted context omitted.

What did you switch to?

I’ve been using Mullvad since the past few years and I’ve no complaints. The fact that the recent Mozilla VPN is based on Mullvad makes me more confident in my decision.

Any thoughts on airvpn.org?

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#152

While not directly about data storage, I loved this tweet [1] from Edward Snowdon this week: > do we really trust signal? cause i see zero reason to. Here's a reason: I use it every day and I'm not dead yet. [1] https://twitter.com/Snowden/status/1347217810368442368?s=20

I like this reason because you don't need to know anything about tech at all to be able to understand this. You also don't need to trust or like Snowden. If you view Snowden as a hero or a traitor, it changes nothing. All you need to trust is that he's got no reason to lie about using Signal, and neither does Elon Musk.

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#153

Earlier quoted context omitted.

PIA used to be my go-to, but I immediately ceased using PIA after the 2019 acquisition by Kape Technologies, which has a rather foul track record.

What did you switch to?

Like many others here, Mullvad. I've also been experimenting with ProtonVPN because it was offered as part of a bundle with ProtonMail.

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#154

Signal’s claim to fame here is that they were subpoenaed in 2016 and could only supply account creation and last connection times: > The American Civil Liberties Union announced Tuesday that Open Whisper Systems (OWS), the company behind popular encrypted messaging app Signal, was subpoenaed earlier this year by a federal grand jury in the Eastern District of Virginia to hand over a slew of information—"subscriber na…

Signal may have only supplied that metadata at the time. But what I am concerned about is that if Signal is US-based, couldn’t the state demand Signal’s app signing key via a NSL, and couldn’t that signing key then be used for targeted attacks by which someone of interest gets a Signal app upgrade that is malicious (while everyone else gets the non-malicious app)? I admit to being somewhat unfamiliar with Android distribution through the Play Store, so if this is unfeasible, help me understand why.

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#155

Earlier quoted context omitted.

What I don't get is people are trusting unverifiable builds of Signal, Telegram, WhatsApp, etc as "secure" on each of their E2EE implementations when that part of the binaries we install on our phones isn't even verifiable by code and compilable by ourselves. But what I do like about Telegram is their good user experience and Bot API developer experience. It's soooooooooo fucking good I'm telling you. It just works,…

> At this point who the fuck knows if Durov can be trusted (hell we all wish, right, no harm in that). It's a threat model decision. If you're someone who wants privacy from the US or other Western governments (think Antifa on the left side, or corona-deniers, qanons and other conspiracy nuts on the right side), Telegram is the best option since the Western governments can't hold them accountable. If you're a Russian…

Isn’t Telegram now based in Dubai, an emirate within a country that largely allies with the West?

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#156
post #98

Earlier quoted context omitted.

I think this discussion should also mention that Signal is a non-profit organization, dedicated to enabling secure and private communications. Yes, it's not strong proof, but it should be taken into account when comparing the goals and motivations of organizations developing various other communicators. The organization behind your communicator app could be in the business of gathering data about you and selling it i…

I prefer to look at the history of who founded and continues to run the Signal Foundation... Moxie Marlinspike. Moxie has a long history of improving security in all kinds of tech and fighting for privacy. The Signal app itself is opensource as well various pieces of the tech stack. You can audit yourself what is being sent and how their protocols work. The protocol itself has won awards due to its security and elega…

Curious. Is there an easy way to validate the code running on my phone is exactly the same code available on Github (here: https://github.com/signalapp) ?

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#157

Earlier quoted context omitted.

I prefer to look at the history of who founded and continues to run the Signal Foundation... Moxie Marlinspike. Moxie has a long history of improving security in all kinds of tech and fighting for privacy. The Signal app itself is opensource as well various pieces of the tech stack. You can audit yourself what is being sent and how their protocols work. The protocol itself has won awards due to its security and elega…

Curious. Is there an easy way to validate the code running on my phone is exactly the same code available on Github (here: https://github.com/signalapp ) ?

I don't believe so directly, but you can build it yourself and put it on your phone. You'll still be able to use your account and their service.

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#158

Earlier quoted context omitted.

What I don't get is people are trusting unverifiable builds of Signal, Telegram, WhatsApp, etc as "secure" on each of their E2EE implementations when that part of the binaries we install on our phones isn't even verifiable by code and compilable by ourselves. But what I do like about Telegram is their good user experience and Bot API developer experience. It's soooooooooo fucking good I'm telling you. It just works,…

> At this point who the fuck knows if Durov can be trusted (hell we all wish, right, no harm in that). It's a threat model decision. If you're someone who wants privacy from the US or other Western governments (think Antifa on the left side, or corona-deniers, qanons and other conspiracy nuts on the right side), Telegram is the best option since the Western governments can't hold them accountable. If you're a Russian…

There are many anti fascists in Russia too. In general anti fascists face repression from every nation state

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#159
Signal: operations that involve sending your contacts (like contact discovery) use a pattern Signal invented where the client can validate the software running on the server. The server runs inside the SGX secure enclave. Before your client sends any data, it performs remote attestation on the running server code to ensure it matches the published open source code.

See the full explanation at https://signal.org/blog/private-contact-discovery/ (starts part way down, with "trust but verify"). Or check the client source code yourself!

Telegram: I dunno, they.re closed source, don't encrypt by default, and have shady ownership. I don't trust them at all, personally.

Re: Ask HN: How do we know Signal or Telegram don't store our data on their servers?

#160
post #53

Earlier quoted context omitted.

Is it possible that they could in fact produce this data but were prevented from publicly saying so due to a gag order? I'm asking specifically because I remember Private Internet Access, a VPN provider, also being tested in court in the past [1], and because of this I've chosen to trust them despite them falling under Five Eyes jurisdiction. [1] https://torrentfreak.com/private-internet-access-no-logging-...

PIA used to be my go-to, but I immediately ceased using PIA after the 2019 acquisition by Kape Technologies, which has a rather foul track record.

Thanks for the heads up. Really excited to see a lot of folks here agree on Mullvad as a good alternative.
Post reply on HN