Live data from Hacker News

‘I will show you how safe Telegram is’

twitter.com

181–190 of 206 posts

Re: ‘I will show you how safe Telegram is’

#181

Earlier quoted context omitted.

> No, not really _hacked_. I see a number of comments similar to yours on HN, and I am legitimately curious and do not mean to offend: Why did you think Belarusian police do not hack phones? Was your comment based on any source or personal experience, or did it feel right? I ask because I have observed a number of times where HN comments are wrong on things (on have personal or professional experience in) but get upv…

Because to beat up someone and order them to unlock their phone is faster, does not require trained staff, can be done anywhere and is fun for the cops. In some cases they use israeli hardware (forgot the name of the company), if you are fooled into giving your phone away for some period of time, like entering a police building, where they have a "no-phone zone" for visitors.

> Because to beat up someone and order them to unlock their phone is faster, does not require trained staff, can be done anywhere and is fun for the cops.

The implicit assumption is that the states always go for the faster solution. I'd argue that intercepting an SMS/call is easier/faster for nation-states, than arrest and torture; most carriers worldwide have interception capabilities mandated by law: using the secret police to subvert those capabilities is not rocket science - especially when coordinating with hacking-as-a-service companies like "Team Jorge".

What really grinds my gears, when someone confidently state their thought experiment/"derivation from (idealized) first principles" as a rebuttal to empirical evidence. Incidentally, the wording is sometimes absolute, which cloaks the speculative (and wrong) nature of such comments ("No, not really hacked." Implying hacking doesn't happen, and yet it does).

I've seen such 'truthy' but wrong comments voted to the top on HN, because the up-voters share the same blindspot and think "Yeah, that sounds right"

Re: ‘I will show you how safe Telegram is’

#182
post #123
post #93

Earlier quoted context omitted.

If you have reproducible builds and you can verify the digest of the app on your phone, difference is like night and day in open-source vs. closed-source projects.

But you can’t have reproducible builds at least in the App Store.

Apple can implement to show pre-encrypt hash if they want. I cannot see anything negative impact for them if we just give some pressure.

Re: ‘I will show you how safe Telegram is’

#183

Earlier quoted context omitted.

Interesting. Where can we read more?

Can you read russian or translate it via google translate? https://medium.com/@anton.rozenberg/friendship-betrayal-clai... while the whole store is about on how Durov tried to sleep with authors wife and tried to put pressure on him using his work position, author did expose facts which very interesting: - telegram office in sankt petersburg sharing same office that mail ru does (and mail ru basically is pro governme…

Curious how good chatGPT is at translation. Tried it on Russian?

Re: ‘I will show you how safe Telegram is’

#184

Earlier quoted context omitted.

Huh? Their client code isn't just fully open-source, it also has reproducible builds both on Android and iOS, has been for a while. Doesn't Signal only have them on Android? It's a great app either way but if RBs matter, that's a little knock against it.

Where did you get that idea from? Their client code is not usable because they don't provide working instructions for compiling it. If you can't compile it, they can't have reproducible builds. For example, see this issue from 2019 which the developers still haven't replied to: https://github.com/TelegramMessenger/Telegram-iOS/issues/97 There are a lot more issues about people not being able to use the code, none of…

GitHub builds directly from their source code just fine: https://github.com/TelegramMessenger/Telegram-iOS/actions/ru...

(uses this script: https://github.com/TelegramMessenger/Telegram-iOS/blob/maste...)

And here are few recent examples of them helping people to solve build issues: https://github.com/TelegramMessenger/Telegram-iOS/issues/968... https://github.com/TelegramMessenger/Telegram-iOS/issues/986... https://github.com/TelegramMessenger/Telegram-iOS/issues/992...

How were you digging to find an irrelevant issue yet omitted all of this? I really don't see the picture you're trying to paint.

Re: ‘I will show you how safe Telegram is’

#185

Earlier quoted context omitted.

