Live data from Hacker News

‘I will show you how safe Telegram is’

twitter.com

81–90 of 206 posts

Re: ‘I will show you how safe Telegram is’

#81
post #69
post #63

Earlier quoted context omitted.

1 GB?

The size is fairly irrelevant. 1 GB fits on a microSD card many times smaller than a Roman General's hand-written cypher.

How do you handle that SD card in practice to do your communication?

My point is, if anyone is on to you and can physically get to you (or anyone else in the group), there is a high risk they can get hold of the data.

Re: ‘I will show you how safe Telegram is’

#82

Isn't this a weakness in all SMS based verification? If you can reroute SMS auth codes, it's game over. It's too bad that most 2FA rely on this method (or use it as a fallback). I don't see how it is directly related to telegram, though.

> If you can reroute SMS auth codes, it's game over. Except it's absolutely trivial to do so, just bribe a low ranking employee of the phone company, and it's done. This has been done thousands/millions of times, usually targeting Bitcoin holders. Just google "Simjacking" I absolutely loathe when companies make me use SMS as 2FA. I flat out refuse to use the service if they force SMS for account recovery, because at…

Telegram actually uses SMS as the first factor. You can set a password as well, but that's an optional second factor.

That said, Telegram isn't very secure at all. You can make it secure by sacrificing all kinds of conveniences (i.e. not taking part in group chats) but the platform is just too unreliable.

It's a shame their apps work so well because the underlying protocol and security are behind on all of their competitors. From iMessage to WhatsApp and from FB Messenger to XMPP, encrypted group chats can be enabled easily. Only SMS/MMS is a less secure way to group chat.

Re: ‘I will show you how safe Telegram is’

#83
post #68

Smoke and mirrors, this post. Maybe replace Telegram with SS7 and it would make more sense.

If a service uses a known insecure authentication method, how is that the fault of the authentication and not the service?

Most serfkces use insecure authentication methods, especially in the messenger space. They're almost exclusively built around your phone number being the guiding proof of your identity.

Re: ‘I will show you how safe Telegram is’

#84
post #50

Earlier quoted context omitted.

the Two Factor auth to validate is really you after guessing/knowing your pass from a previous leak

It's worse. 2FA is optional and SMS code is the first (and default) auth method.

> It's worse. 2FA is optional and SMS code is the first (and default) auth method.

This will be changed on Saturday.

Got the following message about API changes last week: https://telegra.ph/Telegram-API-Changes-02-16

Re: ‘I will show you how safe Telegram is’

#85
post #74

Earlier quoted context omitted.

I'd love to hear more about this. I thought Pavel Durov (founder) isn't really welcome in Russia. He seems to have a left a lot of money on the table with his previous company (VK) to get out of there. The interpretation of events with telegram I've always heard has been that Russia tried to block telegram but doing so blocked most of the rest of useful services as telegram was hosted on e.g. AWS. This meant that rea…

https://www.wired.com/story/the-kremlin-has-entered-the-chat...

While very long, it doesn't look like that article provides anything but speculation. What would you say is the key point? Where's the meat?

I know that it would be hard to get good evidence here but I still think the burden of proof lies on the more extreme claim. Which to me is that a company founded by someone fleeing oppression would work directly with the oppressor.

The example of messages appearing as 'read' does not imply to me that telegram is working with them - rather that the her app was compromised by other means. Otherwise, why create such a flaw in your monitoring?

Meduza - news organization criminally charged in russia operating in latvia - is mostly accessed in russia via telegram. It's hard but not impossible to imagine that the russian government would allow it to remain uncensored.

Re: ‘I will show you how safe Telegram is’

#86
post #68

Earlier quoted context omitted.

If a service uses a known insecure authentication method, how is that the fault of the authentication and not the service?

Most serfkces use insecure authentication methods, especially in the messenger space. They're almost exclusively built around your phone number being the guiding proof of your identity.

True, but in most of them, you can‘t recover past conversations using SMS-OTP alone.

Authentication should be proportional to what it‘s protecting.

Re: ‘I will show you how safe Telegram is’

#87
post #74

Earlier quoted context omitted.

https://www.wired.com/story/the-kremlin-has-entered-the-chat...

While very long, it doesn't look like that article provides anything but speculation. What would you say is the key point? Where's the meat? I know that it would be hard to get good evidence here but I still think the burden of proof lies on the more extreme claim. Which to me is that a company founded by someone fleeing oppression would work directly with the oppressor. The example of messages appearing as 'read' do…

The agreement with the Russian Government over "Terrorism" cases is not just speculation, but announced by both parties.

Re: ‘I will show you how safe Telegram is’

#88

I monitor Russian war channels and some people there insist on using Telegram only for Russian military people. If you use Whatsapp, Ukrainian officers will get all chats from NATO. Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. My takeaway is that for truly private chat one should write his own software using simple crypto without all those fancy clients. Ideally ju…

> Signal might be safe, but I think it's a honeypot. Telegram smells a lot more like a honeypot than Signal

Both could be, just from different queen bees

Re: ‘I will show you how safe Telegram is’

#89
post #31

I monitor Russian war channels and some people there insist on using Telegram only for Russian military people. If you use Whatsapp, Ukrainian officers will get all chats from NATO. Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. My takeaway is that for truly private chat one should write his own software using simple crypto without all those fancy clients. Ideally ju…

> My takeaway is that for truly private chat one should write his own software That's the only way to make sure you're using software you trust, but rolling your own crypto implementations is often not so secure (because of the many pitfalls).

you could run your own xmpp or matrix instances.
Post reply on HN