Live data from Hacker News

Introducing Telegram Passport

telegram.org

51–60 of 85 posts

Re: Introducing Telegram Passport

#51

Their messaging application had horrible security in past, and there have been many discussions on HN about Telegram vs Signal. Why would I trust them for ID when their messaging was suspicious....

Please, provide sources if you’re willing to say something like that.

Re: Introducing Telegram Passport

#52

Earlier quoted context omitted.

I recently learned this the hard way. I changed my phone number after moving cities, and AT&T just leased my old number to someone else!

There is a finite supply of numbers. Not recycling old numbers and just throwing them in a hole forever wouldn't be very prudent.

There is an infinite supply of numbers. You can just add extra digits. Mobile phone numbers used to be 8 digits in NZ, then became 9 digits when they needed more numbers.

Re: Introducing Telegram Passport

#53
post #50

Earlier quoted context omitted.

No, the server implementation is proprietary. Therefore, it's a walled garden that relies entirely on them. Supporting federation would be going above/beyond just releasing the server implementation's source under a permissive license. As it stands today, you have no choice but to rely on their proprietary server implementation, since the clients are useless on their own.

Considering the whole point of end-to-end encryption is to reduce or eliminate necessary trust in the middleman, this seems like a minor, but still valid concern. Open sourcing the backend code wouldn't allow you to attest to what's running on the server. If the clients also allowed you to point to a custom server URL, which I would support, then the source availability might matter.

Without the proprietary server backend, you cannot use the clients. It's a walled garden. If keybase goes away for whatever reason, you're stuck. You cannot host it yourself, others cannot host it, and even if they released binaries, you'd have no idea what it is doing with the unencrypted 'metadata'.

Re: Introducing Telegram Passport

#55

Earlier quoted context omitted.

I recently learned this the hard way. I changed my phone number after moving cities, and AT&T just leased my old number to someone else!

There is a finite supply of numbers. Not recycling old numbers and just throwing them in a hole forever wouldn't be very prudent.

Numbers aren't limited to the amount you can count, there will always be more.

Re: Introducing Telegram Passport

#56
post #3

Would Telegram and others please stop using phone number as a primary source of identity? It's 2018, I have a data only sim and I have no desire to have a phone number.

Same. I'm nomadic at the moment, and have to change sims with each country. I don't have a permanent phone number (or address). I know I'm in a minority, but still... it's like things businesses assume about people: 1: they have a phone number. 2: they have an address. 3: the country they are in at the moment is the country they live in

Project Fi from Google has been a lifesaver for me while traveling. I get to use the same number everywhere I go and don't have to do the new SIM dance in every country I visit. It can also be very handy sometimes to have internet access minutes after hitting the tarmac.

They've also expanded it to support more phones recently. I think having a Fi phone, even if it's not your primary device, makes a lot of sense for nomads.

Re: Introducing Telegram Passport

#57
post #13
post #11

Earlier quoted context omitted.

Agreed that such services should stop using phone numbers. In the meantime, you can get inexpensive numbers from https://jmp.chat/ - useful for 2FA as well.

Yeah I use Google Voice for this purpose, which isn't _really_ 2fa anyway (because it's my google account).

Some services somehow know that the phone number is VoIP (Google Voice) and disallow you from using it with TFA. IIRC, Steam is one example.

Re: Introducing Telegram Passport

#59
post #51

Their messaging application had horrible security in past, and there have been many discussions on HN about Telegram vs Signal. Why would I trust them for ID when their messaging was suspicious....

Please, provide sources if you’re willing to say something like that.

https://gizmodo.com/why-you-should-stop-using-telegram-right...
Post reply on HN