Live data from Hacker News

Why Isn’t Telegram End-to-End Encrypted by Default (2017)

telegra.ph

41–50 of 151 posts

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#41
post #29
post #8

The why doesn't matter. (the tl;dr is that they apparently never bothered to support some popular features within the context of e2ee, and believe people ultimately don't care about e2ee by default) What matters is that: - It doesn't do e2ee by default. - It is not a properly documented protocol[0]. - It is not an open protocol. - It has a history of extremely poor cryptography practices[1][2]. - It is not open sourc…

> - It doesn't do e2ee by default. When creating a 1 to 1 chat, it's one of the default buttons. In Android, you click a {pencil} icon, then "new chat" (encrypted in transit and at rest like your bank website) or "new secret chat" (end to end encrypted) > - It is not an open protocol. The protocol is fully open source and audited. https://telegram.org/apps scroll down to source code. > - It is not open source. As abo…

[deleted]

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#42
post #8

The why doesn't matter. (the tl;dr is that they apparently never bothered to support some popular features within the context of e2ee, and believe people ultimately don't care about e2ee by default) What matters is that: - It doesn't do e2ee by default. - It is not a properly documented protocol[0]. - It is not an open protocol. - It has a history of extremely poor cryptography practices[1][2]. - It is not open sourc…

>It doesn't do e2ee by default.

I read the article and he claims it does? It's just that the default uses their cloud backup where Telegram has access to the private keys.

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#43
post #34
post #28

Earlier quoted context omitted.

Non room members shouldn't be able to read the text in the room. That's quite basic. As far as old messages goes, Matrix rooms do not allow new participants to see old history, unless explicitly enabled. >if you have 250 people in the chat I'm not sure it'll be very effective. It only takes one of those people to leak the messages. Ultimately, the system is only good when the members of a room deliberately leaking me…

Neither does XMPP, given it doesn't store it ;)

But XMPP has the non-trivial problem of e2ee as an extension added very late and not the default.

I can't suggest XMPP to non-technical people, because I know they'll end up talking to each other with neither e2ee nor awareness of lack of e2ee.

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#44

Here is what puzzles me every time about telegram (which is my primary messager so far) I can get the reasons behind not doing e2e encryption by default to reach more audience (msgs history, lack of resources on start, special backups) What I cannot get is why Durov is blaming FB/WhatsApp that much, it seems to be the main competitor. As for me the story with WhatsApp is clear, it's Facebook and if you like being Zuc…

There was & may still be a lot of anger towards WhatsApp. It was only after it became the de facto messaging app for most of the world that it became a FB property, so I think people felt either betrayed, hoodwinked, or simply trapped without a good exit. Compare to FB Messenger, which was always a FB product from day one, so you always knew what you were getting.

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#45
post #6

Bait-and-switch topic in the opening paragraph. Insists that what people ask for, e2e chat, isn’t what they actually want or should want.

no, it says that what people ask for, e2e chat, isn't what people get (because of unencrypted cloud backups).

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#46
post #4

Still avoiding the main point - e2e encryption does not prohibit syncing, backup etc for said data (without decryption)

e2e does not prohibit it. But makes it hard or impossible even for an advanced user (i tried moving my whatsapp data from iphone to android once, not sure of the current status with signal). Telegram is all about convenience, security is just bolt on. Everybody says they care about security, but hardly any TG user does it, because it is inconvenient. Install it on any any new device, confirm your phone number with an…

This just is not true. The fact that you are writing this, clearly shows you don't know of Element/Matrix.

When you use Matrix, and open a web client, the only thing you have to do is 1) logging in and 2) providing a password, key file, scan a QR code, OR compare Emojis - and you get everything synced.

The same holds for any type of client. I barely see a loss of convenience, let a lone something being hard or impossible.

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#47
post #29
post #8

The why doesn't matter. (the tl;dr is that they apparently never bothered to support some popular features within the context of e2ee, and believe people ultimately don't care about e2ee by default) What matters is that: - It doesn't do e2ee by default. - It is not a properly documented protocol[0]. - It is not an open protocol. - It has a history of extremely poor cryptography practices[1][2]. - It is not open sourc…

> - It doesn't do e2ee by default. When creating a 1 to 1 chat, it's one of the default buttons. In Android, you click a {pencil} icon, then "new chat" (encrypted in transit and at rest like your bank website) or "new secret chat" (end to end encrypted) > - It is not an open protocol. The protocol is fully open source and audited. https://telegram.org/apps scroll down to source code. > - It is not open source. As abo…

I don't have a security or crypto background, but I saw an interesting bug story about Telegram, provocatively entitled "Cryptography Dispatches: The Most Backdoor-Looking Bug I’ve Ever Seen."

"Now, normally the two sides would compute the shared key as (g^a)^b mod p and (g^b)^a mod p. Instead, the original version of MTProto computed it as

(g^a)^b mod p XOR nonce

where nonce was an arbitrary, supposedly random value sent by the server along with the peer’s public contribution.

This was a completely non-standard and useless addition, and all it did was let the server perform an undetected Person-in-the-Middle attack."

https://buttondown.email/cryptography-dispatches/archive/cry...

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#48
post #3

> 1) Users don’t want to lose their entire message history when they lose/change their phones so apps of this kind never become massively popular. I think this is a key point to consider for Signal and the other "good" messengers - there's ways to do secure backups, it just needs to be implemented so well that you won't miss the convenience of Google Drive backups. I tend to fall back on anecdotes a lot, but the firs…

Amazingly this is why I’m attracted to Signal and have set all chats to 1 week auto delete. To me text chats should be ephemeral. If I want something to stick around for years, send to email.

Even email is not permanent. There was a discussion a few months ago on HN where people were complaining that very old attachments just don't load up in Gmail, because they are not backed up on the servers.

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#49
post #16

Genuine question, and I'm certainly no expert in this - just a curious end-user, aren't the backups that WhatsApp creates and uploads to iCloud/GDrive kind of encrypted? As in, I can't simply download the backup file and access the messages and media? My understanding is that in order to restore/access said messages and media, you would need the SIM/phone number that created the backup file and would have to register…

If WhatsApp has the decryption key, it's not end-to-end encrypted.

If Apple has your decryption key, then iCloud uploads aren't encrypted (and Apple seems to have the decryption key, as they offer "reset password" functionality).

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#50
post #7
post #5

Earlier quoted context omitted.

> and WhatsApp makes this as easy as one click during setup. unless you switch platforms. then you lose it all

Yes, this happened to me after iOS -> Android switch all messages was wiped, you cant load icloud backup on android

I've just spent like 10 hours this week trying to figure out how to get my Android history into iOS. I finally did succeed with one the paid apps, but it's crazy to me that Whatsapp hasn't fixed this (and neither has Signal, by the way).
Post reply on HN