Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

321–330 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#322

Earlier quoted context omitted.

"You do make bear service here." I'm not sure what this means.

> The meaning of "bear's service" originally comes from a fable about a man and a bear. The bear wanted to help the man by killing a gnat which sat on his forehead. As a result both the gnat and the man died. Basically, by being proactive you do more damage as if you didn't do anything.

Replying to this, as I can't reply to your down-thread reply for some reason.

What if the gnat isn't a gnat? What if the gnat is another man who now knows the communications of the first man? I'm not saying the Bear should kill both, but I'm pointing out that the analogy falls apart when the gnat isn't just a mildly annoying third party.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#323
post #69

Earlier quoted context omitted.

What country do you live in?

Same In the EU, no ones that's legit uses Telegram, except scammers that you can run into in local "graigslist" website.

"Same in the EU" - but you're actually make an opposite statement than the GP (GP said "everyone i know uses telegram" and you said "nobody uses telegram")

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#324

Earlier quoted context omitted.

On Signal vs Telegram: Telegrams Encryption is off most of the time. They have serverside access to messages. The optional E2E is annoying to use and isnt even available on every platform. For example Tdesktop afaik still has no E2E support. (And has a very brittle software architecture.) You can't register Telegram accounts with the open source client anymore. This should be a non-Discussion. MG implying that just b…

You can buy "anonymous number" on fragment without using any client and without providing any personal information and use it as much as you can When signal becomes at least remotely as popular as telegram it will implement same protection to fight against spammers because you can't have free unrestricted registrations and don't drown in spam Telegram currently makes it as accessible as possible: either use it freely…

Signal is already extremely popular, their anti-spam by default is that you need to get matched to the user's local contact list or the spam becomes an allow/deny prompt. They also require a confirmed phone number and handle registration throttling.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#326
post #233

Earlier quoted context omitted.

Telegram rolled their own crypto and is used for a lot of intelligence operations like monitoring dissident groups, promoting propaganda, recruiting agents, etc. That probably explains the push to discredit more private apps like Signal. Researchers of Telegram's protocol have said in some ways it's weaker than TLS. E.g. - https://www.wired.com/story/the-kremlin-has-entered-the-chat... - https://therecord.media/teleg…

“Rolling your own crypto” is discouraged for programmers, not for field experts. It’s not your average joe’s first try at encryption writing a caesar cypher…

It's discouraged for field experts too. In practice, real crypto schemes go through several rounds of analysis by multiple teams of experts, often working against each other. It's unusual these days for a single company to come up with a custom crypto scheme. It was probably more usual toward the beginning of cryptography.

For example of this sort of vetting, take a look at the standardization around AES or the post-quantum schemes.

In crypto you're almost always relying on hardness assumptions that aren't provable yet. So you need to guard against things like accidentally haven chosen the wrong constants that collapse a problem's hardness. Or, more mundanely, making a seemingly reasonable engineering choice that is known to weaken the protocol and which would be caught by a big org with a thorough review, but a startup may not catch.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#327
post #305
post #75

Another thing that wasn't pointed out: Du Rove said "Signal messages have been exploited against them in US courts or media." This would be the same case for Telegram as well, if someone has your phone. I believe that Signal can have a lock on the client, and the database is encrypted. The other part that Du Rove conveniently left out: Signal went against the US courts and won [0]. When subpoenaed to give all user in…

The database is encrypted, and the password is right next to the database in a json file.

On desktop, on Android and iOS it uses the OS keystore. It really should do on desktop as well, Windows, Mac and Linux (through freedesktop standard) all have APIs for that, there really isn't much excuse. Desktop Signal has always had terrible security, unfortunately.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#328
post #192

Earlier quoted context omitted.

Here's the other side: https://news.ycombinator.com/item?id=40301508 https://news.ycombinator.com/item?id=40336005 https://news.ycombinator.com/item?id=40330694 https://news.ycombinator.com/item?id=40308241 https://news.ycombinator.com/item?id=40299313 https://news.ycombinator.com/item?id=40298608 https://news.ycombinator.com/item?id=40279661 https://twitter.com/jack/status/1787895769183268948 https://twitter.com/elo…

Are you pointing out that Mr. Durov is in conspiracy with... Jack Dorsey and Elon Musk?

In my opinion this has started as part of Rufo's campaign against Katherine Maher (see https://news.ycombinator.com/item?id=40341993), then Dorsey and Musk boosted that article because it aligns with their political views. Durov decided to add Telegram vs Signal angle in his post.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#329
post #154

Earlier quoted context omitted.

Telegram Foss clients exist only because of unpaid volunteers that take Telegrams messy mix of open and closed parts and rip closed parts out and replace them. The Telegram organisation is notoriously late to release the source code to their current release. If they do, its a giant squashed commit without proper changelog. These releases must then be first wrangled by volunteers to be well buildable. The Telegram Org…

This doesn't affect the user that downloads these from distro repos or F-Droid because every single update they get comes from the source code. There is never a lag even for 1 second because without the source code there are no builds. Pretty much all the packages on Linux repos come from package maintainers taking upstream source code, removing parts they don't like and then building that. This is a normal part of p…

I take it you haven't been following Telegram for iOS and macOS.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#330
post #228

Earlier quoted context omitted.

As I stated in a sister comment, Dubai is marginally better, but not significantly better. If it's the same original developers, they could be squeezed through their family.

Same goes for Signal devs, or any devs really. You're only stating the obvious: humans can be forced and coerced given enough motivation and resources. Singling out Telegram, or Signal, or any other service's devs is not advancing any argument forward.

There is more reason to be concerned about Telegram than most other similar services.

Partly because it’s insecure by default, which makes a large percentage of conversations vulnerable.

And also because the team behind it is very susceptible to pressure from the Russian government, which is especially bad when it comes to these things. Even if some of them are based out of Dubai now, it doesn’t mean that they aren’t still at risk of coercion, either directly or through for example threats against family members who remain in the country.

If you don’t trust Russia, which you shouldn’t, then don’t trust Telegram with anything sensitive.

Post reply on HN