Where did you get that idea from? Their client code is not usable because they don't provide working instructions for compiling it. If you can't compile it, they can't have reproducible builds. For example, see this issue from 2019 which the developers still haven't replied to: https://github.com/TelegramMessenger/Telegram-iOS/issues/97 There are a lot more issues about people not being able to use the code, none of…

GitHub builds directly from their source code just fine: https://github.com/TelegramMessenger/Telegram-iOS/actions/ru... (uses this script: https://github.com/TelegramMessenger/Telegram-iOS/blob/maste... ) And here are few recent examples of them helping people to solve build issues: https://github.com/TelegramMessenger/Telegram-iOS/issues/968... https://github.com/TelegramMessenger/Telegram-iOS/issues/986... https:/…

[deleted]

Re: ‘I will show you how safe Telegram is’

#186
post #48
post #31

Earlier quoted context omitted.

> My takeaway is that for truly private chat one should write his own software That's the only way to make sure you're using software you trust, but rolling your own crypto implementations is often not so secure (because of the many pitfalls).

You don't have to roll your own crypto. You can e.g. just use libsodium which is designed to be easy-to-use and not possible to use incorrectly.

I'd have no idea where to start securing an app against side channel hacks.

Is the memory encrypted? Should it be? Can other apps access it?

E2E might be working fine, its the ends I'd be concerned about.

Re: ‘I will show you how safe Telegram is’

#187

Earlier quoted context omitted.

Huh? Their client code isn't just fully open-source, it also has reproducible builds both on Android and iOS, has been for a while. Doesn't Signal only have them on Android? It's a great app either way but if RBs matter, that's a little knock against it.

Where did you get that idea from? Their client code is not usable because they don't provide working instructions for compiling it. If you can't compile it, they can't have reproducible builds. For example, see this issue from 2019 which the developers still haven't replied to: https://github.com/TelegramMessenger/Telegram-iOS/issues/97 There are a lot more issues about people not being able to use the code, none of…

It certainly is usable. I'd used Telegram FOSS from F-Droid for quite long before switching to Nekogram (also on F-Droid), a third-party Telegram client with some extra features.

Incidentally, Signal is still not available on F-Droid, and Signal developers are known to be hostile towards third-party clients (for "security reasons." Almost like I've heard that argument before from a certain smartphone manufacturer...)

Re: ‘I will show you how safe Telegram is’

#188

Earlier quoted context omitted.

Confused by this; Moxie did eventually concede and provide a signed APK.

Drew DeVault took the time to write it up: https://drewdevault.com/2018/08/08/Signal.html

> Truly secure systems don’t require trust.

This blatant absolutist statement is completely false. It exactly means, that there is no computer which is secure today. It also means, that it’s pointless to care about security on any phone in existence, because it cannot be achieved that currently.

Re: ‘I will show you how safe Telegram is’

#189
There's a broader question I've been raising for a number of years now, about how major online service providers address the brownshirt threat. I'd first raised that in 2016 on the now-defunct Google+, entirely coincidentally on the anniversary of Kristallnacht:

https://web.archive.org/web/20170604101018/https://plus.goog...>

Telegram seems to either have turned or been compromised from the start. Given transitions closer to HN's home, Twitter's userpation by an alt-right zottanaire would be another case in point. Ironically, Yonatan Zunger and Lea Kissner (to whom I'd addressed much of that post's message) were both at Twitter when Musk acquired it, though both have since left. (Zunger was G+'s chief architect, Kissner lead a security team there. For all its various faults, G+ had relatively little co-option by fascists, something I had an opportunity to assess during the site's shutdown, by way of the 8-million-odd Communities that existed, some with clearly white nationalist / antisemitic, or other bents, virtually all of which were inactive for years by the time I looked at them (late 2018 / early 2019), whilst at the same time legitimate use of terms such as "Aryan" in an Indian/Hindu context were generally active. Google+ managed to avoid the Scunthorpe Problem.

Mediated communications, particular the electronic / digital / AI variants ... are seeming increasingly fraught. The Telegram story is a bump on that node.

Thought as I write this: Telegram's namesake, the original telegraph, was itself notably used to intercept and alter communications back in the day, notably news of the outcome at Waterloo and by agents of Standard Oil.

Re: ‘I will show you how safe Telegram is’

#190
I'm in China, and I just see people learning about this the very hard way. There were many unusual unrests and crackdowns recently.

SMS is definitely a weak spot without a second thought. The state actor can easily analyse and reroute then pull off a massive list of names straight to gulag.

Post reply on HN