Live data from Hacker News

‘I will show you how safe Telegram is’

twitter.com

91–100 of 206 posts

Re: ‘I will show you how safe Telegram is’

#91
post #66
post #62

Earlier quoted context omitted.

You can never ensure that your communication channel isn’t corrupted. But with a one time pad you’ll just receive unreadable garbage then. You‘re also free to sign messages before encryption.

if an adversary xors their guess of part of your message (a crib) and what they want it to say with the one-time-pad ciphertext, they can make it say what they want if the guess is right; this is a general vulnerability with unauthenticated stream ciphers if they guess wrong, there's a little unreadable garbage in the message, but in many scenarios they only have to guess right once so you need some kind of message a…

Good point I guess that’s the same as the “heil h**er” vulnerability

Maybe some kind of low density salting would make messages hard to guess but not too hard to read

Re: ‘I will show you how safe Telegram is’

#92
post #57

Earlier quoted context omitted.

I don't think anyone can whatsapp chat. Somehow, whats app is the most reliable end-to-end encrypted messaging service today and many just don't know.

WhatsApp is closed source. For what it's worth, the protocol itself might be impenetrable, but the client itself has access to your decrypted messages and can still decide to send them back to Facebook without your knowledge. The system that depends on a good will and "trust me bro" is not secure by default, even if Meta/Facebook were the most trustworthy company in the world under the most honest legislation.

Software can be reverse engineered even if it doesn't have source available (and WhatsApp has been extensively reverse engineered). Similarly, software might be impractical to audit even if it does have source available.

Re: ‘I will show you how safe Telegram is’

#93
post #73

Earlier quoted context omitted.

WhatsApp is closed source. For what it's worth, the protocol itself might be impenetrable, but the client itself has access to your decrypted messages and can still decide to send them back to Facebook without your knowledge. The system that depends on a good will and "trust me bro" is not secure by default, even if Meta/Facebook were the most trustworthy company in the world under the most honest legislation.

Open vs. closed source is a completely moot point in the context of iOS and Android if your threat model includes vendor/supply chain attacks.

If you have reproducible builds and you can verify the digest of the app on your phone, difference is like night and day in open-source vs. closed-source projects.

Re: ‘I will show you how safe Telegram is’

#94
post #87

Earlier quoted context omitted.

While very long, it doesn't look like that article provides anything but speculation. What would you say is the key point? Where's the meat? I know that it would be hard to get good evidence here but I still think the burden of proof lies on the more extreme claim. Which to me is that a company founded by someone fleeing oppression would work directly with the oppressor. The example of messages appearing as 'read' do…

The agreement with the Russian Government over "Terrorism" cases is not just speculation, but announced by both parties.

That would be damning if I could find a statement by telegram about how they are working with the russian government to deal with 'terrorism'.

I'm seeing quoted statements by the russian government in the article that I cannot verify elsewhere but I'm unable to see telegram making a statement from their side of working with the russian government.

I'm truly interested in getting to the bottom of this. This wired piece doesn't inspire a lot of confidence in it's trustworthiness but I'm unable to find something with more concrete sources or at least a better reputation.

Re: ‘I will show you how safe Telegram is’

#95
post #35

I monitor Russian war channels and some people there insist on using Telegram only for Russian military people. If you use Whatsapp, Ukrainian officers will get all chats from NATO. Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. My takeaway is that for truly private chat one should write his own software using simple crypto without all those fancy clients. Ideally ju…

If you and your group chat friends can meet up in person once to input an agreed upon a ~1Gb one-time-pad then you can exchange uncrackable text messages for years on any insecure channel I’ve long felt that this is the ideal solution for anything super super secret

That actually makes a lot of sense. Matrix should add it as a feature.

Re: ‘I will show you how safe Telegram is’

#96
post #74

Earlier quoted context omitted.

I'd love to hear more about this. I thought Pavel Durov (founder) isn't really welcome in Russia. He seems to have a left a lot of money on the table with his previous company (VK) to get out of there. The interpretation of events with telegram I've always heard has been that Russia tried to block telegram but doing so blocked most of the rest of useful services as telegram was hosted on e.g. AWS. This meant that rea…

https://www.wired.com/story/the-kremlin-has-entered-the-chat...

as a counter point, here's telegram's answer to this article https://telegra.ph/Wired-Errors

Re: ‘I will show you how safe Telegram is’

#97

I monitor Russian war channels and some people there insist on using Telegram only for Russian military people. If you use Whatsapp, Ukrainian officers will get all chats from NATO. Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. My takeaway is that for truly private chat one should write his own software using simple crypto without all those fancy clients. Ideally ju…

> Signal might be safe, but I think it's a honeypot. Telegram smells a lot more like a honeypot than Signal

If you use group chats or unencrypted individual chats, then it's absolutely not secure. I don't use those for the security though. It's just a really nice messenger that's not Messenger. But it does also have E2E encrypted chats, and that's what you should use if you're trying to keep your conversation secret. Unfortunately many people aren't aware of that, and just assume Telegram is secure by default.

Re: ‘I will show you how safe Telegram is’

#98

I monitor Russian war channels and some people there insist on using Telegram only for Russian military people. If you use Whatsapp, Ukrainian officers will get all chats from NATO. Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. My takeaway is that for truly private chat one should write his own software using simple crypto without all those fancy clients. Ideally ju…

Good old pgp (in the form of using gnupg to send encrypted emails) is safe. Make sure that you trust the correct keys though.

Non standard solutions are a recipe for disaster.

Re: ‘I will show you how safe Telegram is’

#99
post #28

Earlier quoted context omitted.

Yes it is. It’s worse for Telegram though because it gives the attacker access to the chat history too. Telegram does however send a message to all devices when a new device is logging in, so at least you would know. Signal does not do that but your contacts will get a message that your security code changed if they have the option for that enabled, but people generally ignore this message. Both services offer to set…

Signal provides a Registration Lock that is available in the settings for preventing this from happening to some degree, it's however opt-in and you need to set and remember a PIN.

Telegram too.

Re: ‘I will show you how safe Telegram is’

#100

Earlier quoted context omitted.

> Signal might be safe, but I think it's a honeypot. Telegram smells a lot more like a honeypot than Signal

Both could be, just from different queen bees

Moxie Marlinspike is a lot of things but I'm pretty confident the queen bee of a honeypot is not one of them.
Post reply on HN