Live data from Hacker News

Telegram messaging app proves crucial to Belarus protests

latimes.com

471–480 of 557 posts

Re: Telegram messaging app proves crucial to Belarus protests

#471
post #447

Earlier quoted context omitted.

They're working on V2 groups, AFAIK it's in internal beta right now.

That's actually encouraging to hear!

It was internal alpha but whatever:

https://community.signalusers.org/t/beta-feedback-for-the-up...

The community forums are a wonderful place to follow the development BTW.

Re: Telegram messaging app proves crucial to Belarus protests

#472
post #387

It's not surprising that every time Telegram pops up here, many comments miss the fact that Telegram has a great UX, a great feature set and also provides the kind of privacy protestors value, i.e., not having their phone numbers flashed to every random stranger in groups or to random channel owners whose channels you've subscribed to. With Telegram you cannot even do a phone number enumeration attack (this can be ch…

" And nope, Signal doesn't make the cut for the above reasons because it exposes your phone number to everyone else " This is being worked on. The thing is you're mixing two threat models. One is a creepy dude who will give you nightly calls if they learn your phone number. The other is a state actor who will hack the server and track you based on your IP-address if no phone number is being used otherwise: hence the…

The "thing" is they're "mixing two threat models"? What does that mean?

I feel like they have 1 threat model and the "thing" is you're trying to decompose it into a mixture of black and white....

Re: Telegram messaging app proves crucial to Belarus protests

#473
post #442

Earlier quoted context omitted.

Since E2E encryption is not enabled by default in Telegram, I believe it's used by 2% of their users at most. Messages of the rest can be read by Telegram team. https://www.google.com/search?newwindow=1&q=are+telegram+cha...

> Since E2E encryption is not enabled by default in Telegram, I believe it's used by 2% of their users at most. You are probably answering another post here. I don't think it is intentional. > Messages of the rest can be read by Telegram team. Well, there are a number of ways to prevent that from happening easily. I cannot verify this, but Telegram said years ago that they solved certain problems by routing keys and…

"I cannot verify this, but Telegram said years ago that they solved certain problems by routing keys and messages through different datacenters in different jurisdictions."

Firstly, there is no proof of this happening. I've been looking for the documentation and/or source code for this for more than five years now, and it's never been published.

Secondly, even IF it was happening, the server that strips the in-transit encryption has access to the plaintext, and can copy the message to anywhere it damn pleases. It can write it to "plaintext-messages.txt" for all it cares, that's like two lines of Python in the backend.

Also, the servers creating database entries must by definition have the full database encryption key in its RAM, from where privileged processes can exfiltrate it (computer organization 101).

The thing is, there isn't technology out there that allows Telegram to do what it claims as securely as it claims. If they are indeed innovating on this, why aren't they publishing their research and proving their worth?

"they seem remarkable competent at certain aspects of what they do"

Yeah, you can be great at UX design and shitty at cryptography. That's perfectly fine. The fact they won't spend money to hire competent cryptographers is the shitty part. I don't know if it's this Russian pride wrt. Nikolai being an award winning mathematician, or if they don't really give a fuck and think damage control can mend the damage that resulted from nepotism.

Well, the first time they get hacked properly shows how shit the architecture was. We can only hope people will then ask "ok where the fuck did we go wrong, again, can we switch to something that fixed this once and for all", and that by then, Signal is usable enough for their needs.

Re: Telegram messaging app proves crucial to Belarus protests

#474

Earlier quoted context omitted.

Just in case anyone is wondering. The 'official' vote count for Thikhanovskaya is 588,622. So regardless of how unbiased a sample it may be the Telegram poll shows over 2x as many people (or phone numbers to be exact), willing to vote for Thikhanovskaya (at the time of writing). Use this information as you wish.

That's cool and all, except everyone in that country had 2 sim cards with 2 numbers. They don't have free long distance over there, nor are plans for cheap text+data the same plans as cheap calls. So I take this information to mean this poll was useless. Everyone who voted could vote twice, and felons and kids voted too.

Sure but both sides could do that right?

