Live data from Hacker News

‘I will show you how safe Telegram is’

twitter.com

151–160 of 206 posts

Re: ‘I will show you how safe Telegram is’

#151

I monitor Russian war channels and some people there insist on using Telegram only for Russian military people. If you use Whatsapp, Ukrainian officers will get all chats from NATO. Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. My takeaway is that for truly private chat one should write his own software using simple crypto without all those fancy clients. Ideally ju…

Just use a open protocol that doesn't lock you into a specific server or client, like XMPP with OMEMO.

Re: ‘I will show you how safe Telegram is’

#152
post #33

I monitor Russian war channels and some people there insist on using Telegram only for Russian military people. If you use Whatsapp, Ukrainian officers will get all chats from NATO. Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. My takeaway is that for truly private chat one should write his own software using simple crypto without all those fancy clients. Ideally ju…

> Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. No, not really _hacked_. You give your phone unlocked to the police, and they access your Telegram account. You can't refuse, and you probably can imagine why.

> No, not really _hacked_.

I see a number of comments similar to yours on HN, and I am legitimately curious and do not mean to offend: Why did you think Belarusian police do not hack phones? Was your comment based on any source or personal experience, or did it feel right?

I ask because I have observed a number of times where HN comments are wrong on things (on have personal or professional experience in) but get upvoted because the comments look reasonable, but the correct comment gets downvoted.

It's an interesting failure mode of HN discussions. I thought I'd ask you because the topic is not contentious, and hopefully this comment does not cone across as underhanded.

Re: ‘I will show you how safe Telegram is’

#153
post #54

Earlier quoted context omitted.

Not only that but they've made suspicious ties with the Kremlin that resulted in it being unblocked in Russia and have a mysterious source of funding after TON collapsed.

Interesting. Where can we read more?

Can you read russian or translate it via google translate?

https://medium.com/@anton.rozenberg/friendship-betrayal-clai...

while the whole store is about on how Durov tried to sleep with authors wife and tried to put pressure on him using his work position, author did expose facts which very interesting:

- telegram office in sankt petersburg sharing same office that mail ru does (and mail ru basically is pro government org)

- telegram team still contributes to vkotankte and they do share some software components connect to online messaging

- most interesting russian oligarchs has very big influence on the products (vkontakte and telegram). While both productions trying to tell its not true, behind the doors they do have well established process of giving data when certain criterias are met

Re: ‘I will show you how safe Telegram is’

#154
post #33

Earlier quoted context omitted.

> Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. No, not really _hacked_. You give your phone unlocked to the police, and they access your Telegram account. You can't refuse, and you probably can imagine why.

> No, not really _hacked_. I see a number of comments similar to yours on HN, and I am legitimately curious and do not mean to offend: Why did you think Belarusian police do not hack phones? Was your comment based on any source or personal experience, or did it feel right? I ask because I have observed a number of times where HN comments are wrong on things (on have personal or professional experience in) but get upv…

Because to beat up someone and order them to unlock their phone is faster, does not require trained staff, can be done anywhere and is fun for the cops.

In some cases they use israeli hardware (forgot the name of the company), if you are fooled into giving your phone away for some period of time, like entering a police building, where they have a "no-phone zone" for visitors.

Re: ‘I will show you how safe Telegram is’

#155

Earlier quoted context omitted.

Signal is funded by the US State Department[1]. I'm sure you can trust it to send messages to your drug dealer, your mistress, or the competitor you are selling you company's secrets to. I wouldn't trust it if I wanted to keep secrets from american 3 letter agencies, though. [1] https://www.mintpressnews.com/the-open-technology-fund-makes...

DARPA was going to contribute money to the OpenBSD project (which also maintains OpenSSH) before Theo said some things critical of the Iraq war and they retracted it. I wonder how many people would have accused them of being CIA plants if they took the grant money. Regardless, there are many competing interests and bureaucracies in the US government and it's not a safe assumption that they are in cahoots with each ot…

Also see the history of "window" (chaff) in World War II. R&D people for both the Allies and the Germans realised, as improvements of the new "radar" continued, that radar doesn't see a difference between an aeroplane and a suitably sized radio-reflecting object, say a strip of foil. So, if you chuck a bunch of these foil strips out of a plane, now the enemy radar is full of "planes" that don't really exist.

Both sides stalled deployment of this trivial yet effective countermeasure because they believed once they used it their opponents would immediately understand how it was done ("Gee, immediately after the German bombers did that trick which messed up our radar we found loads of metal strips in trees all over the area they attacked...") and so copy it - and both had "official" estimates made which said their opponents would surely benefit more than they would once it came into use.

