It's a shame that people still use Telegram when Signal is so much better, and has better credentials all around.
Telegram is better in every way... except security.
41–50 of 241 posts
It's a shame that people still use Telegram when Signal is so much better, and has better credentials all around.
Telegram is better in every way... except security.
>[Line] fixed it by adding a random number to the user's destination This is a imperfect solution. There's two possibilities: the offset (aka "random number") is dynamic, or it's fixed. If it's the former all you have to do is sample enough times to get through the noise. If it's the latter, it's not vulnerable to the previous attack, but if you have a known point of reference (so you can deduce what the offset is),…
Earlier quoted context omitted.
I’ve heard other folks say WhatsApp is insecure. Do you (or anyone else) have specific examples or concerns?
Like... Facebook can read all your messages? The encryption only protects you from entities that are not Facebook. With that out of the door, it's not really worth it to even consider other angles of attack, since you now depend on the goodwill of a billion dollar company whose sole purpose and reason for existence is to extract and monetize your data. WhatsApp is a nice chat tool, but it's nothing you should ever us…
Earlier quoted context omitted.
signal the protocol is (maybe) better, but the app is inferior. People like Telegram for their usability and security is just a bonus.
I definitely agree with this. Getting people to use Telegram instead of SMS or other random chat apps can be difficult but getting them to switch to Signal is basically a "not going to happen" until Signal ups their usability. Even people I've gotten to try out Signal all abandoned it. At least with Telegram, they stuck with it and still use it to this day. It'd honestly probably be easier to get Telegram to adopt Si…
So in the article, the author was able to find the x- and y- coordinates of the other user. What if the target user lives in a high rise building, is there any technique you can get the height of the said user? Makes me wonder how the law enforcement is able to tri-angulate the suspect's exact location.
>[Line] fixed it by adding a random number to the user's destination This is a imperfect solution. There's two possibilities: the offset (aka "random number") is dynamic, or it's fixed. If it's the former all you have to do is sample enough times to get through the noise. If it's the latter, it's not vulnerable to the previous attack, but if you have a known point of reference (so you can deduce what the offset is),…
Would showing something like “5 mins away“ instead of “800 m” be a simple solution?
Earlier quoted context omitted.
> If it's the latter, it's not vulnerable to the previous attack, but if you have a known point of reference (so you can deduce what the offset is) It sounds like this approach could be prevented by having a random fixed offset for each user, so that you have no point of reference unless you already know where that specific user is. [Removed bit about regenerating this offset infrequently.] EDIT: You could even do th…
With enough data points you'd easily figure out that offset. Just overlay each data point with map data and decide whether the location makes sense. (i.e. you're unlikely to most of the time be in the middle of a lake, farm field etc)
> If this feature is enabled on your phone, you're publishing your home address online. Depending on your definition of 'online' this is true of any app you use. Telegram could at least take a similar approach to Tinder, who have already learnt from a similar mistake.
https://robertheaton.com/2018/07/09/how-tinder-keeps-your-lo...
>[Line] fixed it by adding a random number to the user's destination This is a imperfect solution. There's two possibilities: the offset (aka "random number") is dynamic, or it's fixed. If it's the former all you have to do is sample enough times to get through the noise. If it's the latter, it's not vulnerable to the previous attack, but if you have a known point of reference (so you can deduce what the offset is),…
Would showing something like “5 mins away“ instead of “800 m” be a simple solution?
>[Line] fixed it by adding a random number to the user's destination This is a imperfect solution. There's two possibilities: the offset (aka "random number") is dynamic, or it's fixed. If it's the former all you have to do is sample enough times to get through the noise. If it's the latter, it's not vulnerable to the previous attack, but if you have a known point of reference (so you can deduce what the offset is),…
Would showing something like “5 mins away“ instead of “800 m” be a simple solution?