Don't use messengers that ask for your phone number and aren't end-to-end encrypted. Use services that store as little data as possible. If data is stored, it can be given away and I would assume that it will be given away. Telegram disguises itself as encrypted chat app, when it is actually just a regular centralized plaintext messenger that has an encryption feature that nobody uses.
yes. yes yes. yes. yes 100%. the same reason i avoid whatsapp and signal like the plague. "mobile number" is in itself a big identifier when you are living in a place where you have o do mandatory KYC so that the government knows which each mobile number is linked to the actual human being. i dont care signal doesnt hold any messages. the government can ask for my number and they can use the xkcd spanner method to do…
After Delhi High Court ruling, Telegram discloses personal details of users
121–130 of 230 posts
Re: After Delhi High Court ruling, Telegram discloses personal details of users
#122Earlier quoted context omitted.
In theory you can use OTR[1] but I've yet to see an easy way to use this from a phone. I remember IRC very fondly, but I feel it has a lot of baggage that makes it difficult to bring into the modern era. This blog post (not mine) explains it quite well: https://jlu5.com/blog/im-tired-of-irc-heres-why [1] https://otr.cypherpunks.ca/
OTR doesn't do groups. So it isn't really applicable to IRC. At this point, I am not really sure that end to end encryption is generally applicable to groups. The identity management problem quickly spirals out of control. I note that Telegram doesn't even try. I think the best that can be done is a scheme that makes everyone entirely trust the moderator of the group.
You encrypt the message with all the public key's from persons in the group, what's the problem? You do it the same way with Mail...aka pgp.
You don't need OTR just plain old gnupg:
Re: After Delhi High Court ruling, Telegram discloses personal details of users
#123Re: After Delhi High Court ruling, Telegram discloses personal details of users
#124Earlier quoted context omitted.
yes. yes yes. yes. yes 100%. the same reason i avoid whatsapp and signal like the plague. "mobile number" is in itself a big identifier when you are living in a place where you have o do mandatory KYC so that the government knows which each mobile number is linked to the actual human being. i dont care signal doesnt hold any messages. the government can ask for my number and they can use the xkcd spanner method to do…
So what exactly is your threat model here that signal doesn't counter? They need to know your phone number before asking signal about it.
Re: After Delhi High Court ruling, Telegram discloses personal details of users
#125Don't use messengers that ask for your phone number and aren't end-to-end encrypted. Use services that store as little data as possible. If data is stored, it can be given away and I would assume that it will be given away. Telegram disguises itself as encrypted chat app, when it is actually just a regular centralized plaintext messenger that has an encryption feature that nobody uses.
yes. yes yes. yes. yes 100%. the same reason i avoid whatsapp and signal like the plague. "mobile number" is in itself a big identifier when you are living in a place where you have o do mandatory KYC so that the government knows which each mobile number is linked to the actual human being. i dont care signal doesnt hold any messages. the government can ask for my number and they can use the xkcd spanner method to do…
Re: After Delhi High Court ruling, Telegram discloses personal details of users
#126Earlier quoted context omitted.
TLDR don't use Telegram and Signal as some "alternatives" Use Matrix clients (Element, Fluffy chat) or Session, Briar (no (video)calls), Delta (no (video)calls), Jami, not recommending Threema because they can tie you through payment and it's centralized Here simple chart to see what to use and not use (use translate feature): https://www.messenger-matrix.de/messenger-matrix.html
Threema can be paid with burner Bitcoin. So I would say that Threema is fairly secure.
Re: After Delhi High Court ruling, Telegram discloses personal details of users
#127Earlier quoted context omitted.
It is not. Session and Matrix alone use the same protocol Signal uses without needing your phone number or google play services.
You might want to read up on how Matrix works and what the spec says. (I won’t comment on Session, I’m not familiar with the finer details there.)
Re: After Delhi High Court ruling, Telegram discloses personal details of users
#128Earlier quoted context omitted.
True. That does not affect the message integrity and message confidentiality though. So let me ask you this: What’s your threat model? Does your threat model require you to hide your location from the Five Eyes?
In my opinion "secure messenger" should protect from any actor. If we start making exceptions then it cannot be called secure anymore. Signal requires extra information that is not necessary for exchanging messages. That is at least suspicious. If you are fine with giving away your number you can just use WhatsApp or Telegram.
Those projects do not have the same high standards as Signal has. Especially not Telegram. I use Whatsapp for convenience/social reasons, but I definitely prefer Signal for the additional security. Telegram I don’t use at all.
I don’t believe it’s reasonable to throw out the baby with bath water, just because Signal requires a phone number for registration.
Protection from “any actor” would of course be nice – but do you really believe that threat model is reasonable?
Would using Session, Matrix or OMEMO protect against any actor whatsoever?
If we want to base our discussion in reality, I do believe we need to talk about threat models in more detail than “I want protection from any threat actor”.
Let’s take an example:
If I send a message to a friend I don’t want any script kiddies, ISP, cloud provider or advertising agency to be able to read it. I don’t want any passive eavesdropper to be able to read it e.g. by slurping up all traffic from my nearest IXP (i.e. dragnet surveillance). However, if Five Eyes/Mossad/MUST/FSB really wanted some intel on me, they would probably be able to retrieve it if they were willing to spend some resources. But probably not by decrypting my Signal messages. There would be other, far cheaper ways to retreive the info.
Re: After Delhi High Court ruling, Telegram discloses personal details of users
#129Earlier quoted context omitted.
You might want to read up on how Matrix works and what the spec says. (I won’t comment on Session, I’m not familiar with the finer details there.)
I don't use it these days but please enlighten me or show me the specific section you are talking about. Specifically, I was referring to libolm.
Re: After Delhi High Court ruling, Telegram discloses personal details of users
#130Earlier quoted context omitted.
Most countries require SIM card registration nowadays. https://www.phonetravelwiz.com/phone-travel-options/sim-card... > Of the 245 countries/territories with territory-bound mobile operators, 185 countries have SIM card registration laws. 13 will collect biometrics (fingerprints, but some will take a face scan too). 51 countries have no registration requirements. Which by itself is questionable.
Hmm I didn't think it would be that many. I'm sure there might be workarounds, like ordering online or buying from vending machines at airports, etc., but yeah, it's certainly not as convenient as before.