Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

201–210 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#201
post #130
post #74

You can download Telegram and many forked clients from F-Droid. All the builds are from source code, so you know the source code is up-to-date. Any distro can have Telegram clients, both official and third-party, in their repository. Compared to this 1. You cannot download Signal from F-Droid. You need to download it from the Google Play Store. The released source code has lagged behind the version on the Google Play…

> 2. Signal has sent legal threats to repositories that package Signal. The repos either need to confuse users by offering the client under other package names or remove it. Not that I really want to defend Signal (XMPP FTW!), but the legal threats were about using the Signal name, not making an unofficial client per se. I know a bit about it because I develop an alternative signal client (a signal-XMPP gateway to be…

The official Signal stance has been last I checked:

>we really don't want forked versions of the app maintained by other parties connecting to our servers.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#202

Earlier quoted context omitted.

> The telegram protocol has been found to have issues that are, if not malicious, amateur level mistakes. Please provide evidence of such issues. Because at most, the issues with MTProto were at the level of "we are not familiar with this, but seems ok". Which seem to be inflated by Signal activists into maliciousness. You do make bear service here.

https://eprint.iacr.org/2023/469.pdf

From your own link:

> Recently, in [MV21 ] MTProto 2.0 (the current version) was proven secure in a symbolic model, but assuming ideal building blocks and abstracting away all implementation/primitive details.

Translation: it is secure, except for bugs, if any.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#203
post #107
post #74

You can download Telegram and many forked clients from F-Droid. All the builds are from source code, so you know the source code is up-to-date. Any distro can have Telegram clients, both official and third-party, in their repository. Compared to this 1. You cannot download Signal from F-Droid. You need to download it from the Google Play Store. The released source code has lagged behind the version on the Google Play…

All true. But where are the sources of Telegram server? They are not open source, simply! What are they actually doing with our messages? Only they know. And they can read them because by default there's no E2E encryption.

would it matter if the server was open source? You'd know have no proof what is what they run on the actual server anyway, nor can you use a custom server.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#204

Earlier quoted context omitted.

A nitter instance that still works? What is this sorcery?

Nitter still works if you configure the instance to use valid accounts.

* enough valid accounts. If the instance gets popular, you're going to need hundreds of them to get past rate limits according to the announcements some time ago (maybe the rate limits have changed though)

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#205
post #157
post #74

You can download Telegram and many forked clients from F-Droid. All the builds are from source code, so you know the source code is up-to-date. Any distro can have Telegram clients, both official and third-party, in their repository. Compared to this 1. You cannot download Signal from F-Droid. You need to download it from the Google Play Store. The released source code has lagged behind the version on the Google Play…

Your points have little to do with security (which is the main angle of Matthew Green's thread), especially because of reproducibility. Even then > You need to download it from the Google Play Store. Factually incorrect, just go to https://signal.org/android/apk/ (and the apk will then update itself) or build it yourself. > pushed the update to everyone but no one could inspect the source code. That was for the serve…

> Factually incorrect, just go to https://signal.org/android/apk/ (and the apk will then update itself) or build it yourself.

That page tells me that the safest way is to have a Google account, with Google Play Services installed on my phone, and to download it from the Google Play Store.

It then gives me an APK link after saying "Danger zone" and "most users should not do this".

If the app developer tells me it's dangerous and I shouldn't do it, can you even expect users to do this?

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#206

Earlier quoted context omitted.

> The telegram protocol has been found to have issues that are, if not malicious, amateur level mistakes. Please provide evidence of such issues. Because at most, the issues with MTProto were at the level of "we are not familiar with this, but seems ok". Which seem to be inflated by Signal activists into maliciousness. You do make bear service here.

"You do make bear service here." I'm not sure what this means.

> The meaning of "bear's service" originally comes from a fable about a man and a bear. The bear wanted to help the man by killing a gnat which sat on his forehead. As a result both the gnat and the man died.

Basically, by being proactive you do more damage as if you didn't do anything.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#207

Earlier quoted context omitted.

> The telegram protocol has been found to have issues that are, if not malicious, amateur level mistakes. Please provide evidence of such issues. Because at most, the issues with MTProto were at the level of "we are not familiar with this, but seems ok". Which seem to be inflated by Signal activists into maliciousness. You do make bear service here.

"You do make bear service here." I'm not sure what this means.

This is a literal translation of a Russian idiomatic expression.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#208
This issue is sadly all just identity politics. Telegram is frequently associated with fringe groups, conspiracy theorists, anti-vaxxers, and "the right". Signal is pushed by the sort of lefty-liberals who quit Twitter, by journalists, and more associated with the mainstream media.

This is not to group everyone, I realise there are communities that cross that divide, and this is no judgement of people using either. But I think this divide will continue as the political trends continue. Both sides believe they are right, both more than they perhaps should given the evidence. That said, I'll stick with the one the cryptography/security nerds are using, not the one they think is a honeypot.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#209
post #145

There seems to be a concerted effort to discredit Matthew's claims. Even here on HN. I find this suspicious. The Signal protocol has been heavily audited by many different people from many different countries. It's usually found to be sound. The telegram protocol has been found to have issues that are, if not malicious, amateur level mistakes. Once again, this is not my opinion. This is the result of independent audi…

Eh, split any important message into pieces, put a piece each in Signal, WhatsApp, Telegram, Threema, Line, and then the Americans, Russians, Swiss, and Koreans will each have some parts, but if you're lucky, nobody has all...

I didn't even know Line was still a thing!
Post reply on HN