[flagged]
Telegram has launched a pretty intense campaign to malign Signal as insecure
231–240 of 501 posts
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#232Another thing that wasn't pointed out: Du Rove said "Signal messages have been exploited against them in US courts or media." This would be the same case for Telegram as well, if someone has your phone. I believe that Signal can have a lock on the client, and the database is encrypted. The other part that Du Rove conveniently left out: Signal went against the US courts and won [0]. When subpoenaed to give all user in…
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#233You can download Telegram and many forked clients from F-Droid. All the builds are from source code, so you know the source code is up-to-date. Any distro can have Telegram clients, both official and third-party, in their repository. Compared to this 1. You cannot download Signal from F-Droid. You need to download it from the Google Play Store. The released source code has lagged behind the version on the Google Play…
Telegram rolled their own crypto and is used for a lot of intelligence operations like monitoring dissident groups, promoting propaganda, recruiting agents, etc. That probably explains the push to discredit more private apps like Signal. Researchers of Telegram's protocol have said in some ways it's weaker than TLS. E.g. - https://www.wired.com/story/the-kremlin-has-entered-the-chat... - https://therecord.media/teleg…
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#234Earlier quoted context omitted.
> Signal has launched support to use nicknames instead of phone numbers You will still need a phone number to sign up for Signal. Signal still knows your phone number, you just hide it from your contacts. To me this only makes it even more suspicious.
You need a phone number to sign up for Telegram as well. And you can correlate username to phone number not that hard in most standard setting cases.
Sorry, but that's not privacy. I don't care what they do to encrypt your messages, they are still tied to me, which makes the super duper encryption pointless.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#235I got a bit confused here! Didn't Musk support and encourage people to "Use Signal" three years ago?! https://twitter.com/elonmusk/status/1347165127036977153
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#236As far as we can tell, they are both insecure: Telegram is closed source and Signal published their source but basically forces users to use the Google Play version which lags behind the OS version and you can never be 100% sure what it does, not to mention things like SGX.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#237Earlier quoted context omitted.
Hm f-droid provides privacy friendly https://fdroid.gitlab.io/metrics/ for some time now. I'm not sure what sort of "control" they have over the Play Store compared to f-droid, but I'd rather have a trusted 3rd party do the building transparently and verifyable.
Their problem is that F-Droid releases are signed by F-Droid, not by Signal. This way F-Droid could potentially insert a backdoor in an update.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#238Earlier quoted context omitted.
Your points have little to do with security (which is the main angle of Matthew Green's thread), especially because of reproducibility. Even then > You need to download it from the Google Play Store. Factually incorrect, just go to https://signal.org/android/apk/ (and the apk will then update itself) or build it yourself. > pushed the update to everyone but no one could inspect the source code. That was for the serve…
> Factually incorrect, just go to https://signal.org/android/apk/ (and the apk will then update itself) or build it yourself. That page tells me that the safest way is to have a Google account, with Google Play Services installed on my phone, and to download it from the Google Play Store. It then gives me an APK link after saying "Danger zone" and "most users should not do this". If the app developer tells me it's da…
If you care about reproducible builds and avoiding trusting Google, you're already in the class of not-most-users.
Signal seems to have usually taken a pragmatic stance of defaults mattering.
Afaicr, that was the argument for linking to phone numbers (it allowed for more lazy users to use it) and encryption by default (few turn on opt-in-encryption).
And it seems accurate to say 'for most users, who don't know what they're doing and don't want to play personal-IT-department, using the Google Play store is more safe and secure.'
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#239Earlier quoted context omitted.
Your points have little to do with security (which is the main angle of Matthew Green's thread), especially because of reproducibility. Even then > You need to download it from the Google Play Store. Factually incorrect, just go to https://signal.org/android/apk/ (and the apk will then update itself) or build it yourself. > pushed the update to everyone but no one could inspect the source code. That was for the serve…
> Factually incorrect, just go to https://signal.org/android/apk/ (and the apk will then update itself) or build it yourself. That page tells me that the safest way is to have a Google account, with Google Play Services installed on my phone, and to download it from the Google Play Store. It then gives me an APK link after saying "Danger zone" and "most users should not do this". If the app developer tells me it's da…
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#240Earlier quoted context omitted.
"You do make bear service here." I'm not sure what this means.
> The meaning of "bear's service" originally comes from a fable about a man and a bear. The bear wanted to help the man by killing a gnat which sat on his forehead. As a result both the gnat and the man died. Basically, by being proactive you do more damage as if you didn't do anything.