Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

181–190 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#182
post #74

You can download Telegram and many forked clients from F-Droid. All the builds are from source code, so you know the source code is up-to-date. Any distro can have Telegram clients, both official and third-party, in their repository. Compared to this 1. You cannot download Signal from F-Droid. You need to download it from the Google Play Store. The released source code has lagged behind the version on the Google Play…

Telegram Foss clients exist only because of unpaid volunteers that take Telegrams messy mix of open and closed parts and rip closed parts out and replace them. The Telegram organisation is notoriously late to release the source code to their current release. If they do, its a giant squashed commit without proper changelog. These releases must then be first wrangled by volunteers to be well buildable. The Telegram Org…

Good point- I forgot that the FOSS clients were 3rd party.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#183
post #105

Earlier quoted context omitted.

People has been killed based on metadata https://www.nybooks.com/online/2014/05/10/we-kill-people-bas...

No is arguing the metadata is harmless but it's significantly less of an issue than not having E2EE.

When they-them-those know who you are, knowledge of the full attack surface is the better way to compromise because it leaves the first step to compromise uncompromising-appearing. (The attack surface is broader than people generally consider, as it should include over-the-shoulder attacks, XKCD's wrench attack, etc.)

The success of such tactics can more easily be understood by even looking through the many, many comments right in this thread telling us Signal protects metadata because usernames are now a feature - guys, Signal has the metadata as the *services* are what is the topic of discussion here, not other users.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#184

There seems to be a concerted effort to discredit Matthew's claims. Even here on HN. I find this suspicious. The Signal protocol has been heavily audited by many different people from many different countries. It's usually found to be sound. The telegram protocol has been found to have issues that are, if not malicious, amateur level mistakes. Once again, this is not my opinion. This is the result of independent audi…

> The telegram protocol has been found to have issues that are, if not malicious, amateur level mistakes. Please provide evidence of such issues. Because at most, the issues with MTProto were at the level of "we are not familiar with this, but seems ok". Which seem to be inflated by Signal activists into maliciousness. You do make bear service here.

"You do make bear service here."

I'm not sure what this means.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#185
post #86
post #41

Earlier quoted context omitted.

Yep. The magic of "you could turn on encryption" is that nearly all people using it won't. "Ah, but if you need encryption then you'll..." - well, two things now. Suddenly you're the person who has encryption switched on . And also more likely, someone they talk to will forget to switch it on and just blab everything into cleartext anyway. The entire importance of Signal's model is that it is always encrypted. It's w…

Addressing only one point, not your main one which I agree with: > And also more likely, someone they talk to will forget to switch it on and just blab everything into cleartext anyway. I expect that if you enable a Telegram Secret Chat with Bob, Bob cannot unilaterally un-secret it. I would be very surprised if that was the case. Of course Bob can then share the contents with Carol via an un-encrypted channel. But e…

Last I used Telegram, creating an e2ee chat with someone added an encrypted chat in addition to the unencrypted chat. This means if your not careful in which chat with a single person a message is sent to it's easy to accidentally send unencrypted data.

I'd guess this is possible because Telegram e2ee chats aren't multi-device capable, so it's necessary to be able to use unencrypted chats while using Telegram on something else than the phone with e2e.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#186

So since Signal has a board member who worked at a place that some people don't like then the Signal app must be backdoored/compromised/honeypot? That's one hell of a leap. How far has our requirement for evidence fallen?

Um, yes. When the “place that some people don’t like” is all sorts of CIA-connected NGOs and you’re a member of group defined by its paranoia about privacy, then absolutely this becomes disqualifying.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#187
post #151
post #57

Earlier quoted context omitted.

Signal's definition of "reproducible" meant for quite a while "download this binary docker image and build Signal inside of it". I don't know if that has changed since. Signal rejects F-Droid for a different reason, though: They only want to distribute through channels where they get download statistics and control update rollouts.

Hm f-droid provides privacy friendly https://fdroid.gitlab.io/metrics/ for some time now. I'm not sure what sort of "control" they have over the Play Store compared to f-droid, but I'd rather have a trusted 3rd party do the building transparently and verifyable.

F-Droid uses a package maintainer-esque process where the maintainers of F-Droid can intervene and prevent an update to an app from reaching users if it's deemed to be malicious or to add anti-features.

It's of particularly high need on mobile since popular apps, even those who were originally FOSS, are sold to scummy publishers who fill it with ads and subscription schemes (oft called anti-features, since removing them could be seen as a feature in and of itself), ruining the original. You can't really trust mobile app devs because the track record is downright awful. Recently that happened with the "Simple" collection of apps, where the Play Store version got filled with junk but the F-Droid maintainer froze the version and marked the apps as outdated since nobody could conceivably want the new versions.

Of course, that strokes poorly with developers who a. don't want to deal with potential third parties in their distribution chain rejecting their updates or b. are planning to add anti-features to their apps later down the line. With signal, I'm gonna guess it's mainly a; the Play Stores checks and balances are much less invasive than the sort of thing an F-Droid maintainer might check for. (As I understand it, Google Plays checks mostly are anti-exploit and keyword scans.)

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#188
post #75

Another thing that wasn't pointed out: Du Rove said "Signal messages have been exploited against them in US courts or media." This would be the same case for Telegram as well, if someone has your phone. I believe that Signal can have a lock on the client, and the database is encrypted. The other part that Du Rove conveniently left out: Signal went against the US courts and won [0]. When subpoenaed to give all user in…

Telegram has moved to Dubai long ago so no idea where you get the idea that FSB can strong-arm them from.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#189
post #74

You can download Telegram and many forked clients from F-Droid. All the builds are from source code, so you know the source code is up-to-date. Any distro can have Telegram clients, both official and third-party, in their repository. Compared to this 1. You cannot download Signal from F-Droid. You need to download it from the Google Play Store. The released source code has lagged behind the version on the Google Play…

> The released source code has lagged behind the version on the Google Play store by long periods of time many times.

Seems like FUD. This took me 30 seconds to check just now:

-Telegram's android source code git hasn't had a tagged release in more than two months and is several versions behind the android app (10.12.0 vs 10.9.1)[1]

-Signal's android source has a tagged release two days ago that is two releases ahead of the stable version on google's app store, and also lists the tagged release for the version that is on the app store.[2]

[1] https://github.com/DrKLO/Telegram/releases

[2] https://github.com/signalapp/Signal-Android/tags

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#190

Earlier quoted context omitted.

Tell me, can you have a Signal account WITHOUT giving them your phone number?

Can you sign up for Telegram without a phone number?

Yes: https://telegram.org/blog/ultimate-privacy-topics-2-0
Post reply on HN