Earlier quoted context omitted.
Both of these rhetorical claims are misinformation. Please don't do this. Telegram messages are encrypted at rest on Telegram's servers with the keys held by Telegram the company. [1] MTProto is fully open-source. [2] Here's a FAQ of Telegram's most frequent criticisms. [3] [1] https://telegram.org/faq#q-do-you-process-data-requests [2] https://core.telegram.org/mtproto [3] https://telegra.ph/How-really-secure-and-pr…
I wish it was different, but it isn't. Mtproto v2 seems OK, but it is not default, so hardly used. Server side encryption protects against very little. I like Telegram, but not for security. Nobody should.
Looking back at how Signal works
211–220 of 301 posts
Re: Looking back at how Signal works
#212Earlier quoted context omitted.
Not within the spec. Which was sort of the point I was (poorly) trying to make - that it's a huge caveat, but otherwise a decent fallback if and when that changes. Google is adding an implementation into Messages, and it's honestly not a critical problem if OS vendors are supporting it at that level, but there's still too much we don't know about it imo. Will that be supported by iOS, if and when it supports RCS at a…
The only thing getting RCS any real traction is Google seems to be pushing it in their SMS application, and is now running an RCS server for everyone (or something). Which basically means, instead of having a federated mess as designed to replace the federated mess of SMS and MMS, we'll get a Google mess, maybe. But if Google was any good at making messenger apps, maybe enough people would use one of them that it wou…
Also how XMPP could have been that spec, if Google hadn't decided when launching (the first version of) Hangouts to go full Ayn Rand while doing it.
Re: Looking back at how Signal works
#213Earlier quoted context omitted.
I wish it was different, but it isn't. Mtproto v2 seems OK, but it is not default, so hardly used. Server side encryption protects against very little. I like Telegram, but not for security. Nobody should.
You wish what was different? My rebuttal specifically corrected false claims, without opinion.
Re: Looking back at how Signal works
#214Earlier quoted context omitted.
You wish what was different? My rebuttal specifically corrected false claims, without opinion.
The way you use encryption matters as much as the quality of the crypto used. In Telegrams case, usage is all wrong and not even better than e.g. WhatsApp. Opt-in E2EE is worse than having it be default, and server side encryption with server side keys is bordering on the pointless.
I use Telegram because it delights its users. When I have tried to bring friends and family to first Riot, then Signal, the experience I encountered was one of frustration, whether it was messages unexpectedly not syncing or delivering, the pain of cross-signing new devices for E2EE (RiotX), or the paucity of features. I have tried nearly every messenger that exists in an effort to seek out a usable compromise for laypeople and Telegram has been the only one to make that bar.
We use Matrix in my workplace because I can count on the employees being technical and patient enough to forgive having to input a multitude of varying passwords in succession just to get their session going.
Re: Looking back at how Signal works
#215Earlier quoted context omitted.
If I understand your description, you reset your account. They delete the messages for safety when you reset. An attacker could reset by getting ahold of your phone number by sim jacking or the govt getting your text. It's a safety method so no one can take you texts. Of course many people want to carry their texts along, but this is a safety risk if you lost control over your number. So that's what signal is doing.…
No, I had removed the app from my mobile previously, not deleted my account. When I resynced, they had removed my account and the messages saved on my desktop disappeared.
Re: Looking back at how Signal works
#216Earlier quoted context omitted.
If I understand your description, you reset your account. They delete the messages for safety when you reset. An attacker could reset by getting ahold of your phone number by sim jacking or the govt getting your text. It's a safety method so no one can take you texts. Of course many people want to carry their texts along, but this is a safety risk if you lost control over your number. So that's what signal is doing.…
No, I had removed the app from my mobile previously, not deleted my account. When I resynced, they had removed my account and the messages saved on my desktop disappeared.
If you did not delete the Signal directory on your phone then there should be some old backups with your messages there. These will be encrypted so you will need to original password to unencrypt them.
Re: Looking back at how Signal works
#217I love Signal and use it as much as I can, but I'm thinking of switching to Matrix solely because the desktop client is pretty bad. It won't show me messages until it syncs everything (so I can't even see old messages while things sync), and, what's worse, it skips messages, and multi-device just doesn't work. My laptop just shows "Message could not be decrypted" until I delete everything and reset. I'm not sure why…
I, for one, have a bigger problem with it forcing the use of phone numbers as a sign-in method. They're an arbitrary identifier from a legacy system that there's not really a point in continuing to extend, because if your device is capable of anything more advanced than SMS it's also capable of... well, this. Also KaiOS and the like are making chat feasible even on feature phones. Don't get me wrong, RCS will be a fi…
Re: Looking back at how Signal works
#218Is it worth trying to move my friends from WhatsApp to Signal? As I understand it, they're both e2e encrypted. I'm also trying to move my chats from SMS and Gchat to something encrypted, but am torn between WhatsApp and Signal. The former has more of a buy-in with my contacts already. I realize WhatsApp is owned by Facebook, but isn't the whole point of e2e encryption that you don't have to trust the intermediate inf…
The important distinction here is that WhatsApp uploads your entire contact book to Facebook. They have up-to-date information on your entire real-life social graph (including people who are not on Facebook and/or never shared their phone with Facebook) and the groups you belong to. If you don't believe me, request a copy of your data in WhatsApp and see for yourself.
So, by using WhatsApp, you are basically snitching on your friends and uploading their data.
Think about the implications — one day, you or one of your friends will add a phone number to Facebook (of course, "for security purposes only, to recover your account". From that moment, Facebook will be able to link an online identity to an offline one, and mine a trove of data: friends, groups, locations.
If you want a different way of looking at it, Facebook paid $19 billion for WhatsApp. That's how much it was worth to them. You don't spend 19 billion dollars just to watch e2e encrypted messages fly by.
I admire the way WhatsApp markets itself as the "encrypted" communications app, somehow hiding the whole problem with groups and contacts as insignificant. Another frequently seen spin is on Signal: that it "only hashes" the phone numbers and that it's "effectively the same thing". Good PR moves, both.
Re: Looking back at how Signal works
#219Is it worth trying to move my friends from WhatsApp to Signal? As I understand it, they're both e2e encrypted. I'm also trying to move my chats from SMS and Gchat to something encrypted, but am torn between WhatsApp and Signal. The former has more of a buy-in with my contacts already. I realize WhatsApp is owned by Facebook, but isn't the whole point of e2e encryption that you don't have to trust the intermediate inf…
The metadata is the difference. Your contact graph is fair game on WhatsApp for Facebook
Re: Looking back at how Signal works
#220Earlier quoted context omitted.
> Meanwhile, yes, Matrix took years to add encryption, but it works much better than Signal, even with quite a few small bugs. I'm not sure which Matrix client you use, but clients like Riot don't even let you opt out of sending read receipts unless you edit `/etc/riot/config.json` to enable experiments and then go into the settings to disable read receipts. Problems like this (and issues like this [0]) give me the i…
I'm a massive Matrix fan and have high hopes for it but in experiments we've done with activist and journalist partners we've found the Riot.im client often gets a bit complicated for people to use. I think the main issue people have is related to keys. As I techie I love the options but I find many don't like having all the options. Signal of course is a lot easier as it hides many of those issues in the UI/UX.
Hopefully none of that changes now that they've been acquired by zoom.