Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

131–140 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#132
post #90

Telegram were claiming they were more secure even when they had their own home-rolled crypto. Security is not Telegram's strong point and it never was.

Why is home-rolled crypto inherently insecure?

Because doing proper crypto is VERY hard. You might think you've gotten the ultimate security and one year later someone will defeat it (or cryptanalize within a practical limit, which boils down to the same), because you forgot a detail. Even just implementing a crypto algorithm properly in a way that doesn't leak information is very complex, reason for which most applications tend to use well-established crypto libraries.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#133
post #87

To quote one comment (Phillip.png): "With assistance from Elon Musk" is a pretty big accusation. I held off replying until I read your whole thread, and then you didn't mention that at all. What the hell?" Seriously, what the heck has Elon Musk to do with this? Unless we also want to debate what we all think of Elon Musk when we talk about chat protocols?

[deleted]

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#135

I don't know about Telegram being nasty towards Signal but Signal brought this upon themselves. Metadata are more important than the content of the messages and yet Signal has always been about knowing your phone number, with handwaving when the subject is mentioned. Sessions, a Signal fork, had its tagline right: "Share encrypted messages, not metadata" . Signal is a metadata exchanging app and it's about collecting…

But Signal specifically used phone numbers to leverage the already existing social graph on your phone. The numbers were never transferred or stored by Signal. You can literally see what information they gave when they were subpoenad: https://signal.org/bigbrother/central-california-grand-jury/

If you read the PDF, the phone numbers are in the subpoena as the key for what's being requested, so yes they clearly were stored in a way Signal can access.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#136
post #96

Stating that Telegram is unencrypted is incorrect. It offers optional end-to-end encryption; however, by default, it uses encryption in transit. Of course, there is a trade-off between convenience and encryption, and having access to all messages on all devices is beneficial. However, technicalities are not the point: both Ukrainians and Russians trust Telegram—despite being at war. Telegram has managed to distribute…

Having in-transit encryption in your communications software is kindergarten level stuff. It's the most minimum of hurdles to pass, so it's not worth mentioning anymore. Thus encryption always refers to E2E encryption in these discussions.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#137
Telegram is just as bullshit as WhatsApp etc as long as it requires:

* A phone number

* Access to your contacts

WHY do messaging apps need ALL our contacts? Why can't we add only the people we want to stay in touch with on a particular app?

WHY doesn't Apple let us choose WHICH contents to let an app steal, just like we can with limited photos access?

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#138
post #74

You can download Telegram and many forked clients from F-Droid. All the builds are from source code, so you know the source code is up-to-date. Any distro can have Telegram clients, both official and third-party, in their repository. Compared to this 1. You cannot download Signal from F-Droid. You need to download it from the Google Play Store. The released source code has lagged behind the version on the Google Play…

Telegram Foss clients exist only because of unpaid volunteers that take Telegrams messy mix of open and closed parts and rip closed parts out and replace them. The Telegram organisation is notoriously late to release the source code to their current release. If they do, its a giant squashed commit without proper changelog. These releases must then be first wrangled by volunteers to be well buildable.

The Telegram Org itself gives no support to volunteers at all.

You can't register with Foss builds. Only official binaries. Nowadays a lot of features are premium only. You can only get premium with official binaries. That part is closed.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#139

I don't know about Telegram being nasty towards Signal but Signal brought this upon themselves. Metadata are more important than the content of the messages and yet Signal has always been about knowing your phone number, with handwaving when the subject is mentioned. Sessions, a Signal fork, had its tagline right: "Share encrypted messages, not metadata" . Signal is a metadata exchanging app and it's about collecting…

Signal has got Usernames now. You can block number discovery. You can't resolve username to number. Your main account ID internally is not your number anymore. If 2 users add you using 2 different links or usernames. Its now harder to confirm its the same account.

You still need a phone number to sign up
Post reply on HN