Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

191–200 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#191
post #83

I don't know about Telegram being nasty towards Signal but Signal brought this upon themselves. Metadata are more important than the content of the messages and yet Signal has always been about knowing your phone number, with handwaving when the subject is mentioned. Sessions, a Signal fork, had its tagline right: "Share encrypted messages, not metadata" . Signal is a metadata exchanging app and it's about collecting…

Not sure if metadata is more important but ok. Signal has launched support to use nicknames instead of phone numbers although it's true this took a long time. I think Telegram is very wide-spread for running large group chats and communities, a use case that Signal is not interested in. Personally, I want my chats end to end encrypted and I'm grateful to Signal for pioneering this and inspiring Whatsapp, facebook mes…

>> Signal has launched support to use nicknames

Wow, really? ICQ had that in 1996 ...

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#192

So, who has actually launched "a pretty intense" campaign here? https://twitter.com/matthew_d_green/status/17883860908411619... https://twitter.com/evacide/status/1788040276331884593 https://twitter.com/naomibrockwell/status/178863495226900939... https://twitter.com/paulmillr/status/1788563576455610552 (I'm pretty sure the list goes on)

Here's the other side:

https://news.ycombinator.com/item?id=40301508

https://news.ycombinator.com/item?id=40336005

https://news.ycombinator.com/item?id=40330694

https://news.ycombinator.com/item?id=40308241

https://news.ycombinator.com/item?id=40299313

https://news.ycombinator.com/item?id=40298608

https://news.ycombinator.com/item?id=40279661

https://twitter.com/jack/status/1787895769183268948

https://twitter.com/elonmusk/status/1787908190799278360

https://twitter.com/elonmusk/status/1787589564917490059

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#193

So since Signal has a board member who worked at a place that some people don't like then the Signal app must be backdoored/compromised/honeypot? That's one hell of a leap. How far has our requirement for evidence fallen?

It is kind of too late at that point. Good security requires proactive measures.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#194
post #131
post #42

Earlier quoted context omitted.

We don’t have to trust the board. We have the binaries.

The binaries? This sounds like some kind of joke.

It is pretty bad bait, but then this whole thread is a dumpster fire of distraction from any substance.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#195
post #130
post #74

You can download Telegram and many forked clients from F-Droid. All the builds are from source code, so you know the source code is up-to-date. Any distro can have Telegram clients, both official and third-party, in their repository. Compared to this 1. You cannot download Signal from F-Droid. You need to download it from the Google Play Store. The released source code has lagged behind the version on the Google Play…

> 2. Signal has sent legal threats to repositories that package Signal. The repos either need to confuse users by offering the client under other package names or remove it. Not that I really want to defend Signal (XMPP FTW!), but the legal threats were about using the Signal name, not making an unofficial client per se. I know a bit about it because I develop an alternative signal client (a signal-XMPP gateway to be…

I can understand that if they didn't compile it themselves they don't want 3rd parties using the 'Signal' name.

The name is what their reputation is staked on, and if a third party compiled it they have no idea if malware is secretly packaged in there too.

Having said that, the smart move is to dedicate a few engineer hours to packaging it for every linux distribution and every app store, even the smallish ones, to prevent others trying to 'be helpful' and requiring you to send a takedown.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#196
post #58

This is a response to the following post from Telegram creator Durov https://t.me/durov/274

- "I don't like where one of their board worked" (find someone high up in the cryptography ecosystem who hasn't been involved in this sort of thing somewhere in their career)

- "I don't like where their funding comes from" (US govt regularly funds secure software because they depend on it for their own operations, see: Tor)

- "An alarming number of people think their chats were leaked". It's easy to state things without sources. Also an alarming number of people think Facebook listens to them through their phones' mic. People are bad at opsec. Not news.

- "No reproducible builds. They closed a GitHub request from the community." Well, except Android is reproducible, and they explicitly state on that closed issue that they don't do feature requests via GitHub and asked the reporter to raise in the proper channel.

- "Telegram is the only service with reproducible builds". Telegram barely has encrypted chats, reproduce all you like, that doesn't make the chats secure. Signal has E2E encryption and verifiable builds for Android, that's a strictly better security position.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#197
post #60

Earlier quoted context omitted.

"including confidential messaging with their agents on the foreign territory" Possible, as many ridiculous things happened around the whole war. (Recently german generals on a video chat were targeted by the russians, wasn't too hard, they did not use any encyption at all) Sources would be nice though. But it really would not be a reason for me to trust telegrams security. Rather a confirmation again, that also secre…

> Recently german generals on a video chat were targeted by the russians, wasn't too hard, they did not use any encyption at all They used Webex. Doesn't Webex use any encryption at all?

It can use encryption. But they choose not to for probably lazy reasons. Which is bad for normal persons, even worse for generals who should lead by example - and ridiculous for generals with an background in IT who really should know better. But as far as I know, there were no real consequences so apparently it was not such a big deal.

https://en.m.wikipedia.org/wiki/German_Taurus_leak

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#198
post #151
post #57

Earlier quoted context omitted.

Signal's definition of "reproducible" meant for quite a while "download this binary docker image and build Signal inside of it". I don't know if that has changed since. Signal rejects F-Droid for a different reason, though: They only want to distribute through channels where they get download statistics and control update rollouts.

Hm f-droid provides privacy friendly https://fdroid.gitlab.io/metrics/ for some time now. I'm not sure what sort of "control" they have over the Play Store compared to f-droid, but I'd rather have a trusted 3rd party do the building transparently and verifyable.

Their problem is that F-Droid releases are signed by F-Droid, not by Signal. This way F-Droid could potentially insert a backdoor in an update.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#199

So, who has actually launched "a pretty intense" campaign here? https://twitter.com/matthew_d_green/status/17883860908411619... https://twitter.com/evacide/status/1788040276331884593 https://twitter.com/naomibrockwell/status/178863495226900939... https://twitter.com/paulmillr/status/1788563576455610552 (I'm pretty sure the list goes on)

this is honestly quite surprising... why are they so adamant? we know telegram is not super safe, but at least is not facebook.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#200

They want to do this because they want more traction for their blockchain: TRON, which, IIRC, is the payment method for ads, usernames and "stuff" inside Telegram. However Du Rove is right about a bunch of things: - Signal clients suck, specially the Desktop one where they ship (or used to) pre-built binaries like their own lib: https://github.com/signalapp/ringrtc - Also you can't have Signal without Google Play Sto…

ton and tron are not the same thing
Post reply on HN