Re: Telegram messaging app proves crucial to Belarus protests

#475
post #385

Telegram created Belarus language public channel. And posted poll to vote for new president with some clever restrictions. Anyone can vote, but you can't choose options with candidates if your phone number is not Balarusian. "I am not from Belarus" is only available poll option to make your vote if your phone number is not Balarusian. There is currently 736'000 votes with that option. Telegram poll https://t.me/s/tel…

"Poll shows that 1,184 million choose to vote for new president Tikhanovskaya." It is possible that Telegram is being impartial and providing more honest statistics wrt. what the citizens want. But it's also the case the results are unverifiable data broadcasted from Telegram's server over TLS-equivalent connection. MITM attack of client-server encryption, as well as compromise of the server broadcasting the results…

Russian oligarch is very specific term[1], due to his age, Durov is missed time frame by 20 years to become one. Durov is Internet entrepreneur that is forced to become political expat, that's on the opposite spectrum from russian oligarch, like self made tech entrepreneur vs oil magnate trough inheritance.

[1] https://en.wikipedia.org/wiki/Russian_oligarch

Re: Telegram messaging app proves crucial to Belarus protests

#476
post #431

Earlier quoted context omitted.

Both four years old. Did they not improve since?

No. Still not E2EE by default, still no E2EE for groups, still no E2EE for desktop clients. Why do you want to imagine Telegram magically got better when it's so obvious it didn't?

Because they “magically” updated and improved tons of stuff in the last four years. So I think it’s not unreasonable to consider whether their encryption improved too.

But yes, not having encryption on by default speaks poorly of them. OTOH it’s not concrete proof that the encryption still sucks as of now.

Re: Telegram messaging app proves crucial to Belarus protests

#477
post #473

Earlier quoted context omitted.

> Since E2E encryption is not enabled by default in Telegram, I believe it's used by 2% of their users at most. You are probably answering another post here. I don't think it is intentional. > Messages of the rest can be read by Telegram team. Well, there are a number of ways to prevent that from happening easily. I cannot verify this, but Telegram said years ago that they solved certain problems by routing keys and…

" I cannot verify this, but Telegram said years ago that they solved certain problems by routing keys and messages through different datacenters in different jurisdictions. " Firstly, there is no proof of this happening. I've been looking for the documentation and/or source code for this for more than five years now, and it's never been published. Secondly, even IF it was happening, the server that strips the in-tran…

I think me and you agree to a large degree :-)

> Firstly, there is no proof of this happening. I've been looking for the documentation and/or source code for this for more than five years now, and it's never been published.

I haven't found anything more either. See also below.

> Secondly, even IF it was happening, the server that strips the in-transit encryption has access to the plaintext, and can copy the message to anywhere it damn pleases. It can write it to "plaintext-messages.txt" for all it cares, that's like two lines of Python in the backend.

Theoretically, couldn't the client send the message to one server and the keys to a different set of servers? Clients would request the encrypted messages from one server and the keys from another?

It is still not nearly as good security as proper E2E-encryption but should still be possible to set up so that a single rogue sysadmin cannot get hold of messages.

> Also, the servers creating database entries must by definition have the full database encryption key in its RAM, from where privileged processes can exfiltrate it (computer organization 101). The thing is, there isn't technology out there that allows Telegram to do what it claims as securely as it claims. If they are indeed innovating on this, why aren't they publishing their research and proving their worth?

See above. As long as they don't do serverside search or anything this should be possible?

> "they seem remarkable competent at certain aspects of what they do" Yeah, you can be great at UX design and shitty at cryptography. That's perfectly fine.

Definitely.

As mentioned before I prefer Signal. I actually like your answer.

We need more of these answers and less:

- X is definitely in the pocket of FSB.

- E2E or nothing!

- Use WhatsApp or nothing!

Hey, even tptacek went as far as admitting this at some point:

https://news.ycombinator.com/item?id=22371316

Re: Telegram messaging app proves crucial to Belarus protests

#478
post #431

Earlier quoted context omitted.

No. Still not E2EE by default, still no E2EE for groups, still no E2EE for desktop clients. Why do you want to imagine Telegram magically got better when it's so obvious it didn't?

Because they “magically” updated and improved tons of stuff in the last four years. So I think it’s not unreasonable to consider whether their encryption improved too. But yes, not having encryption on by default speaks poorly of them. OTOH it’s not concrete proof that the encryption still sucks as of now.

Don't get me wrong, I'm not saying the E2EE encryption itself is flawed. I'm saying it's not being used at all by default. And I'm saying it's not possible to use it for groups or desktop clients. That's _the_ travesty, and the proof that this is the state of things is so obvious people don't realize how serious it is. And my concern is that will lead to a tragedy.

Re: Telegram messaging app proves crucial to Belarus protests

#479
post #473

Earlier quoted context omitted.

