Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

261–270 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#261
post #151

Earlier quoted context omitted.

Hm f-droid provides privacy friendly https://fdroid.gitlab.io/metrics/ for some time now. I'm not sure what sort of "control" they have over the Play Store compared to f-droid, but I'd rather have a trusted 3rd party do the building transparently and verifyable.

F-Droid uses a package maintainer-esque process where the maintainers of F-Droid can intervene and prevent an update to an app from reaching users if it's deemed to be malicious or to add anti-features. It's of particularly high need on mobile since popular apps, even those who were originally FOSS, are sold to scummy publishers who fill it with ads and subscription schemes (oft called anti-features, since removing t…

> where the maintainers of F-Droid can intervene and prevent an update to an app from reaching users if it's deemed to be malicious

That sounds like a feature you want when using FOSS.

Imagine distros wouldn't have been able to intervene quickly and malicious xz would be still deployed through their channels just because the authors want to.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#262

Earlier quoted context omitted.

Is it possible to link to primary or neutral secondary sources, rather than hatchet-jobs?

That’s what the underlined bits throughout are, including to Rufo’s own tweets. But here, primary: https://christopherrufo.com/p/the-zen-koans-of-npr > This week, I have been engaged in a campaign to expose NPR’s new CEO, Katherine Maher, and her anti-speech, anti-truth philosophy.

How does that show he wants to use Telegram in a "psy-op"?

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#263
There are multiple layers where interception can happen:

1) On-screen keyboard - by default most phones do send what is being typed - a lot of phones also have 3rd party keyboards of doubtful origin preinstalled

2) "Enable backup" scam - on starting an app (like Google Photos or WhatsApp) chances you or your wife accidentally press "ok" on a pop up message

3) Hardware drivers - non open source binary blobs with back doors

4) Operating system - you basically don't know what information is logged and sent back to phone's vendor

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#264
post #141
post #74

You can download Telegram and many forked clients from F-Droid. All the builds are from source code, so you know the source code is up-to-date. Any distro can have Telegram clients, both official and third-party, in their repository. Compared to this 1. You cannot download Signal from F-Droid. You need to download it from the Google Play Store. The released source code has lagged behind the version on the Google Play…

Does Telegram still use their own crypto algorithm? If so, up-to-date source code us pretty useless. How many people check their app's source code? With third party clients it's pretty easy to get malicious ones

[flagged]

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#265
post #75

Another thing that wasn't pointed out: Du Rove said "Signal messages have been exploited against them in US courts or media." This would be the same case for Telegram as well, if someone has your phone. I believe that Signal can have a lock on the client, and the database is encrypted. The other part that Du Rove conveniently left out: Signal went against the US courts and won [0]. When subpoenaed to give all user in…

Telegram has moved to Dubai long ago so no idea where you get the idea that FSB can strong-arm them from.

Hardy har har har. How quaint.

Guess you never heard of polonium either.

https://www.theguardian.com/world/2016/mar/06/alexander-litv...

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#266

So, who has actually launched "a pretty intense" campaign here? https://twitter.com/matthew_d_green/status/17883860908411619... https://twitter.com/evacide/status/1788040276331884593 https://twitter.com/naomibrockwell/status/178863495226900939... https://twitter.com/paulmillr/status/1788563576455610552 (I'm pretty sure the list goes on)

Yeah, the pro-encryption and pro-privacy people sure seem to be trying to tell us something about Telegram

Perhaps you're right, and all of them have the "greater good" intentions, but it's ridiculous how their "regular reminders" popped up in the same 24h interval

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#267

Earlier quoted context omitted.

Signal has got Usernames now. You can block number discovery. You can't resolve username to number. Your main account ID internally is not your number anymore. If 2 users add you using 2 different links or usernames. Its now harder to confirm its the same account.

I'm not sure what the behaviour is now but certainly the default a while back was that anytime someone in your contacts joined Signal you would get a message. Imo this was a crazy behaviour that immediately told you something about certain people in your contacts in a very visible way (that they were on Signal). I couldn't tell from the settings whether this was now off by default.

Telegram has done and may still (I don't know personally) do the exact same thing. Stated noncombatively and without assumption about what argument you may or may not be making, but seems relevant to mention in this context. Astonishingly bad behaviour no matter which app!

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#269
post #199

So, who has actually launched "a pretty intense" campaign here? https://twitter.com/matthew_d_green/status/17883860908411619... https://twitter.com/evacide/status/1788040276331884593 https://twitter.com/naomibrockwell/status/178863495226900939... https://twitter.com/paulmillr/status/1788563576455610552 (I'm pretty sure the list goes on)

this is honestly quite surprising... why are they so adamant? we know telegram is not super safe, but at least is not facebook.

My theory is - Telegram gained some extra traction after Carlson's interview

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#270
post #190

Earlier quoted context omitted.

Yes: https://telegram.org/blog/ultimate-privacy-topics-2-0

Without "SIM card" and "without a number" are different things. Apparently you still need a number, a "blockchain-powered" number: "[...] You can have a Telegram account without a SIM card and log in using blockchain-powered anonymous numbers available on the Fragment platform."

Irs super complicated to use. And you need an existing Telegram account to actually handle that cryptocurrency to buy these pseudo-numbers outside of the telephone namespace. Guess what you need to register those. An actual working phone number.
Post reply on HN