So, who has actually launched "a pretty intense" campaign here? https://twitter.com/matthew_d_green/status/17883860908411619... https://twitter.com/evacide/status/1788040276331884593 https://twitter.com/naomibrockwell/status/178863495226900939... https://twitter.com/paulmillr/status/1788563576455610552 (I'm pretty sure the list goes on)
Yeah, the pro-encryption and pro-privacy people sure seem to be trying to tell us something about Telegram
Telegram has launched a pretty intense campaign to malign Signal as insecure
351–360 of 501 posts
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#352So, who has actually launched "a pretty intense" campaign here? https://twitter.com/matthew_d_green/status/17883860908411619... https://twitter.com/evacide/status/1788040276331884593 https://twitter.com/naomibrockwell/status/178863495226900939... https://twitter.com/paulmillr/status/1788563576455610552 (I'm pretty sure the list goes on)
This seems organic to me. I was a security researcher, and for years I've been telling anyone who would listen that Telegram is not as secure as their marketing says it is, while Signal is. The reasons why are already pretty well listed in the thread above. Telegram's E2EE is hand-rolled and not the default. Signal's E2EE is always on, and it's _the_ industry standard protocol. (Outside of iMessage, I believe the Sig…
But you can, under Privacy & Security, switch Phone number visibility to "nobody". You can also change your username anytime you want to. A new feature called "anonymous numbers" allows you to purchase and use virtual numbers (they start with +888).
I think the bigger problem here is that Telegram has not e2e encryption enabled by default, which is definitely suspect.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#353Earlier quoted context omitted.
>Given how the posted described the optional `--no-sandbox` flag as "no sandbox on Linux", it's clear that they don't understand anything they're sharing, and they just want to spread FUD. Could you elaborate as you seem to be more "knowledgeable". This flag is clear at what it does and shouldn't be shipped into production. https://no-sandbox.io/ You can have a look where they specifically chose to force it https://g…
You're right. It seems I am eating my words on that item, the `--no-sandbox` flag does seem to be on in most Linux installs. From context and search, it looks necessary for it to work on Debian. Can confirm with `cat /usr/share/applications/signal-desktop.desktop`. This still would require a pretty sophisticated attack to take advantage of, but I wouldn't rule it out as an attack surface. (We regularly see iPhone exp…
There's an issue open to provide a flatpak for the app.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#354Earlier quoted context omitted.
Telegram iirc moved it's lead developers to Dubai specifically because the FSB was demanding info from them, so you could argue that's an unfounded concern. The bigger problem with Telegram is that it by default has insecure encryption settings (as opposed to Signal, where encrypted is the default, you need to manually activate it with Telegram + I think it's not possible to enable for all chats and clients) and to m…
> because the FSB was demanding info from them But they gave the FSB info they asked for -- the vk.com website (facebook clone, at that time it had way more massive amounts of user data than telegram). They could have deleted the data, but no, they handed it over to FSB.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#3552. Conduct an astroturfed campaign for Signal
3. ???
4. Crypto profits!
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#356Earlier quoted context omitted.
Which bits of this war scream “good judgement and opsec” to you? https://www.nytimes.com/2023/01/04/world/europe/ukraine-russ... > Ukrainian artillery targets Russian soldiers by pinpointing their phone signals. Despite the deadly results, Russian troops keep defying a ban on cellphone use near the front.
The part where they make up stories about the other side doing dumb shit in order to boost/maintain their team's morale. It's especially critical to drip-feed feel good news when you losing.
> “It is already clear that the main reason of what took place included the massive use, contrary to the ban, of personal mobile phones in the range of enemy weapons,” the Russian Defense Ministry said in a statement. The cellphone data allowed Ukraine, it said, to “determine the coordinates of the location of military service members to inflict a rocket strike.”
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#357Earlier quoted context omitted.
Yeah, basically both super duper encrypted privacy oriented services want your phone number. Sorry, but that's not privacy. I don't care what they do to encrypt your messages, they are still tied to me, which makes the super duper encryption pointless.
You compare apples with oranges. Because if you'd compare the apples , you'd notice one of them has no usable E2E. Yes oranges umm phone numbers is a problem. They have that both. Only one can additionally read the contents. Thats for now the price for a normie interface. First goalposts first.
But in this thread, GP was just talking about metadata. The goalpost here is metadata. GP particularly mentioned that Signal "fixed" the phone number issue and I just want to note that currently Signal isn't any better than Telegram in this aspect.
And then you moved orange back.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#358Earlier quoted context omitted.
Facebook actually has had optional E2EE with the Signal protocol since at least 2016 (in my experience), as "secret chats". This puts it on a better security standing than Telegram.
Telegram has a similar feature I believe.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#359Earlier quoted context omitted.
You compare apples with oranges. Because if you'd compare the apples , you'd notice one of them has no usable E2E. Yes oranges umm phone numbers is a problem. They have that both. Only one can additionally read the contents. Thats for now the price for a normie interface. First goalposts first.
I agree with you that Telegram does not even have E2EE and that's bad. But in this thread, GP was just talking about metadata. The goalpost here is metadata. GP particularly mentioned that Signal "fixed" the phone number issue and I just want to note that currently Signal isn't any better than Telegram in this aspect. And then you moved orange back.
This is incorrect. Telegram has E2EE.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#360Earlier quoted context omitted.
Telegram has moved to Dubai long ago so no idea where you get the idea that FSB can strong-arm them from.
Did you hear about a russian pilot who defected to Ukraine and then was killed in Spain? https://www.nytimes.com/2024/02/20/world/europe/russian-pilo... If russia wants to find and kill you they will.
If whatever State/Government wants to find and kill you they will.