So, who has actually launched "a pretty intense" campaign here? https://twitter.com/matthew_d_green/status/17883860908411619... https://twitter.com/evacide/status/1788040276331884593 https://twitter.com/naomibrockwell/status/178863495226900939... https://twitter.com/paulmillr/status/1788563576455610552 (I'm pretty sure the list goes on)
this is honestly quite surprising... why are they so adamant? we know telegram is not super safe, but at least is not facebook.
Telegram has launched a pretty intense campaign to malign Signal as insecure
221–230 of 501 posts
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#222Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#223Earlier quoted context omitted.
This doesn't affect the user that downloads these from distro repos or F-Droid because every single update they get comes from the source code. There is never a lag even for 1 second because without the source code there are no builds. Pretty much all the packages on Linux repos come from package maintainers taking upstream source code, removing parts they don't like and then building that. This is a normal part of p…
Yes and thats why users spend sometimes months on old builds. Also which distro packages Telegram? Fedora doesn't. Debian does but at times it was so old the client crashed from receiving server comms because it wasn't fully compatible. It actually crashed as in segfault.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#224There seems to be a concerted effort to discredit Matthew's claims. Even here on HN. I find this suspicious. The Signal protocol has been heavily audited by many different people from many different countries. It's usually found to be sound. The telegram protocol has been found to have issues that are, if not malicious, amateur level mistakes. Once again, this is not my opinion. This is the result of independent audi…
> The telegram protocol has been found to have issues that are, if not malicious, amateur level mistakes. Please provide evidence of such issues. Because at most, the issues with MTProto were at the level of "we are not familiar with this, but seems ok". Which seem to be inflated by Signal activists into maliciousness. You do make bear service here.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#225Another thing that wasn't pointed out: Du Rove said "Signal messages have been exploited against them in US courts or media." This would be the same case for Telegram as well, if someone has your phone. I believe that Signal can have a lock on the client, and the database is encrypted. The other part that Du Rove conveniently left out: Signal went against the US courts and won [0]. When subpoenaed to give all user in…
Telegram iirc moved it's lead developers to Dubai specifically because the FSB was demanding info from them, so you could argue that's an unfounded concern. The bigger problem with Telegram is that it by default has insecure encryption settings (as opposed to Signal, where encrypted is the default, you need to manually activate it with Telegram + I think it's not possible to enable for all chats and clients) and to m…
Considering the state of Saudi Arabia, having it there is marginally better, but still problematic.
And if the developers are still Russian, there's nothing saying they aren't being squeezed unless their families came with them to Dubai.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#226Earlier quoted context omitted.
this is honestly quite surprising... why are they so adamant? we know telegram is not super safe, but at least is not facebook.
Ironically I saw that FB Messenger started adding E2EE by default to my chats, whereas Telegram I believe still requires opt-in.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#227You can download Telegram and many forked clients from F-Droid. All the builds are from source code, so you know the source code is up-to-date. Any distro can have Telegram clients, both official and third-party, in their repository. Compared to this 1. You cannot download Signal from F-Droid. You need to download it from the Google Play Store. The released source code has lagged behind the version on the Google Play…
> 2. Signal has sent legal threats to repositories that package Signal. The repos either need to confuse users by offering the client under other package names or remove it. Not that I really want to defend Signal (XMPP FTW!), but the legal threats were about using the Signal name, not making an unofficial client per se. I know a bit about it because I develop an alternative signal client (a signal-XMPP gateway to be…
that's just misleading misdirection.
Firefox have issues with the legal name, that's why the source is called by other names and the branding is added later on.
signal ties the branding with the code, so it is impossible to build from the canonical source without triggering the branding issue.
So, in practice, it is a convoluted way to annoy anyone releasing from source. And as we know, actually using open source software without a "distro" is insanity. You cannot trust 1000s devs. you trust the distro, the distro trust 10s of package maintainers, the package maintainers trust 10s of devs. and everyone is happy. I trust f-droid just fine. But i don't trust the person who is publishing every apk on random sites like signal.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#228Another thing that wasn't pointed out: Du Rove said "Signal messages have been exploited against them in US courts or media." This would be the same case for Telegram as well, if someone has your phone. I believe that Signal can have a lock on the client, and the database is encrypted. The other part that Du Rove conveniently left out: Signal went against the US courts and won [0]. When subpoenaed to give all user in…
Telegram has moved to Dubai long ago so no idea where you get the idea that FSB can strong-arm them from.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#229Telegram is just as bullshit as WhatsApp etc as long as it requires: * A phone number * Access to your contacts WHY do messaging apps need ALL our contacts? Why can't we add only the people we want to stay in touch with on a particular app? WHY doesn't Apple let us choose WHICH contents to let an app steal, just like we can with limited photos access?
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#230Earlier quoted context omitted.
https://eprint.iacr.org/2023/469.pdf
From your own link: > Recently, in [MV21 ] MTProto 2.0 (the current version) was proven secure in a symbolic model, but assuming ideal building blocks and abstracting away all implementation/primitive details. Translation: it is secure, except for bugs, if any.
It's like a clunkier version of the backdoor in Dual EC DRBG. When problems like this are found, you can either assume deliberate malice (as in the case of NIST) or accidental incompetence. Either should be immediate grounds for not using the software. This isn't Flappy Bird. This is meant to be secure comms. The "This Is Fine" mentality doesn't cut it.