Live data from Hacker News

Telegram Became the Anti-Facebook

wired.com

211–220 of 257 posts

Re: Telegram Became the Anti-Facebook

#211
post #174

Earlier quoted context omitted.

How is it not E2EE? Are you going by a stricter definition than commonly used? > End-to-end encryption (E2EE) is a system of communication where only the communicating users can read the messages. [..] End-to-end encryption is intended to prevent data being read or secretly modified, other than by the true sender and recipient(s). The messages are encrypted by the sender but the third party does not have a means to d…

It is incorrect to refer to encrypted backups as e2ee. See the wikipedia article on the subject [0], at the bottom of the "Modern usage" section. [0] https://en.wikipedia.org/wiki/End-to-end_encryption

> Some encrypted backup and file sharing services provide client-side encryption. The encryption they offer is here not referred to as end-to-end encryption, because the services are not meant for sharing messages between users[further explanation needed]. However, the term "end-to-end encryption" is sometimes incorrectly used to describe client-side encryption.[23]

This is reasonable, but it's not describing any weakness of encrypted backups. It merely points out that "E2E" isn't the right term to use when there are not two E[nds], but rather only one client and their files.

However, our conversation was about storing chat history. There are two parties to the conversation in that case.

The key property of E2E is that only those parties can read those messages, and nobody else, in particular not the agents running the server. That property is not affected by the existence of backups, as long as those backups are client-side encrypted, because third parties cannot access them.

Therefore, it is possible to have both cloud-stored chat histories and true E2EE. QED.

Re: Telegram Became the Anti-Facebook

#212
This was a great article! It provides a lot of past details that most people wouldn't know about, especially about Pavel Durov (who is an eccentric character, as seen in the posts on his channel).

I'd actually pay a monthly subscription for the value Telegram has given over the years. The pace of development is unmatched by any other platform. I know Telegram chats are not end-to-end encrypted by default. Pavel Durov has explained, and I'm sure it's somewhere on Telegram's site too, that a big reason for not doing E2EE is enabling fast search (on the server). And it shows: Telegram has the best search among chat platforms and is even better than search on social network platforms with more features like Facebook. Maybe they have ulterior motives and/or aren't technically able to provide E2EE for all chats. So far, it hasn't had widespread scandals (other than TON) like Facebook/Meta has had.

This is not to claim that Telegram doesn't have design flaws or drawbacks. But no other platform can catch up to its UX and features for at least a few more years, and that gap seems to be widening as time passes. If any platform were capable of doing so, it would've happened already.

Among Telegram's many features (if you use Telegram, check how many of these you know about):

* Phone number hidden from others? Check.

* Username that can be given to anyone or published anywhere for others to contact? Check.

* Multiple accounts on one app? Check. (the official Telegram clients allow up to three accounts)

* Fast and reliable (comparatively) message delivery? Check.

* Client applications for multiple platforms? Check.

* Messages (the default, non-E2EE ones) sync across all clients? Check.

* Send large files? Check.

* Prevent phone number enumeration by others (who randomly add numbers to their contacts list)? Check.

* Granular privacy settings? Check.

* Search messages by text, by person, by date? Check. Global search? Check.

* Use a calendar view to check activity/messages? Check.

* Edit messages after sending? Check.

* Delete messages after sending? Check.

* Message reply threads? Check.

* User mentions and quick navigation to mentions? Check.

* Scheduled messages? Check.

* Audio messages? Check. Video messages? Check.

* Voice chats (like clubhouse)? Check.

* Polls? Check.

* Chat exports? Check.

* Media editor? Check.

* Built-in video player with playback speed adjustment and fast forward/rewind? Check.

* Edit photos after sending? Check.

* Forward messages with fine control over whether it shows as a forward and whether the caption should be included? Check.

* Pin messages? Check. Multiple pinned messages? Check.

* Broadcast channels (one to many)? Check.

* Bots? Check.

* Themes and stickers? Check.

* Message folders? Check.

* Interactive emoji? Check.

* Message read receipts (by user) for small groups? Check.

* Spoiler formatting? Check.

* Reactions? Check.

P.S.: I do not work for and nor am I in any way associated with Telegram, except as an end user.

Re: Telegram Became the Anti-Facebook

#213

Earlier quoted context omitted.

Telegram is the only platform that "works" on Jolla. WA/Signal are both proprietary and will not work outside the Google-Apple "pleb sandbox".

Pffft. Signal is proprietary? it is on https://Github.com/SignalApp and i’ve got my own variant of Signal server and client running. and runs on not only mobile but Linux too.

...except that for nearly a year you didn't have access to any updates to the Signal server code on their public repo while they were secretly adding Mobilecoin to it.

