Live data from Hacker News

Show HN: TrashEmail – Telegram-based disposable mail service

github.com

81–90 of 105 posts

Re: Show HN: TrashEmail – Telegram-based disposable mail service

#81

Earlier quoted context omitted.

Telegram non-E2E is more than just TLS, though.

What more do they do? I'm not aware.

It is documented here: https://core.telegram.org/mtproto

These layers are used in addition to any encryption done on the transport layer.

Re: Show HN: TrashEmail – Telegram-based disposable mail service

#83
post #46

Earlier quoted context omitted.

Telegram have said that you can’t trust Signal because the developers live in the US and something something the CIA, which is pretty ridiculous. They rolled their own crypto and they aren’t cryptographers, which should be reason enough not to trust its security: https://security.stackexchange.com/questions/49782/is-telegr...

This answer is ridiculous. They got world level mathematicians in their team, what more do you want? Who are those "cryptographers"? And why those cryptographers don't break Telegram if they think that their crypto is broken? Again, crypto is either broken or not. Telegram crypto is not broken. It's fine. Not everyone might like it, but that does not matter. I don't know story about CIA (although I wouldn't be surpri…

Mathematicians are not cryptographers. Crypto is harder to trust when the rationale behind it hasn’t been justified. Signal’s crypto is very easy to justify. That’s about it.

Re: Show HN: TrashEmail – Telegram-based disposable mail service

#84

Earlier quoted context omitted.

does it protect you from taking a picture of your phone? i'd rather have a foundation of properly functioning, award winning cryptography than "features" designed for people who haven't thought through their threat model sufficiently. castles made of sand melt into the sea eventually

My threat model with nudes are different from my whistle blowing. Signal also makes trade offs in order to het crypto to the masses.

Yeah, but “supporting plaintext comms by default” is not a trade off to get crypto to the masses, it’s a failure to do so at all. What’s wrong with the disappearing messages feature?

Re: Show HN: TrashEmail – Telegram-based disposable mail service

#85
post #17

Earlier quoted context omitted.

Signal

Signal leaks your telephone number to everyone with whom you communicate, which is a privacy disaster before you even send your first message. (Please don't take this as implicit approval for Telegram's approach to secure messaging, but at least they managed not to cock up in such a basic way.)

This has been explained on HN ad nauseam. It leaks less metadata than anything else, the phone number is the only metadata that it leaks (only to people you’re messaging, mind), and they’re working on a solution to that problem right now. It works that way because the developers wanted to avoid holding a central server with metadata for their entire user base. Instead it uses your local contact list to discover other users. I would say that being unencrypted by default and having a centralized metadata directory in plaintext is more of a cock-up in secure messaging than taking a rigorous and cautious approach to metadata leakage.

Re: Show HN: TrashEmail – Telegram-based disposable mail service

#86

Earlier quoted context omitted.

What more do they do? I'm not aware.

It is documented here: https://core.telegram.org/mtproto These layers are used in addition to any encryption done on the transport layer.

Fair enough, but they have the keys for that layer, I don’t see how that’s an improvement over TLS.

Re: Show HN: TrashEmail – Telegram-based disposable mail service

#87
post #23

Earlier quoted context omitted.

> This doesn't make it not reasonably secure in my mind. While the TG people will be able to access your messages, they can also process them, making stuff like large groups even possible (imagine the distribution hell otherwise). So your standard for “reasonably secure” communications is Facebook Messenger?

No. You're using the same "if it's not perfect it's worthless" argumentation as GP. It's not perfect, nothing is. But it makes better compromises than others.

It’s worthless as a “secure messenger.” They can read and store all the messages unless you use the E2E mode.

Re: Show HN: TrashEmail – Telegram-based disposable mail service

#88
post #85

Earlier quoted context omitted.

Signal leaks your telephone number to everyone with whom you communicate, which is a privacy disaster before you even send your first message. (Please don't take this as implicit approval for Telegram's approach to secure messaging, but at least they managed not to cock up in such a basic way.)

This has been explained on HN ad nauseam. It leaks less metadata than anything else, the phone number is the only metadata that it leaks (only to people you’re messaging, mind), and they’re working on a solution to that problem right now. It works that way because the developers wanted to avoid holding a central server with metadata for their entire user base. Instead it uses your local contact list to discover other…

The constant repetition is indeed nauseating. It's also nonsense.

There is another unique identifier that's stored in the local contact list: email addresses.

Use either email address or a phone number as an identifier, and you've no longer built a offensively privacy-violating service but have exactly the same distributed property.

Re: Show HN: TrashEmail – Telegram-based disposable mail service

#89
post #85

Earlier quoted context omitted.

This has been explained on HN ad nauseam. It leaks less metadata than anything else, the phone number is the only metadata that it leaks (only to people you’re messaging, mind), and they’re working on a solution to that problem right now. It works that way because the developers wanted to avoid holding a central server with metadata for their entire user base. Instead it uses your local contact list to discover other…

The constant repetition is indeed nauseating. It's also nonsense. There is another unique identifier that's stored in the local contact list: email addresses. Use either email address or a phone number as an identifier, and you've no longer built a offensively privacy-violating service but have exactly the same distributed property.

You can use any phone number to sign up, it doesn’t have to be the one on your SIM. The rationale is that people typically text using phone numbers, and they wanted to make it easier to text people securely. It’s not nonsense, it makes perfect sense, and again, they’re working on it: https://signal.org/blog/signal-pins/

If you only have access to one phone number and not giving it out is critical, then Signal might not be the right choice for you. But you won’t find a more secure channel that collects less metadata anywhere else.

Re: Show HN: TrashEmail – Telegram-based disposable mail service

#90

Earlier quoted context omitted.

Email has no E2E and people still use it all the time, for much more sensitive things than get sent over whatsapp and such.

What's your point? I'd rather not assume you're saying "privacy doesn't matter because people don't care about it" or "Email is more private because people think it's more private".

The point is that it doesn't make sense to be paranoid about no E2E if you still use emails for sending/receiving sensitive info.
Post reply on HN