Live data from Hacker News

‘I will show you how safe Telegram is’

twitter.com

131–140 of 206 posts

Re: ‘I will show you how safe Telegram is’

#131

Earlier quoted context omitted.

Both could be, just from different queen bees

Moxie Marlinspike is a lot of things but I'm pretty confident the queen bee of a honeypot is not one of them.

Haha I'm sorry but a name like Moxie Marlinspike seems designed by professionals to tickle the so quirky so he must be safe button in the nerd community.

Re: ‘I will show you how safe Telegram is’

#132

Earlier quoted context omitted.

Moxie Marlinspike is a lot of things but I'm pretty confident the queen bee of a honeypot is not one of them.

https://github.com/signalapp/Signal-Android/issues/127

Confused by this; Moxie did eventually concede and provide a signed APK.

Re: ‘I will show you how safe Telegram is’

#133

Earlier quoted context omitted.

https://www.wired.com/story/the-kremlin-has-entered-the-chat...

I actually wrote to Telegram’s support team to get more info about this, and it seems the article has a lot of errors. The support rep linked me to this, https://telegra.ph/Wired-Errors which is Telegram’s response to all of it.

> as no app can defend against direct access to a device.

Of course you can't protect the local data from all the possible attacks but there are many ways to prevent some attacks and complicate others. So this article isn't honest.

I kinda don't understand why people trust telegram. Regular messages aren't even encrypted. SMS authentication. Contact harvesting. Mandatory background run permissions (the app would constantly complain if it can't run its background tasks). Then some strange people selling users' metadata. One time I've purchased my location history for ~30 euros in TRX and it was accurate.

Re: ‘I will show you how safe Telegram is’

#134

Earlier quoted context omitted.

Moxie Marlinspike is a lot of things but I'm pretty confident the queen bee of a honeypot is not one of them.

Haha I'm sorry but a name like Moxie Marlinspike seems designed by professionals to tickle the so quirky so he must be safe button in the nerd community.

Despite the "trustless" credo that gets passed around in cryptography, it's actually often very important to know the people that work in this space and I invite you to read more about this particular person, his background and roots and make a determination as to his intentions in this space and the level of trust you are willing to put in his work (and/or the stuff he previously worked on) and not just make a base judgement on his name alone. FWIW, I've been familiar with his work since before I even used or cared about cryptography.

Re: ‘I will show you how safe Telegram is’

#135

[flagged]

I equally can't be arsed to read threads titled like this. the titling of articles is probably the thing that bothers me most on this website. if it isn't "why [high entropy word] and [high entropy word] are [high entropy word]"[1], then it's this. if Telegram is insecure, say that. if it's secure, say that. healthy titles don't make things less clear to make you want to clarify them.

Re: ‘I will show you how safe Telegram is’

#136

Earlier quoted context omitted.

telegram isn't e2e encrypted (unless you use secret chats which nobody does (and those do not support more than 2 participants))

Is there a e2e chat program that actually supports encrypted chats with more than 2 people? We've used telegram e2e but its frustrating since you can't see those chats on desktop at all. (for obvious reasons)

Yes, WhatsApp and Signal. Both use the Signal Protocol.

Re: ‘I will show you how safe Telegram is’

#137

Earlier quoted context omitted.

https://github.com/signalapp/Signal-Android/issues/127

Confused by this; Moxie did eventually concede and provide a signed APK.

Drew DeVault took the time to write it up: https://drewdevault.com/2018/08/08/Signal.html

Re: ‘I will show you how safe Telegram is’

#139
post #20

Isn't this a weakness in all SMS based verification? If you can reroute SMS auth codes, it's game over. It's too bad that most 2FA rely on this method (or use it as a fallback). I don't see how it is directly related to telegram, though.

The only thing worse than SMS-2FA is SMS-1FA, which I believe is Telegram‘s default.

It's the default but you can set up a password as your second factor. You should really do that if your Telegram account is important to you.

Re: ‘I will show you how safe Telegram is’

#140

Earlier quoted context omitted.

Both could be, just from different queen bees

Moxie Marlinspike is a lot of things but I'm pretty confident the queen bee of a honeypot is not one of them.

Signal is funded by the US State Department[1]. I'm sure you can trust it to send messages to your drug dealer, your mistress, or the competitor you are selling you company's secrets to. I wouldn't trust it if I wanted to keep secrets from american 3 letter agencies, though.

[1] https://www.mintpressnews.com/the-open-technology-fund-makes...

Post reply on HN