Re: Telegram Became the Anti-Facebook

#214
post #81
post #72

Earlier quoted context omitted.

For most people the said security is not a big issue. Esp. in countries where police can come for you and make you talk by any means. E2EE won't help you if they want you.

"Encryption isn't useful because you can be tortured" is a bizarre and ridiculous argument. The police can only make you talk if they know who to make talk in the first place. Reading your messages tells them who to interrogate, where to find them, who else is involved, etc. Encryption is important especially in such countries.

I'm sorry but as someone from Russia - you are wrong.

>Reading your messages tells them who to interrogate, where to find them, who else is involved, etc.

Why read my messages if they can start from me? Or that other guy who posted something on twitter? Or any other place? Or talked to someone.

I'm not saying encryption is unimportant. I'm saying that it really only matters as long as all parties involved keep their business secure in the first place.

Not to mention that they police don't really work with that kind of precision here.

Re: Telegram Became the Anti-Facebook

#215
post #195
post #102

Earlier quoted context omitted.

You can install the Telegram FOSS client, at least in an Android cellphone.

For me, Telegram FOSS client stopped working. Telegram server side is open source?

The Telegram server code is not open source. It's been in the "we will open source everything at some point in time" limbo for years.

Re: Telegram Became the Anti-Facebook

#216
post #122

It's hilarious to watch Americans get triggered at Telegram's success. I'll grab my popcorn.

Nope, am American as they come and loving it.

Same. Also an American, and while I don't personally use it for some of the same reasons I try to avoid Facebook Messenger, I'm certainly not "triggered" by its success, whatever that means. It's at least nicer than close competitors like FB Messenger or Google Hangouts in my opinion.

Re: Telegram Became the Anti-Facebook

#217
post #176

The "sad thing" is that Whatsapp is 10x-50x more popular in my country and its quite hard to integrate (APIs, bots) compared to Telegram, at least for "small business". I wonder if Telegram would also be more closed if it was #1...

Telegram doesn't support bots and most other advanced features for E2EE conversations either. It seems at least as valid (IMO) to speculate that WhatsApp's lack of API/bot support is due to an additional technical hurdle than its dominant market status.

Re: Telegram Became the Anti-Facebook

#218

Earlier quoted context omitted.

>Regarding the security theater, the backups encrypted with your password are far more vulnerable to being compromised than any of the popular e2e encryption protocols. Hmm? How so? Surely this depends on the strength of your password.

All messages are encrypted with one key. Break one key, and all messages will be accessible to an attacker. Proper encryption protocols rotate encryption keys and compromising one message will not compromise the rest.

The situation is a bit more nuanced, given the large feature set that Matrix is trying to implement.

> Break one key, and all messages will be accessible to an attacker.

How do you propose breaking that one key, though? The attacker also needs to somehow acquire access to the key backup and to the encrypted messages, so it's a multi-step process.

The encryption protocol does rotate message keys. In fact it uses the same cryptographic primitives as Signal, that is the double ratchet algorithm.

I think you're conflating the message encryption protocol with cold storage, which is the purpose the key backup serves. It's completely typical for backups to be encrypted with a single symmetric key.

Finally, the key backup is completely optional and can be disabled.

Re: Telegram Became the Anti-Facebook

#219

Earlier quoted context omitted.

Element is still an UX clusterfuck. I've been on IRC since its inception in the 90's and I've used ircII and BitchX etc. I'm no stranger to janky clients for communication tools. Element is still in its death by a thousand cuts phase. There's nothing hugely wrong with it, but everything is a bit wonky. Just enough to be consistently annoying enough for me not to bother. Summary: Matrix mostly good, Element bad. They…

While I can't make Element copy Discords UX (not sure I'd even want that), I can show you a young client that seems to do that: https://cinny.in/

Cinny is close, but it still lacks a few features. For example it understands spaces, but can't create them.

Re: Telegram Became the Anti-Facebook

#220
post #164

Earlier quoted context omitted.

Check out "telegram russian block" or "ban" in a search engine, from 2018. I don't want to give any particular resources as you will know better what is better source for you - that was a huge event and most news sources wrote on that, including HN. Russian gov forced a block on so many IP classes that a lot of goverment services stopped working, not to mention whole public clouds. Let me just cherry-pick this hilari…

great, so a story from 4 years ago? the ban was removed in 2020, although they could have easily choked Telegram at the appstore level. Yet, it's officially alive and well.

Appstore you say.. well, there are many other distribution methods then appstore. I for instance use the direct download built into telegram. A bonus that I can enter chats that my government thinks is not appropriate, like ones that leaked their official communication they did on random public email services.

Also I'm sorry I dissapointed you with sources. Yes, it's sarcasm. How would one provide any meaningfull sources to what you are afraid of? Is it even possible?

Post reply on HN