Earlier quoted context omitted.
Telegram non-E2E is more than just TLS, though.
What more do they do? I'm not aware.
These layers are used in addition to any encryption done on the transport layer.
81–90 of 105 posts
Earlier quoted context omitted.
Telegram non-E2E is more than just TLS, though.
What more do they do? I'm not aware.
These layers are used in addition to any encryption done on the transport layer.
How does this bot differ from this existing one?
Earlier quoted context omitted.
Telegram have said that you can’t trust Signal because the developers live in the US and something something the CIA, which is pretty ridiculous. They rolled their own crypto and they aren’t cryptographers, which should be reason enough not to trust its security: https://security.stackexchange.com/questions/49782/is-telegr...
This answer is ridiculous. They got world level mathematicians in their team, what more do you want? Who are those "cryptographers"? And why those cryptographers don't break Telegram if they think that their crypto is broken? Again, crypto is either broken or not. Telegram crypto is not broken. It's fine. Not everyone might like it, but that does not matter. I don't know story about CIA (although I wouldn't be surpri…
Earlier quoted context omitted.
does it protect you from taking a picture of your phone? i'd rather have a foundation of properly functioning, award winning cryptography than "features" designed for people who haven't thought through their threat model sufficiently. castles made of sand melt into the sea eventually
My threat model with nudes are different from my whistle blowing. Signal also makes trade offs in order to het crypto to the masses.
Earlier quoted context omitted.
Signal
Signal leaks your telephone number to everyone with whom you communicate, which is a privacy disaster before you even send your first message. (Please don't take this as implicit approval for Telegram's approach to secure messaging, but at least they managed not to cock up in such a basic way.)
Earlier quoted context omitted.
What more do they do? I'm not aware.
It is documented here: https://core.telegram.org/mtproto These layers are used in addition to any encryption done on the transport layer.
Earlier quoted context omitted.
> This doesn't make it not reasonably secure in my mind. While the TG people will be able to access your messages, they can also process them, making stuff like large groups even possible (imagine the distribution hell otherwise). So your standard for “reasonably secure” communications is Facebook Messenger?
No. You're using the same "if it's not perfect it's worthless" argumentation as GP. It's not perfect, nothing is. But it makes better compromises than others.
Earlier quoted context omitted.
Signal leaks your telephone number to everyone with whom you communicate, which is a privacy disaster before you even send your first message. (Please don't take this as implicit approval for Telegram's approach to secure messaging, but at least they managed not to cock up in such a basic way.)
This has been explained on HN ad nauseam. It leaks less metadata than anything else, the phone number is the only metadata that it leaks (only to people you’re messaging, mind), and they’re working on a solution to that problem right now. It works that way because the developers wanted to avoid holding a central server with metadata for their entire user base. Instead it uses your local contact list to discover other…
There is another unique identifier that's stored in the local contact list: email addresses.
Use either email address or a phone number as an identifier, and you've no longer built a offensively privacy-violating service but have exactly the same distributed property.
Earlier quoted context omitted.
This has been explained on HN ad nauseam. It leaks less metadata than anything else, the phone number is the only metadata that it leaks (only to people you’re messaging, mind), and they’re working on a solution to that problem right now. It works that way because the developers wanted to avoid holding a central server with metadata for their entire user base. Instead it uses your local contact list to discover other…
The constant repetition is indeed nauseating. It's also nonsense. There is another unique identifier that's stored in the local contact list: email addresses. Use either email address or a phone number as an identifier, and you've no longer built a offensively privacy-violating service but have exactly the same distributed property.
If you only have access to one phone number and not giving it out is critical, then Signal might not be the right choice for you. But you won’t find a more secure channel that collects less metadata anywhere else.
Earlier quoted context omitted.
Email has no E2E and people still use it all the time, for much more sensitive things than get sent over whatsapp and such.
What's your point? I'd rather not assume you're saying "privacy doesn't matter because people don't care about it" or "Email is more private because people think it's more private".