Live data from Hacker News

Introducing Telegram Passport

telegram.org

41–50 of 85 posts

Re: Introducing Telegram Passport

#41

I really wish telegram would focus on being a messaging app and not whatever this is. I'm not going to trust them with my info.

Remember, it's not a mandatory thing, you can continue to use telegram just like whatsapp.

But telegrams apps and Bots are growing exponentially and the developers unnecessarily keeping a basic work flow outside telegram, which is painful.

Re: Introducing Telegram Passport

#43
The unintented consequence of this will be that now any website can easily demand real life ID. Ordinary, non-financial websites (think Reddit, Twitter, Hacker News) will require ID to log in, to protect against spam and make the community safer.

This implements the dream of authoritarian governments that internet access should never be anonymous. Russian government officials have long wanted to establish a similar authentication system.

Is Pavel with us or against us?

Re: Introducing Telegram Passport

#44
post #43

The unintented consequence of this will be that now any website can easily demand real life ID. Ordinary, non-financial websites (think Reddit, Twitter, Hacker News) will require ID to log in, to protect against spam and make the community safer. This implements the dream of authoritarian governments that internet access should never be anonymous. Russian government officials have long wanted to establish a similar a…

Many people don't use Telegram and presumably most sites can't afford to alienate that many people.

Re: Introducing Telegram Passport

#45
post #9
post #3

Would Telegram and others please stop using phone number as a primary source of identity? It's 2018, I have a data only sim and I have no desire to have a phone number.

I think everyone wants phone numbers to prevent people generating billions of accounts to spam people with.

That seems like a pretty crummy way to solve that particular problem.

Re: Introducing Telegram Passport

#46
post #37

Earlier quoted context omitted.

keybase is a proprietary walled garden.. so.. no thanks.

Proprietary? The backend maybe, but the keybase clients are open source. Some of the code is a little rough, and completed API docs would be nice, especially concerning KBFS, which is still missing. It's still under heavy development though, so these shortcomings should be understandable. (I personally won't use it much until I can actually develop my own non-reverse-engineered client, but that's just my requirement.…

No, the server implementation is proprietary. Therefore, it's a walled garden that relies entirely on them. Supporting federation would be going above/beyond just releasing the server implementation's source under a permissive license. As it stands today, you have no choice but to rely on their proprietary server implementation, since the clients are useless on their own.

Re: Introducing Telegram Passport

#47
post #16

Earlier quoted context omitted.

I cannot up-vote this more. Many people don't realise that they don't own their phone number! It is possible to own a phone number but it is not widely available just like domains are. Hence it is a stupid idea to use it as an identity.

I recently learned this the hard way. I changed my phone number after moving cities, and AT&T just leased my old number to someone else!

What did you expect was going to happen?

Re: Introducing Telegram Passport

#49
post #3

Would Telegram and others please stop using phone number as a primary source of identity? It's 2018, I have a data only sim and I have no desire to have a phone number.

This is possible? Or do you technically have a phone number but just don't use it? Also, don't lots of situations require you to give a phone number? How do you handle that?

Re: Introducing Telegram Passport

#50
post #37

Earlier quoted context omitted.

Proprietary? The backend maybe, but the keybase clients are open source. Some of the code is a little rough, and completed API docs would be nice, especially concerning KBFS, which is still missing. It's still under heavy development though, so these shortcomings should be understandable. (I personally won't use it much until I can actually develop my own non-reverse-engineered client, but that's just my requirement.…

No, the server implementation is proprietary. Therefore, it's a walled garden that relies entirely on them. Supporting federation would be going above/beyond just releasing the server implementation's source under a permissive license. As it stands today, you have no choice but to rely on their proprietary server implementation, since the clients are useless on their own.

Considering the whole point of end-to-end encryption is to reduce or eliminate necessary trust in the middleman, this seems like a minor, but still valid concern. Open sourcing the backend code wouldn't allow you to attest to what's running on the server. If the clients also allowed you to point to a custom server URL, which I would support, then the source availability might matter.
Post reply on HN