Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

361–370 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#361

Earlier quoted context omitted.

You are speaking of metadata as if all metadata is equal. Signal does collect phone numbers (even though, since usernames have been introduced [1], this can be made opt in from now on), but not the contacts or social graph, neither many other relevant metadata [2]. What they can gather from this, is only when the specified phone number registered to signal services and its last connection to the server [3]. So, if yo…

>but not the contacts or social graph, neither many other relevant metadata [2]. Assuming you trust them (notice all your links point to signal.org own publications). Most of the privacy people are cautious/paranoid and assume that everything that can be collected is collected. Even assuming a lack of malicious intent, what's stopping NSA from hacking into Signal's infrastructure and logging who's talking to who alon…

> Even assuming a lack of malicious intent, what's stopping NSA from hacking into Signal's infrastructure and logging who's talking to who along with timestamps?

Sealed Sender, the second link in the comment you've replied to. The indicator is off by default, but you can enable it under Settings → Privacy → Advanced. If I remember correctly, it doesn't work for the very first message you exchange with someone, but then it turns on and remains on.

In layman terms, it turns "from A; to B; content: " into "to B; content: ". Their infrastructure doesn't need to know the "from" part to serve its purpose, so they strip it away.

If it was the other way around, they'd have to give that info to the (US) court. Same as any other US-based business, it's not optional, they can't ignore such requests, they can't lie, otherwise they'd be placing themselves in legal troubles for a random nobody that happens to be using their product. So, when I see this page, I fully believe them: https://signal.org/bigbrother/. If I didn't, my first step would be to look up those court cases from alternate sources.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#362
post #90

Telegram were claiming they were more secure even when they had their own home-rolled crypto. Security is not Telegram's strong point and it never was.

Why is MTProto considered "home-rolled" but the Signal Protocol isn't? Both are boutique and written from scratch to fit their respective systems.

Of course. But the history of the Signal protocol and implementation traces back 20 years. It's good enough that Facebook, WhatsApp, and Skype use it for E2EE messages. Telegram's traces back 10 years, the first version was very bad, and both versions have had a lot of scrutiny for weird design decisions.

Crypto schemes which get broken usually follow a pattern of "something smells wrong", "we have weakened it a little bit", "we have weakened it a little bit more", "this is now completely broken", "my god why are you still using MD5, it's 2017".

We're in the "something smells wrong" or "we have weakened it a little bit" phase for MTProto2, depending on how you view it.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#363
post #359
post #357

Earlier quoted context omitted.

I agree with you that Telegram does not even have E2EE and that's bad. But in this thread, GP was just talking about metadata. The goalpost here is metadata. GP particularly mentioned that Signal "fixed" the phone number issue and I just want to note that currently Signal isn't any better than Telegram in this aspect. And then you moved orange back.

> Telegram does not even have E2EE This is incorrect. Telegram has E2EE. https://core.telegram.org/api/end-to-end

I don't see how I can start an E2EE chat from my PC. If a feature only ever exists on phone it does not exist.

https://github.com/telegramdesktop/tdesktop/issues/871

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#364

Earlier quoted context omitted.

Telegram has moved to Dubai long ago so no idea where you get the idea that FSB can strong-arm them from.

Durov travels freely to and from Russia and several of their employees are still based in Russia. So yeah, the FSB have leverage if they need to use it.

You say it like it's a fact, so I assume you have proof? Durov is very vocal about being in exile so this looks doubtful.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#365
post #51

Telegram is full of scammers. Something something bricks and a glass house.

I've started getting a lot of spam scam messages on Signal as well lately. What's going on with these platforms?

Isn't it an expected issue with popular services, particularly ones with proper e2e encryption?

Things like WhatsApp and iMessage get scam messages too, and the less visibility the operators have for contents of messages the harder it is to proactively filter out spam.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#366

Earlier quoted context omitted.

That’s what the underlined bits throughout are, including to Rufo’s own tweets. But here, primary: https://christopherrufo.com/p/the-zen-koans-of-npr > This week, I have been engaged in a campaign to expose NPR’s new CEO, Katherine Maher, and her anti-speech, anti-truth philosophy.

How does that show he wants to use Telegram in a "psy-op"?

Signal was the last place she worked. https://christopherrufo.com/p/signals-katherine-maher-proble...

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#367

Earlier quoted context omitted.

> because the FSB was demanding info from them But they gave the FSB info they asked for -- the vk.com website (facebook clone, at that time it had way more massive amounts of user data than telegram). They could have deleted the data, but no, they handed it over to FSB.

vk.com and telegram have nothing in common, except the founder. Durov was forced to sell his part in the vk.com and telegram development started after that as a response.

> vk.com and telegram have nothing in common, except the founder.

This is a deeply funny sentence.

"Other than that, Mrs. Lincoln, how was the play?"

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#368

So since Signal has a board member who worked at a place that some people don't like then the Signal app must be backdoored/compromised/honeypot? That's one hell of a leap. How far has our requirement for evidence fallen?

AFAICT Signal is collateral damage in this disinformation campaign. The original attack seems to be aimed at the CEO of NPR, coming from an assortment of right wing (and some Russian-aligned) voices. She happens to also be on the board of Signal which, through the prism of conspiracy theory, now extends their crusade. Given that Telegram is commonly understood to be aligned with the Russian government, this maps neatly on the US/left vs Russia/right axis through which such people already understand the world.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#369
post #359
post #357

Earlier quoted context omitted.

I agree with you that Telegram does not even have E2EE and that's bad. But in this thread, GP was just talking about metadata. The goalpost here is metadata. GP particularly mentioned that Signal "fixed" the phone number issue and I just want to note that currently Signal isn't any better than Telegram in this aspect. And then you moved orange back.

> Telegram does not even have E2EE This is incorrect. Telegram has E2EE. https://core.telegram.org/api/end-to-end

...in secret chats, that are only available in 1-to-1 conversations via mobile apps.

So, not on by default (unlike Signal), no group chats (unlike Signal), no support at all in desktop apps (you've guessed it: unlike Signal).

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#370
Which big centralized messenger operator can be more trusted to run the SW they say they are running is always a contentious shifting argument. If you host your own or use a small hoster, these arguments about who might have been compromised or compelled are not relevant. Decentralized and federated protocols such as Simplex.chat, XMPP, Nextcloud Talk, Matrix, Session, and Delta Chat eliminate this concern.
Post reply on HN