Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

391–400 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#391
post #51

Telegram is full of scammers. Something something bricks and a glass house.

I've started getting a lot of spam scam messages on Signal as well lately. What's going on with these platforms?

It feels like any platform that allows for one-way initiation of a conversation is bound to increase in spam as the platform grows in usage (phone calls, email, SMS, various social media, various messengers, etc.).

Do any platforms require that both parties add one another? (And/or allow for restricting an account to such a mode)

e.g. if user123 and user789 wish to communicate, then user123 must add/contact user789 AND user789 must add/contact user123. Until both do so, then nothing happens.

It's more work to legitimately establish contact with someone, but that seems like it pales in comparison to the effort produced by spam/scams.

Same thing with verifying identities. In order to actually establish proper contact with someone, you need to communicate with them via some outside means (ideally in person) in order to establish the connection. Requiring both parties to enter/scan some ID/code/whatever seems like it would only facilitate proper verification (though not guarantee it, of course).

I'm sure that I'm missing something, though. I assume I'm just not familiar enough with these platforms and that some/all of them provide such a feature. It's just odd to me that spam sounds like such a problem when it feels like the above solution would be highly effective and simple to include.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#392

Earlier quoted context omitted.

Perhaps you're right, and all of them have the "greater good" intentions, but it's ridiculous how their "regular reminders" popped up in the same 24h interval

> have the "greater good" intentions, It's getting harder and harder to tell because bot activity has gotten so good, but Matthew Green has been around a while and is a genuine old school crypto dude. There is a group of people who just believes that crypto and privacy are good things and want to promote them. The reason it gets harder is because you can spin up a handful of "expert" accounts shilling for this or tha…

> There is a group of people who just believes that crypto and privacy are good things and want to promote them.

Doesn't mean one can't become a sellout eventually.

Especially in Green's particular case - he had invested a lot of attention to Margaret Salter, e.g. https://twitter.com/matthew_d_green/status/13578907313697095...

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#394

Go on, keep defending the overlord you believe have your best interests at heart while the other 57 of us go worry-free, using Matrix or XMPP.

You will eventually revise your opinion once you find your chat logs 20 years later in some randomly occuring IRC logs because that one guy was using an IRC bridge. You cannot critique missing guaranteed end to end encryption when effectively matrix cannot guarantee it either.

If one guy gets their device compromised or decides to publish the contents of a conversation, is it that a problem of E2E? Of course not.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#395
post #90

Telegram were claiming they were more secure even when they had their own home-rolled crypto. Security is not Telegram's strong point and it never was.

Why is home-rolled crypto inherently insecure?

We explain this under the heading "A Somewhat Opinionated Discussion" here: https://mtpsym.github.io/ which is our security analysis of MTProto's symmetric cryptography.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#396
post #9

https://nitter.poast.org/matthew_d_green/status/178968789886...

On Signal vs Telegram: Telegrams Encryption is off most of the time. They have serverside access to messages. The optional E2E is annoying to use and isnt even available on every platform. For example Tdesktop afaik still has no E2E support. (And has a very brittle software architecture.) You can't register Telegram accounts with the open source client anymore. This should be a non-Discussion. MG implying that just b…

Both services are relatively insecure because they require phone authentication. In the EU at least the number can always be traced back to you if you don't buy specific burner phones.

The level of encryption isn't as important anymore at that point. It is less probable you get into problems by using a service that doesn't know your identity.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#397

Earlier quoted context omitted.

Why is home-rolled crypto inherently insecure?

In the case of Telegram, MTProto’s implementation leaves a lot to be desired[1][2]. Additionally, home rolled crypto does not usually get the kind of security review from the cryptography community which makes it very likely that bugs of all kinds exist. [1] https://words.filippo.io/dispatches/telegram-ecdh/ [2] http://unhandledexpression.com/2013/12/17/telegram-stand-bac...

Telegram's symmetric cryptography has been reviewed by cryptographers: https://mtpsym.github.io/

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#398
post #90

Telegram were claiming they were more secure even when they had their own home-rolled crypto. Security is not Telegram's strong point and it never was.

Technically Signal is using their own home-rolled crypto, too – right?

Telegram had some weird primitives which they said we should trust because they were made by their top team of mathematicians. Signal builds on widely used crypto primitives even if their protocol is their own (vetted by actual cryptographers though)

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#399
post #259

Earlier quoted context omitted.

> I'd personally argue that's a security dark pattern - make privacy a big selling point, but then don't activate the security by default I think it's a great approach instead: the secure, end to end encryption is there and it's ready to be used. You can easily activated it but you aren't burdened by it for 99% of the time when e2e encryption is not needed.

> You can easily activated it but you aren't burdened by it for 99% of the time when e2e encryption is not needed. So, in those 1% of the cases when you actually need it, you're instantly flagging yourself as doing something fishy? Because if it ever comes down to it, good luck proving otherwise in a court. That's like the whole point of why it should be on by default. Not because me making dinner plans is something…

Yes. Additionally you are at bare minimum signalling that the metadata of the encrypted comms is worth further analysis.

For exactly the same reason if you have a paper shredder, you don't only shred confidential material, you shred a bunch of junk as well to make it harder to find which pieces to reconstruct.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#400

Earlier quoted context omitted.

There is more reason to be concerned about Telegram than most other similar services. Partly because it’s insecure by default, which makes a large percentage of conversations vulnerable. And also because the team behind it is very susceptible to pressure from the Russian government, which is especially bad when it comes to these things. Even if some of them are based out of Dubai now, it doesn’t mean that they aren’t…

Whom should we trust then? Have we already forgotten about Snowden?

Can we trust some more than others without trusting anyone completely?

I for one trust that there are more Americans who would say no to the NSA when they have a legal basis for doing so than there are Russians saying no to the FSB.

The state of the rule of law is certainly not great anywhere in the world right now. But it's far worse in some places than in others. The difference still matters to some degree.

Post reply on HN