Live data from Hacker News

‘I will show you how safe Telegram is’

twitter.com

191–200 of 206 posts

Re: ‘I will show you how safe Telegram is’

#191
post #150

Earlier quoted context omitted.

Moxie Marlinspike - and Whisper Systems - have assumed a variety of concerning positions over the years. Concerning, because their flaws are obvious, yet Moxie - a very smart guy - pretends not to notice them. For example, Moxie defended discontinuing encrypted SMS on the grounds that it leaked metadata to telcos - yet failed to emphasize that this was merely the same metadata leaked to Whisper Systems, or justify wh…

The SMS support that was discontinued was for plain SMS to/from other plain SMS numbers from within the Signal app - it was not encrypted.

Nope: https://signal.org/blog/goodbye-encrypted-sms/

Re: ‘I will show you how safe Telegram is’

#192
post #17

Earlier quoted context omitted.

Indeed, you're right: the worst that can happen is that chat recipients would see a "your security number has changed". But nothing will happen when talking to a whole new person, or when you join a group you've never been in before.

But notice that these are all things you could do anyway. Why are we even bothering to impersonate someone else? If local group "Superb Fun for a Superb Owl" is letting in anybody who wants to join, rather than pretending to be party animal Steve, by using SMS interception to impersonate Steve, why wouldn't a cop named Bill just join the group as Bill ? And if they don't want cops, perhaps because they suspect that "…

The impersonator, by definition isn't known. Only the profile being impersonated is.

If an activist is part of a private group, and a cop impersonates the activist, they can get all the new messages without raising any doubt. In a lively conversation, the cop can even send messages and expect the activist not to see them. Disappearing messages will help here.

Re: ‘I will show you how safe Telegram is’

#193
post #22

Earlier quoted context omitted.

We know from experience that most users never change defaults. For that reason alone, Telegram‘s "secure chat" is anything but.

> For that reason alone, Telegram‘s "secure chat" is anything but. I didn't think that particular Telegram feature was affected in any way by any option, only that they needed to be started explicitly but were always secure no matter what. So I immediately went looking through my settings and found an option that leaks tracking info by default, even in Secure Chats. Signal, by default, routes all calls through their…

Huh? Signal uses P2P call routing by default. The "always relay" option is available for users who do not want to reveal their IP to anyone but the OWS service, and is found (defaulted to off) in Settings>Privacy>Advanced>Always Relay Calls.

Of course of P2P is impossible your call gets routed through the server no matter what, but I don't think there's a fix for that -- there's ~always going to be a need to relay connections in case of NAT issues, firewalls, etc.

Re: ‘I will show you how safe Telegram is’

#194

Earlier quoted context omitted.

Both could be, just from different queen bees

Moxie Marlinspike is a lot of things but I'm pretty confident the queen bee of a honeypot is not one of them.

Even assuming Moxie is beyound doubt, that won't help much today, as he resigned as Signals CEO.

"https://www.bbc.com/news/technology-59937614"

(He is still part of Signals board, though).

Re: ‘I will show you how safe Telegram is’

#195

Earlier quoted context omitted.

Because to beat up someone and order them to unlock their phone is faster, does not require trained staff, can be done anywhere and is fun for the cops. In some cases they use israeli hardware (forgot the name of the company), if you are fooled into giving your phone away for some period of time, like entering a police building, where they have a "no-phone zone" for visitors.

> Because to beat up someone and order them to unlock their phone is faster, does not require trained staff, can be done anywhere and is fun for the cops. The implicit assumption is that the states always go for the faster solution. I'd argue that intercepting an SMS/call is easier/faster for nation-states, than arrest and torture; most carriers worldwide have interception capabilities mandated by law: using the secr…

> The implicit assumption is that the states always go for the faster solution.

That’s what cops in Belarus did to me twice since 2020 when I declined to unlock my phone. That’s what they did to many of my friends and colleagues. Hacking happens but it is a more of an exception as it requires planning and effort, which is hard. Blackmail and threats are much easier.

Re: ‘I will show you how safe Telegram is’

#196

Earlier quoted context omitted.

