Live data from Hacker News

Telegram Became the Anti-Facebook

wired.com

191–200 of 257 posts

Re: Telegram Became the Anti-Facebook

#191
post #174

Earlier quoted context omitted.

How is it not E2EE? Are you going by a stricter definition than commonly used? > End-to-end encryption (E2EE) is a system of communication where only the communicating users can read the messages. [..] End-to-end encryption is intended to prevent data being read or secretly modified, other than by the true sender and recipient(s). The messages are encrypted by the sender but the third party does not have a means to d…

It is incorrect to refer to encrypted backups as e2ee. See the wikipedia article on the subject [0], at the bottom of the "Modern usage" section. [0] https://en.wikipedia.org/wiki/End-to-end_encryption

The wording there has no effect on security, it's semantics. E2EE being an application of client-side encryption for messaging.

Re: Telegram Became the Anti-Facebook

#192

Earlier quoted context omitted.

Telegram is ridiculously smooth, runs on everything, doesn’t treat any platform as an afterthought (despite having the electron thing, Signal is still very mobile oriented), and isn’t Facebook. It’s about as good as you’re going to get without making big sacrifices somewhere.

Yeah, it’s ridiculously well made. I’m not disputing that. The protocol is weird but they built a great app on top of that. They just cannot be sustainable long term. There is literally no restriction size-wise on data you can save on their servers. For free. And they have basically no income. They have some new ad program with basically no tracking (which is good for users, sure, but nobody will pay that much for th…

The restriction is done trough throttling in speed. It only looks like you have unlimited space but lets say you would actually want to upload a TB of stuff it would take very very long unless you use multiple accounts and then if you ever would need to download it it would again take very very long.

It also seems like files that are not downloaded by many people for a while get moved to slow servers and downloading these is really really really slow. If you have a few GB and want an additional online backup sure you could abuse it for that but realistically the potential to abuse it is low as it simply makes no sense as a could storage + they simply delete accounts from people who abuse the network. "Spam" is very lose defined and if you spam upload/download I'm sure they consider that to be spam and delete your account. Kinda pointless "backup" if you can lose access the moment you use the backup.

>And they have basically no income.

How would you know? They launched ads in public channels.

>TON went nowhere.

TON exists and seems functional just doesn't have anything to do with Telegram anymore due to the SEC.

Re: Telegram Became the Anti-Facebook

#193
post #154

Earlier quoted context omitted.

Nobody has any problem with Russia the country or the Russian people. It's the current Russian government and its psychopathic leader that are freaking us out.

Still, I believe a reflection of the government deeds affects just people – entrepreneurs, projects, etc. I don't have data for that. I am just sharing my 5 cents here. People could "freak out" when they hear "it's Russian" without doing any research from their side. I hope it's not happening often. As a Russian ciz this thought disappoints me sometimes and makes me sad (and our Gov deeds too).

That's a legacy from the Cold War.

Re: Telegram Became the Anti-Facebook

#194

People are consistently surprised that Telegram is not encrypted by default in any setting. You have to create a device-to-device-specific encrypted chat with your counter-party. It's not a reasonable security model, vastly outclassed by (the still quite flawed) Signal. Ultimately, we need encrypted-by-default messaging based on public/private key pairs (obscured from the uninterested user, of course).

Both Threema and Signal are the way to go with chat apps, the only advantage Telegram offers are vast groups for specific purposes. Here in Berlin, I'm getting cheap produce through telegram, get alerted to public transport controls (I do have a ticket, but sometimes friends do not), and sell/buy stuff I don't need.

"Die Fahrscheine bitte! Schwarzfahren ist eine Straftat"

Re: Telegram Became the Anti-Facebook

#195
post #102
post #97

If we install binaries, how can we be sure that any messaging app has no backdoors?

You can install the Telegram FOSS client, at least in an Android cellphone.

For me, Telegram FOSS client stopped working.

Telegram server side is open source?

Re: Telegram Became the Anti-Facebook

#197

Earlier quoted context omitted.

Checkout Element, it covers all that as well. However, the Desktop App is Electron, so I don't know if you are OK with that

This is the main problem with Matrix for me. If they would just develop a good desktop client, I would be all over it.

Have you tried some of the alternatives like fluffychat ? I feel their UI is far ahead of the official clients

Re: Telegram Became the Anti-Facebook

#198

Earlier quoted context omitted.

I have nowhere called them end-to-end encrypted Backups, that's a straw man. > Regarding the security theater, the backups encrypted with your password are far more vulnerable to being compromised than any of the popular e2e encryption protocols. How, so? Are you aiming weak passwords? (One is provided for you ("security key"), however you can opt into a custom one that is not directly used for encryption ("security…

It is proven beyond doubt that whatever Element fetches from their own servers and decodes on application launch are not messages encrypted using e2ee protocols. It is also completely clear that it does reduce the privacy of user messages. I don't know what else to argue about here.

Element does not fetch any message from their servers in general. If you use a server hosted by Element and don't disable encryption, e2ee encrypted messages will be fetched from their servers.

What is "it" that in your opinion should reduce the users privacy?

> I don't know what else to argue about here.

I don't know what you are arguing about right now. What I know, is that I have disproven your original thesis (visible messages right after login through a password is not possible with e2ee) by explaining how it works and providing an example that has put that concept into practice.

If you feel there is anything to discuss, or if you have any further questions, don't hesitate to respond though.

I'll add link that adds technical Implementation details, in case you are interested: https://matrix.org/docs/guides/implementing-more-advanced-e-...

Re: Telegram Became the Anti-Facebook

#199

People are consistently surprised that Telegram is not encrypted by default in any setting. You have to create a device-to-device-specific encrypted chat with your counter-party. It's not a reasonable security model, vastly outclassed by (the still quite flawed) Signal. Ultimately, we need encrypted-by-default messaging based on public/private key pairs (obscured from the uninterested user, of course).

No post body was provided.

Re: Telegram Became the Anti-Facebook

#200

Earlier quoted context omitted.

The funniest thing is that Telegram's group management tools blow anything FB has out of the water by a nautical mile. If you only need the one channel and you need to manage a 100+ people, Telegram is by far the best tool. For "communities" Discord is a bit better, since you can split stuff to multiple channels. Anyone with basic knowledge of the internet can also install bots on both to manage dozens of different t…

Does anyone need e2ee on group chats anyway?

Nope.

If you're managing a 100+ user channel, encryption matters fuck-all unless your invitation process is 100% airtight and every user has all their devices encrypted and locked up at all times.

Data will leak anyway so E2EE won't bring any real advantages.

Post reply on HN