Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

151–160 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#151
post #57
post #48

Earlier quoted context omitted.

Signal has reproducible builds for android now? Why not f-droid then, too?

Signal's definition of "reproducible" meant for quite a while "download this binary docker image and build Signal inside of it". I don't know if that has changed since. Signal rejects F-Droid for a different reason, though: They only want to distribute through channels where they get download statistics and control update rollouts.

Hm f-droid provides privacy friendly https://fdroid.gitlab.io/metrics/ for some time now.

I'm not sure what sort of "control" they have over the Play Store compared to f-droid, but I'd rather have a trusted 3rd party do the building transparently and verifyable.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#152
post #96

Stating that Telegram is unencrypted is incorrect. It offers optional end-to-end encryption; however, by default, it uses encryption in transit. Of course, there is a trade-off between convenience and encryption, and having access to all messages on all devices is beneficial. However, technicalities are not the point: both Ukrainians and Russians trust Telegram—despite being at war. Telegram has managed to distribute…

Optional E2E encryption is effectively not encryption. The default encryption in transit is useless if you don't trust the server. The argument about convenience is ridiculous. Whatsapp provides better default encryption than Telegram. The (probably deliberate) flaw in Whatsapp encryption is the default backup method, but E2E encryption is enabled by default with no loss in convenience. Telegram is not encrypted by default, and their encryption scheme has been shown to have rookie level mistakes in it. Just because it's "preferred by activists" doesn't mean said activists have any idea about secure communications.

I'm not saying that you should jump on Signal (or anything else). I'm saying Telegram is almost certainly broken. Maybe maliciously, maybe accidentally, but almost certainly.

For reference, I don't use either Signal or Telegram anymore, but Telegram sets off so many alarms I'd steer clear of it.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#153
post #37

Not a huge fan of Signal (phone number requirement [0], crypto push a while ago), but there are worlds between those two, and every time the Telegram CEO makes a post it looks more like a scam than before. [0]: Yeah, might be changing or has already. Now, after ages.

> phone number requirement. Yeah, might be changing or has already. Now, after ages. A phone number is still required for registration. As of a few weeks, it's not necessarily communicated to your contacts anymore, which solves a few concerns (but not all). > crypto push a while ago I was worried about this, but I use Signal daily and I haven't even noticed anything in the UI about this, it seems like a non event in…

The crypto payments have to be manually enabled under Settings -> Payments, which is the correct way to handle such features imo.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#154
post #74

You can download Telegram and many forked clients from F-Droid. All the builds are from source code, so you know the source code is up-to-date. Any distro can have Telegram clients, both official and third-party, in their repository. Compared to this 1. You cannot download Signal from F-Droid. You need to download it from the Google Play Store. The released source code has lagged behind the version on the Google Play…

Telegram Foss clients exist only because of unpaid volunteers that take Telegrams messy mix of open and closed parts and rip closed parts out and replace them. The Telegram organisation is notoriously late to release the source code to their current release. If they do, its a giant squashed commit without proper changelog. These releases must then be first wrangled by volunteers to be well buildable. The Telegram Org…

This doesn't affect the user that downloads these from distro repos or F-Droid because every single update they get comes from the source code. There is never a lag even for 1 second because without the source code there are no builds.

Pretty much all the packages on Linux repos come from package maintainers taking upstream source code, removing parts they don't like and then building that. This is a normal part of packaging and building open-source apps.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#155

Earlier quoted context omitted.

I don't get this. I'm in the EU and nearly everybody I know has Telegram. Telegram has a huge advantage versus WhatsApp: it's not Meta. Then the Telegram UI is really excellent. When you tell people all your friends and family are using it and that's it's not from Facebook, they usually install it on the spot. Then they're hooked.

I'm in France and don't know anyone using it. Except the government, as reported in the news. Actually the only time I used it it's because I needed to chat with a Russian SaaS personnel.

I know few people who use Telegram either. All my contacts and I use Signal here.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#157
post #74

You can download Telegram and many forked clients from F-Droid. All the builds are from source code, so you know the source code is up-to-date. Any distro can have Telegram clients, both official and third-party, in their repository. Compared to this 1. You cannot download Signal from F-Droid. You need to download it from the Google Play Store. The released source code has lagged behind the version on the Google Play…

Your points have little to do with security (which is the main angle of Matthew Green's thread), especially because of reproducibility.

Even then

> You need to download it from the Google Play Store.

Factually incorrect, just go to https://signal.org/android/apk/ (and the apk will then update itself) or build it yourself.

> pushed the update to everyone but no one could inspect the source code.

That was for the server code, which you shouldn't care about from a security standpoint for an E2EE messenger such as Signal. AFAIK that was not the case for the clients.

Regarding your other points, they have reasons that have been discussed elsewhere[0] to avoid federation, notably a lot of the progress on the Signal protocol would be way harder in a federated setting. There's no other messenger that has the same usability ("my grandfather can use it and won't have problems using it afterwards") while being at this level security-wise.

[0]: https://signal.org/blog/the-ecosystem-is-moving/

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#158
post #102
post #87

To quote one comment (Phillip.png): "With assistance from Elon Musk" is a pretty big accusation. I held off replying until I read your whole thread, and then you didn't mention that at all. What the hell?" Seriously, what the heck has Elon Musk to do with this? Unless we also want to debate what we all think of Elon Musk when we talk about chat protocols?

https://twitter.com/elonmusk/status/1787908190799278360 https://twitter.com/elonmusk/status/1787589564917490059 Keep in mind that X/Twitter's "For You" algo boosts posts to which Elon replies in his followers' feeds.

Thanks for the missing context, I think that qualifies as "boosting".

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#159

There seems to be a concerted effort to discredit Matthew's claims. Even here on HN. I find this suspicious. The Signal protocol has been heavily audited by many different people from many different countries. It's usually found to be sound. The telegram protocol has been found to have issues that are, if not malicious, amateur level mistakes. Once again, this is not my opinion. This is the result of independent audi…

You can have a secure verified protocol but an insecure implementation of the protocol (the app). Note though that Im not saying that Signal the app is insecure. However I do think that Signal can certainly do more to make itself more transparrent and to accomodate libre 3rd party implementations of their protocol

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#160

There seems to be a concerted effort to discredit Matthew's claims. Even here on HN. I find this suspicious. The Signal protocol has been heavily audited by many different people from many different countries. It's usually found to be sound. The telegram protocol has been found to have issues that are, if not malicious, amateur level mistakes. Once again, this is not my opinion. This is the result of independent audi…

> The telegram protocol has been found to have issues that are, if not malicious, amateur level mistakes.

Please provide evidence of such issues. Because at most, the issues with MTProto were at the level of "we are not familiar with this, but seems ok". Which seem to be inflated by Signal activists into maliciousness.

You do make bear service here.

Post reply on HN