Re: ‘I will show you how safe Telegram is’

#156

Earlier quoted context omitted.

> Signal might be safe, but I think it's a honeypot. Telegram smells a lot more like a honeypot than Signal

If you use group chats or unencrypted individual chats, then it's absolutely not secure. I don't use those for the security though. It's just a really nice messenger that's not Messenger. But it does also have E2E encrypted chats, and that's what you should use if you're trying to keep your conversation secret. Unfortunately many people aren't aware of that, and just assume Telegram is secure by default.

Even Telegram's encrypted chats have not had nearly enough analysis to be trusted. They used to use some bad home-grown techniques, now it's just "probably secure enough".

Their client code also isn't really open source, even though they claim it is. While Signal has reproducible builds.

Re: ‘I will show you how safe Telegram is’

#157

I monitor Russian war channels and some people there insist on using Telegram only for Russian military people. If you use Whatsapp, Ukrainian officers will get all chats from NATO. Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. My takeaway is that for truly private chat one should write his own software using simple crypto without all those fancy clients. Ideally ju…

"Signal might be safe, but I think it's a honeypot." Based on what? Signal documents its own encryption process, and you can check the app source code to verify it. https://signal.org/docs/specifications/doubleratchet/ Signal is the best choice I know of when I'm looking for the union of 1. True e2e encryption, and 2. Ease of use by non-technical people.

The fact that it locks you into using their servers, does not distribute on F-Droid (only Google Play OR an APK with an insecure update mechanism), and has a completely closed-source "abusive message filter" module server side, that could functionally be used for censorship, storing messages for future decryption, or any other number of nefarious purposes - we have no idea since it's not open source (https://github.com/signalapp/Signal-Server/blob/main/.gitmod...).

Additionally, you cannot distribute branded forks or Signal, and if you do fork it, your fork is not allowed to connect to Signal's "official" OWS (open whisper systems) servers - hostility to federation should be viewed with prejudice and suspicion at the very least, it suggests a vested interest in a single point of failure (or control), which goes against user interests.

Further reading: https://drewdevault.com/2018/08/08/Signal.html

Re: ‘I will show you how safe Telegram is’

#158

Earlier quoted context omitted.

> No, not really _hacked_. I see a number of comments similar to yours on HN, and I am legitimately curious and do not mean to offend: Why did you think Belarusian police do not hack phones? Was your comment based on any source or personal experience, or did it feel right? I ask because I have observed a number of times where HN comments are wrong on things (on have personal or professional experience in) but get upv…

Because to beat up someone and order them to unlock their phone is faster, does not require trained staff, can be done anywhere and is fun for the cops. In some cases they use israeli hardware (forgot the name of the company), if you are fooled into giving your phone away for some period of time, like entering a police building, where they have a "no-phone zone" for visitors.

Obligatory XKCD: https://xkcd.com/538/

Cellebrite and GrayKey are prominent providers of cellular DFIR hardware used by government agencies.

Re: ‘I will show you how safe Telegram is’

#159

Earlier quoted context omitted.

How out of date are you? Both server and client apps have been on GitHub for half a decade.

Signal did notoriously not update their repositories for a while when they implemented their cryptocurrency scheme into the app. If you're basing your trust on their open source software, you should also run a client you've compiled yourself (after auditing the code, of course).

I'm aware that there was at a certain point over a year without server code updates. I'm also aware that Signal went out of their way to discourage forks of the official clients, but I don't know if that was just Moxie or does the new CEO share the same opinion.

In any case, I don't think either of those things = Signal not being open source. Not free software? Sure, who gives a shit. But the source is there and long pause doesn't mean much to me. While it was still happening, it certainly raised my eyebrows. Now that we know it was a pause and not a full stop? Doesn't mean a thing to me.

Re: ‘I will show you how safe Telegram is’

#160
post #119
post #108

Earlier quoted context omitted.

OTP one time pads are uncrackable if is random enough. Hard part is transporting that decoder to someone.

Textbook one-time pads are trivially malleable. Sometimes non-malleability matters just as much or more than privacy. ("This is POTUS, do$ÿ} launch the nukes!!!")

If you are a developer working for the government and in charge of this, please do not make this mistake. If you are the President of the United States and need to send a message like this, please make it completely unambiguous. Maybe repeat it several times and provide a justification.
Post reply on HN