Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

311–320 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#311

Earlier quoted context omitted.

Well... if you scrolled up a bit you would have found https://discuss.privacyguides.net/t/according-to-elon-musk-s... which says Signal isn't great either.

No, it does not. Let's enumerate the purported problems: - "Elon Musk said so", which does not matter. - Signal attachments can be viewed by an attacker with local access to the client . This is not Signal's job to protect against. - Signal offers an optional `--no-sandbox` flag which only has security options if enabled on Linux. - Weaknesses in sealed sender. This is the only one that might be an actual problem (tw…

>Given how the posted described the optional `--no-sandbox` flag as "no sandbox on Linux", it's clear that they don't understand anything they're sharing, and they just want to spread FUD.

Could you elaborate as you seem to be more "knowledgeable". This flag is clear at what it does and shouldn't be shipped into production. https://no-sandbox.io/

You can have a look where they specifically chose to force it https://github.com/signalapp/Signal-Desktop/commit/1ca0d8210...

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#312

> Telegram has launched a pretty intense campaign to malign Signal as insecure, with assistance from Elon Musk I got a bit confused here! Didn't Musk support and encourage people to "Use Signal" three years ago?! https://twitter.com/elonmusk/status/1347165127036977153

I was also initially confused. But then I remember that Musk is a jabroni and nothing he says should be taken at face value. Fuck him.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#313

Earlier quoted context omitted.

Telegram iirc moved it's lead developers to Dubai specifically because the FSB was demanding info from them, so you could argue that's an unfounded concern. The bigger problem with Telegram is that it by default has insecure encryption settings (as opposed to Signal, where encrypted is the default, you need to manually activate it with Telegram + I think it's not possible to enable for all chats and clients) and to m…

> Telegram iirc moved it's lead developers to Dubai specifically because the FSB was demanding info from them, so you could argue that's an unfounded concern. I'd argue it's not giving us any certainty. They could've moved away to escape. They could've moved away to a nice FSB-sponsored location while making good publicity. Ideally the tech should be good enough for this issue to not matter.

To add to this: and they may have hired a FSB agent without knowing it.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#314

It seems like a twitter thread of multiple messages. How can I read the rest of the messages, not just /1? There's no links to them.

Found the answer to my question in comments here: https://nitter.poast.org/matthew_d_green/status/178968789886...

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#315

I don't know about Telegram being nasty towards Signal but Signal brought this upon themselves. Metadata are more important than the content of the messages and yet Signal has always been about knowing your phone number, with handwaving when the subject is mentioned. Sessions, a Signal fork, had its tagline right: "Share encrypted messages, not metadata" . Signal is a metadata exchanging app and it's about collecting…

You are speaking of metadata as if all metadata is equal. Signal does collect phone numbers (even though, since usernames have been introduced [1], this can be made opt in from now on), but not the contacts or social graph, neither many other relevant metadata [2]. What they can gather from this, is only when the specified phone number registered to signal services and its last connection to the server [3]. So, if yo…

>but not the contacts or social graph, neither many other relevant metadata [2].

Assuming you trust them (notice all your links point to signal.org own publications). Most of the privacy people are cautious/paranoid and assume that everything that can be collected is collected. Even assuming a lack of malicious intent, what's stopping NSA from hacking into Signal's infrastructure and logging who's talking to who along with timestamps? That's not to say I don't trust signal (it's the best mainstream solution right now), but it could do better to hide metadata from the protocol.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#316
post #253

Earlier quoted context omitted.

Ah yes, Dubai the bastion of integrity, equality and human rights.

True, they aren't. Whether they're friends with Russia is another thing though.

They don't have to be friends to turn a blind eye.

If Dubai had to pick between letting some nobody foreign national living on their soil get squeezed by a foreign secret police, or pissing off the Russians, what do you think they would do?

(This isn't a knock on Dubai specifically, substitute them for almost any non-NATO country in the world).

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#317

Earlier quoted context omitted.

I'm not sure what the behaviour is now but certainly the default a while back was that anytime someone in your contacts joined Signal you would get a message. Imo this was a crazy behaviour that immediately told you something about certain people in your contacts in a very visible way (that they were on Signal). I couldn't tell from the settings whether this was now off by default.

Telegram has done and may still (I don't know personally) do the exact same thing. Stated noncombatively and without assumption about what argument you may or may not be making, but seems relevant to mention in this context. Astonishingly bad behaviour no matter which app!

Both do that.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#318
post #228

Earlier quoted context omitted.

As I stated in a sister comment, Dubai is marginally better, but not significantly better. If it's the same original developers, they could be squeezed through their family.

Same goes for Signal devs, or any devs really. You're only stating the obvious: humans can be forced and coerced given enough motivation and resources. Singling out Telegram, or Signal, or any other service's devs is not advancing any argument forward.

No, telegram is especially concerning given how insecure it is by default.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#319

Earlier quoted context omitted.

On Signal vs Telegram: Telegrams Encryption is off most of the time. They have serverside access to messages. The optional E2E is annoying to use and isnt even available on every platform. For example Tdesktop afaik still has no E2E support. (And has a very brittle software architecture.) You can't register Telegram accounts with the open source client anymore. This should be a non-Discussion. MG implying that just b…

You can buy "anonymous number" on fragment without using any client and without providing any personal information and use it as much as you can When signal becomes at least remotely as popular as telegram it will implement same protection to fight against spammers because you can't have free unrestricted registrations and don't drown in spam Telegram currently makes it as accessible as possible: either use it freely…

I just looked at the fragment.com site to see how much such a number costs. The lowest possible bid you can currently make, and that is for an auction that has six days to go, so probably not even the final price, is over 100$. That is an unacceptable price for basic privacy.
Post reply on HN