" I cannot verify this, but Telegram said years ago that they solved certain problems by routing keys and messages through different datacenters in different jurisdictions. " Firstly, there is no proof of this happening. I've been looking for the documentation and/or source code for this for more than five years now, and it's never been published. Secondly, even IF it was happening, the server that strips the in-tran…

I think me and you agree to a large degree :-) > Firstly, there is no proof of this happening. I've been looking for the documentation and/or source code for this for more than five years now, and it's never been published. I haven't found anything more either. See also below. > Secondly, even IF it was happening, the server that strips the in-transit encryption has access to the plaintext, and can copy the message t…

Theoretically, couldn't the client send the message to one server and the keys to a different set of servers? Clients would request the encrypted messages from one server and the keys from another?

That would imply client-side encrypted cloud backups, with external key management which isn't the case in Telegram, if it were it could be shown from client-side code. Also, even if that would be the case, it would just need combining key and ciphertext in once place which is again the weak link.

Also, there's no way the search would work as fast as it does now if key /ciphertexts would have to be transported via servers, and finally, since it's a single server that can request data (I have checked the destination IPs), anything of the sort is not happening.

"should still be possible to set up so that a single rogue sysadmin cannot get hold of messages."

I'm afraid that's not possible. When the message arrives to server and the outer layer that is in-transit encryption is stripped, what must remain is the plaintext message, or a message that the server can not decrypt. Such technology already exists, it's called end-to-end encryption. If there was a simpler way to protect from malicious servers, there wouldn't be a need for E2EE communication ;)

"See above. As long as they don't do serverside search or anything this should be possible?"

So no that wouldn't work in practice. Proper cryptographic design in secure messaging apps doesn't distinguish between entities on server who have access to keys. "Jack has one part of the key and Jill has another, but they will never collude or get hacked at the same time" is very bad security rationale.

"- X is definitely in the pocket of FSB."

Well, the problem here is, if the scenario is this "Telegram is secretly in the pocket of the FSB and they're giving access to every message on their server" I can't say "No way, it's all end-to-end encrypted they have nothing to give". I can say that for Signal, however, so I'd rather recommend it instead, and actually, because I can't say Telegram definitely isn't in the pocket of FSB, I don't think it should be used. I hope you understand this requirement of verifiability. If Telegram really wanted to lock themselves from user data, the would've implemented E2EE from the get go.

"E2E or nothing!"

Not sure what to make of this, I haven't heard anyone claim no encryption is better than weaker encryption. But wrt. message confidentiality, since there is no difference when it comes to service provider obtaining the plaintext copy, it's hard to not say "don't use it if it's not E2EE".

"- Use WhatsApp or nothing!"

Another complex problem that boils down to trusting WA has not changed source code after Moxie helped implement Signal Protocol. Like I said earlier, there's maybe a 1..2% chance of backdoor that allows WA to snoop on it's E2EE. So if for some reason one would have to compare these particular ones (IRL this is what we'd call a false dilemma), I'd say

1. Telegram secret messages for one-on-one chats 2. WhatsApp group messages 3. Telegram group messages

WhatsApp may have 1..2% chance of backdoor, but with Telegram I know there's a front door with 100% probability.

If we forget the false dilemma, suddenly Signal solves all of our woes wrt. cross-platform private one-on-one chats and group chats.

"Hey, even tptacek went as far as admitting this at some point:"

Let's not put his words "almost literally any secure messenger is better than email."

Firstly, that assumes he considers Telegram a secure messenger. Secondly, encrypted email has serious problems with deniability (which we'll ignore this time) and forward secrecy: in those respects Telegram's E2EE is better, sure, but E2EE email for group chats (Assuming the client knows how to reply individually to all, and to use each individual's PGP key to protect it) is again more private than Telegram's group chats.

Re: Telegram messaging app proves crucial to Belarus protests

#480
post #388
post #286

Earlier quoted context omitted.

I love telegram. Great UI, feels natural to use it. And SO MANY features, it's hard to keep up. Unlimited storage helps too.

When you realize end-to-end encryption is a necessary property of all features, you realize Telegram lacks even basic things like desktop clients, syncable chats, and group chats. Not so feature rich anymore ;)

> you realize Telegram lacks even basic things like desktop clients

the desktop client of telegram is the main reason to use it over the competition for me. something that does not lag when you type text or resize its window, opens in a quarter of second, etc etc

Post reply on HN