Where did you get that idea from? Their client code is not usable because they don't provide working instructions for compiling it. If you can't compile it, they can't have reproducible builds. For example, see this issue from 2019 which the developers still haven't replied to: https://github.com/TelegramMessenger/Telegram-iOS/issues/97 There are a lot more issues about people not being able to use the code, none of…

It certainly is usable. I'd used Telegram FOSS from F-Droid for quite long before switching to Nekogram (also on F-Droid), a third-party Telegram client with some extra features. Incidentally, Signal is still not available on F-Droid, and Signal developers are known to be hostile towards third-party clients (for "security reasons." Almost like I've heard that argument before from a certain smartphone manufacturer...)

Yep, I also use Nekogram. I like how open the client aspect is of Telegram.

Re: ‘I will show you how safe Telegram is’

#198
post #191

Earlier quoted context omitted.

The SMS support that was discontinued was for plain SMS to/from other plain SMS numbers from within the Signal app - it was not encrypted.

Nope: https://signal.org/blog/goodbye-encrypted-sms/

Ah, right. I thought OP was referring to https://www.signal.org/blog/sms-removal-android/ , my bad.

Re: ‘I will show you how safe Telegram is’

#199
post #192

Earlier quoted context omitted.

But notice that these are all things you could do anyway. Why are we even bothering to impersonate someone else? If local group "Superb Fun for a Superb Owl" is letting in anybody who wants to join, rather than pretending to be party animal Steve, by using SMS interception to impersonate Steve, why wouldn't a cop named Bill just join the group as Bill ? And if they don't want cops, perhaps because they suspect that "…

The impersonator, by definition isn't known. Only the profile being impersonated is. If an activist is part of a private group, and a cop impersonates the activist, they can get all the new messages without raising any doubt. In a lively conversation, the cop can even send messages and expect the activist not to see them. Disappearing messages will help here.

To make things easier, let's suppose our Activist is named Alice, and our Cop is named Charlie.

> The impersonator, by definition isn't known. Only the profile being impersonated is.

Charlie isn't able to impersonate Alice's profile because that's encrypted and Charlie doesn't have the key. Charlie can make a fresh profile, but it's not Alice's, although of course Charlie is able to use a stock photo of Alice (if he has one) and name it "Alice". Let's label this Alice2.

> If an activist is part of a private group, and a cop impersonates the activist, they can get all the new messages without raising any doubt.

Although Alice may be part of a group, Charlie isn't and Alice2 isn't either. Messages sent to Alice (as a group member) are not received by Alice2, who wouldn't be able to decrypt them anyway. Charlie will need to (as Alice2) ask to have Alice2 admitted to the group. Perhaps he can pretend Alice dropped her phone and bought a new one. Depending on what sort of "activist group" this is and the threat level, this may be quite easy or involve an in-person meeting which will be difficult to fake.

Of course since apparently you're imagining Alice is actually still around, she presumably tells people Alice2 is an imposter and it's likely this goes very badly for Charlie even if it's not an in-person meeting.

> In a lively conversation, the cop can even send messages and expect the activist not to see them. Disappearing messages will help here.

If Alice isn't knocked off the network, none of this "impersonation" works. You seem to be imagining Signal is some toy message board system where you can log in as Alice - just need an SMS, but it's nothing like that, that's why subpoenas don't bring anything meaningful back when they ask Signal about phone numbers, Signal doesn't know anything.

Re: ‘I will show you how safe Telegram is’

#200
post #105

Earlier quoted context omitted.

Only if you have one device: once you have authenticated on two devices the code is sent over Telegram to other devices you have. In that case there is no option to fall back to SMS when authenticating. I think if you lose all your devices then you're locked out, unless you have a recovery email set up. In addition, if login succeeds, an authentication warning that a new device has connected is sent to every other de…

> In that case there is no option to fall back to SMS when authenticating. That's not true. The option is there. (Edit: at least for now, some changes in that area are upcoming) > In that case there is no option to fall back to SMS when authenticating. The attack usually happens at night. By the time you wake up, all your chat histories are already downloaded and the secret police is on its way.

> That's not true. The option is there.

I tried it before I wrote the comment to be 100% sure, the option was not there, and it still is not.

I am not sure why it is the case but I am quite sure it was the case way before as I was making sure of this back then.

Post reply on HN