Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

411–420 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#411

Earlier quoted context omitted.

Durov travels freely to and from Russia and several of their employees are still based in Russia. So yeah, the FSB have leverage if they need to use it.

You say it like it's a fact, so I assume you have proof? Durov is very vocal about being in exile so this looks doubtful.

That's the tune of every Russian oligarch that doesn't want to get caught up in a sanctions regime that makes their Paris/Milan shopping trips a pain.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#412
Not being in either Telegram/Signal camp I see a lot of tribalism in the comments. It seems that any arguments for/against either one end up in politics.

Like I understand that Telegram is probably not very secure, but seeing what proponents of Signal are saying doesn't really make me trust Signal either.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#413

Earlier quoted context omitted.

Of course. But the history of the Signal protocol and implementation traces back 20 years. It's good enough that Facebook, WhatsApp, and Skype use it for E2EE messages. Telegram's traces back 10 years, the first version was very bad, and both versions have had a lot of scrutiny for weird design decisions. Crypto schemes which get broken usually follow a pattern of "something smells wrong", "we have weakened it a litt…

> It's good enough that Facebook, WhatsApp, and Skype use it for E2EE messages. Wait if it's the same why don't we just use Facebook, WhatsApp and Skype instead of Signal?

It's only the protocol for their E2EE chats. There are two big caveats:

- Facebook and Skype E2EE messages are optional, and people rarely use that option, and - Those apps collect a huge amount of data outside the contents of the messages.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#414
post #409

Earlier quoted context omitted.

Are you saying this is a worse alternative to other communication methods with businesses? What would you use with them that has better encryption?

The lack of encryption between myself and a business is less offensive than replacing an open standard (plain old telephone systems, eMail) with a proprietary and closed one, backed by a single, private corporation

I don't think they've been replaced, though?

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#415

Earlier quoted context omitted.

On Signal vs Telegram: Telegrams Encryption is off most of the time. They have serverside access to messages. The optional E2E is annoying to use and isnt even available on every platform. For example Tdesktop afaik still has no E2E support. (And has a very brittle software architecture.) You can't register Telegram accounts with the open source client anymore. This should be a non-Discussion. MG implying that just b…

Both services are relatively insecure because they require phone authentication. In the EU at least the number can always be traced back to you if you don't buy specific burner phones. The level of encryption isn't as important anymore at that point. It is less probable you get into problems by using a service that doesn't know your identity.

> Both services are relatively insecure because they require phone authentication.

That hasn't been the case for Signal for some months: https://signal.org/blog/phone-number-privacy-usernames/

You still require a phone number for sign up for Signal, but your phone number isn't visible to anyone you chat with.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#416

Earlier quoted context omitted.

Of course. But the history of the Signal protocol and implementation traces back 20 years. It's good enough that Facebook, WhatsApp, and Skype use it for E2EE messages. Telegram's traces back 10 years, the first version was very bad, and both versions have had a lot of scrutiny for weird design decisions. Crypto schemes which get broken usually follow a pattern of "something smells wrong", "we have weakened it a litt…

> It's good enough that Facebook, WhatsApp, and Skype use it for E2EE messages. Wait if it's the same why don't we just use Facebook, WhatsApp and Skype instead of Signal?

Why don't you go to the local casino to chat with friends? They serve the same beer.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#417

Earlier quoted context omitted.

> It's good enough that Facebook, WhatsApp, and Skype use it for E2EE messages. Wait if it's the same why don't we just use Facebook, WhatsApp and Skype instead of Signal?

It's only the protocol for their E2EE chats. There are two big caveats: - Facebook and Skype E2EE messages are optional, and people rarely use that option, and - Those apps collect a huge amount of data outside the contents of the messages.

Still I think mentioning the greatest data collection projects in human history in the same sentence as Signal which is supposed to fight that is not very good.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#419
post #200

They want to do this because they want more traction for their blockchain: TRON, which, IIRC, is the payment method for ads, usernames and "stuff" inside Telegram. However Du Rove is right about a bunch of things: - Signal clients suck, specially the Desktop one where they ship (or used to) pre-built binaries like their own lib: https://github.com/signalapp/ringrtc - Also you can't have Signal without Google Play Sto…

ton and tron are not the same thing

ty. you're right

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#420

They want to do this because they want more traction for their blockchain: TRON, which, IIRC, is the payment method for ads, usernames and "stuff" inside Telegram. However Du Rove is right about a bunch of things: - Signal clients suck, specially the Desktop one where they ship (or used to) pre-built binaries like their own lib: https://github.com/signalapp/ringrtc - Also you can't have Signal without Google Play Sto…

> you can't have Signal without Google Play Store You can use Signal without the Play Store. Download the apk from Signal's website and it will use a background connection to receive calls and notifications. The downside is that it's heavier on the battery.

just that? then why not a f-droid release?
Post reply on HN