Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

231–240 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#232
post #75

Another thing that wasn't pointed out: Du Rove said "Signal messages have been exploited against them in US courts or media." This would be the same case for Telegram as well, if someone has your phone. I believe that Signal can have a lock on the client, and the database is encrypted. The other part that Du Rove conveniently left out: Signal went against the US courts and won [0]. When subpoenaed to give all user in…

"Winning" would mean not having to comply with the subpoena...

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#233
post #74

You can download Telegram and many forked clients from F-Droid. All the builds are from source code, so you know the source code is up-to-date. Any distro can have Telegram clients, both official and third-party, in their repository. Compared to this 1. You cannot download Signal from F-Droid. You need to download it from the Google Play Store. The released source code has lagged behind the version on the Google Play…

Telegram rolled their own crypto and is used for a lot of intelligence operations like monitoring dissident groups, promoting propaganda, recruiting agents, etc. That probably explains the push to discredit more private apps like Signal. Researchers of Telegram's protocol have said in some ways it's weaker than TLS. E.g. - https://www.wired.com/story/the-kremlin-has-entered-the-chat... - https://therecord.media/teleg…

“Rolling your own crypto” is discouraged for programmers, not for field experts. It’s not your average joe’s first try at encryption writing a caesar cypher…

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#234
post #103

Earlier quoted context omitted.

> Signal has launched support to use nicknames instead of phone numbers You will still need a phone number to sign up for Signal. Signal still knows your phone number, you just hide it from your contacts. To me this only makes it even more suspicious.

You need a phone number to sign up for Telegram as well. And you can correlate username to phone number not that hard in most standard setting cases.

Yeah, basically both super duper encrypted privacy oriented services want your phone number.

Sorry, but that's not privacy. I don't care what they do to encrypt your messages, they are still tied to me, which makes the super duper encryption pointless.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#235
> Telegram has launched a pretty intense campaign to malign Signal as insecure, with assistance from Elon Musk

I got a bit confused here! Didn't Musk support and encourage people to "Use Signal" three years ago?! https://twitter.com/elonmusk/status/1347165127036977153

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#236

As far as we can tell, they are both insecure: Telegram is closed source and Signal published their source but basically forces users to use the Google Play version which lags behind the OS version and you can never be 100% sure what it does, not to mention things like SGX.

What do you mean by SGX? SGX, even if it's fatally flawed, won't be worse than not using SGX. That's the worst case - they added a broken sandbox. Best case - they added a working one.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#237
post #151

Earlier quoted context omitted.

Hm f-droid provides privacy friendly https://fdroid.gitlab.io/metrics/ for some time now. I'm not sure what sort of "control" they have over the Play Store compared to f-droid, but I'd rather have a trusted 3rd party do the building transparently and verifyable.

Their problem is that F-Droid releases are signed by F-Droid, not by Signal. This way F-Droid could potentially insert a backdoor in an update.

That's not true tho. f-droid supports (true) https://f-droid.org/en/docs/Reproducible_Builds/ for quite some time now. Those are signed by both, f-droid and the author.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#238
post #205
post #157

Earlier quoted context omitted.

Your points have little to do with security (which is the main angle of Matthew Green's thread), especially because of reproducibility. Even then > You need to download it from the Google Play Store. Factually incorrect, just go to https://signal.org/android/apk/ (and the apk will then update itself) or build it yourself. > pushed the update to everyone but no one could inspect the source code. That was for the serve…

> Factually incorrect, just go to https://signal.org/android/apk/ (and the apk will then update itself) or build it yourself. That page tells me that the safest way is to have a Google account, with Google Play Services installed on my phone, and to download it from the Google Play Store. It then gives me an APK link after saying "Danger zone" and "most users should not do this". If the app developer tells me it's da…

> If the app developer tells me it's dangerous and I shouldn't do it, can you even expect users to do this?

If you care about reproducible builds and avoiding trusting Google, you're already in the class of not-most-users.

Signal seems to have usually taken a pragmatic stance of defaults mattering.

Afaicr, that was the argument for linking to phone numbers (it allowed for more lazy users to use it) and encryption by default (few turn on opt-in-encryption).

And it seems accurate to say 'for most users, who don't know what they're doing and don't want to play personal-IT-department, using the Google Play store is more safe and secure.'

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#239
post #205
post #157

Earlier quoted context omitted.

Your points have little to do with security (which is the main angle of Matthew Green's thread), especially because of reproducibility. Even then > You need to download it from the Google Play Store. Factually incorrect, just go to https://signal.org/android/apk/ (and the apk will then update itself) or build it yourself. > pushed the update to everyone but no one could inspect the source code. That was for the serve…

> Factually incorrect, just go to https://signal.org/android/apk/ (and the apk will then update itself) or build it yourself. That page tells me that the safest way is to have a Google account, with Google Play Services installed on my phone, and to download it from the Google Play Store. It then gives me an APK link after saying "Danger zone" and "most users should not do this". If the app developer tells me it's da…

You know what you're doing, so you can ignore those errors. Seems like a much better alternative to endorsement of apk downloads directly from websites for non tech-literate users.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#240

Earlier quoted context omitted.

"You do make bear service here." I'm not sure what this means.

> The meaning of "bear's service" originally comes from a fable about a man and a bear. The bear wanted to help the man by killing a gnat which sat on his forehead. As a result both the gnat and the man died. Basically, by being proactive you do more damage as if you didn't do anything.

Thanks for the explanation. I'll try to be less proactive, I guess...
Post reply on HN