Live data from Hacker News

Why Isn’t Telegram End-to-End Encrypted by Default (2017)

telegra.ph

91–100 of 151 posts

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#91
post #36

This article touches on the core issue holding back E2E encryption today. There's currently no way for a sophisticated application to implement E2E encryption without accepting tradeoffs in terms of the product. I'm working on starting a new company called Comm and we're trying to scale E2E. Some more context here: https://site.ashoat.com/comm/comm (We're currently hiring!!)

> There's currently no way for a sophisticated application to implement E2E encryption without accepting tradeoffs in terms of the product.

no?

> I'm working on starting a new company called Comm and we're trying to scale E2E. Some more context here: https://site.ashoat.com/comm/comm

How about you join forces with MLS

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#93
post #83

Earlier quoted context omitted.

This just is not true. The fact that you are writing this, clearly shows you don't know of Element/Matrix. When you use Matrix, and open a web client, the only thing you have to do is 1) logging in and 2) providing a password, key file, scan a QR code, OR compare Emojis - and you get everything synced. The same holds for any type of client. I barely see a loss of convenience, let a lone something being hard or imposs…

You are right, I never used Matrix. I guess i have to check it out. Missed it. Usable client apps for martix are what, 1.5 years old? Signal seems to have been around for ages. OTP even longer

> Usable client apps for martix are what, 1.5 years old?

Older, Element (also known as Riot and Vector) should already have been existing for at least 5 years.

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#94
post #76

Earlier quoted context omitted.

Honestly you have no idea about real use cases. Almost no one is going to set up a dedicated local server for all of his conversations, hosting only conversations in which you are part of anyways. Most people aren't even able to do this.

> Almost no one is going to set up a dedicated local server for all of his conversations 85000 Prosody servers disagree to some level :) https://news.ycombinator.com/item?id=25713679

in other words, almost no one compared to at least 2 billion potential users.

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#95

Earlier quoted context omitted.

Matrix is a protocol. Servers are horrible to set up and you have to find federations to join. Telegram, Signal and others are centralized, so you join one, you're a member of all.

Actually setting up a server is not difficult. Check out https://www.youtube.com/watch?v=dDddKmdLEdg for setting one up with video conferencing. Finding a server is not difficult - in the worst case you take the default server. And given the server is not locked down, you have access to all other servers (and their users) as well. So I don't really get where you are going with this.

> Actually setting up a server is not difficult.

And yet you point me to a YouTube video, rather than a link on their website.

The documentation itself strongly encourages setting up your own server to have your own user information and then federating into a system, and yet, the documentation doesn't seem to describe, in friendly terms, how to do that.

It might be easy to set up, but I've had trouble discovering all of that in their documentation.

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#97
post #8

The why doesn't matter. (the tl;dr is that they apparently never bothered to support some popular features within the context of e2ee, and believe people ultimately don't care about e2ee by default) What matters is that: - It doesn't do e2ee by default. - It is not a properly documented protocol[0]. - It is not an open protocol. - It has a history of extremely poor cryptography practices[1][2]. - It is not open sourc…

Can you do your research before posting statements like these? They hurt a messenger that has done a great deal of good for protestors and other political rebels. If I take the kindest interpretation of your statements, they are factually wrong in whole but true in part. That is, the Telegram server code is closed source, yes. But Telegram clients and the protocols they use to "speak" are all either open source or do…

> My message history is extremely precious to me and Telegram does an admirable job protecting it

How would you know without E2EE? A Telegram sysadmin could copy all your messages from non-secret chats and you would never know.

The lack of E2EE is also why many (including security experts) recommend WhatsApp over Telegram.

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#98
post #85

Earlier quoted context omitted.

try having verified e2ee conversations with XMPP - good luck.

Doing it actively. Try Conversations.

how many contacts with how many devices do you have there?

can't be many

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#100
post #20
post #8

The why doesn't matter. (the tl;dr is that they apparently never bothered to support some popular features within the context of e2ee, and believe people ultimately don't care about e2ee by default) What matters is that: - It doesn't do e2ee by default. - It is not a properly documented protocol[0]. - It is not an open protocol. - It has a history of extremely poor cryptography practices[1][2]. - It is not open sourc…

I've been exploring options with a friend, their requirements: 1) option for large groups (around 250) This drops Signal out which has a limit of 150 on groups: https://support.signal.org/hc/en-us/articles/360007319331-Gr... 2) e2e encrypted (because it sounds good, not because people actually understand what it is), including groups. This drops Telegram out: no e2e rooms. 3) handles sending photos, videos, and voice…

> This drops Signal out which has a limit of 150 on groups

Your own link mentions "Size limit of 1000", where did you see 150?

To be fair that's for new groups, maybe the limit used to be lower. Or do you mean that in practice it's not usable beyond 150 people?

Post reply on HN