Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

431–440 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#431
Du Rove made the original post on May 8th 7:31, judge it yourself if it is 'pretty intense'.

Boast that end-to-end encryption is absolutely safe is obscurantism. If you want most security in transmission, share your GPG public keys face-to-face.

Du Rove made this post after the founder of Twitter forwarded an article about Signal. Instead of Elon Musk who has turned Twitter into a easy to surveillance platform. It was also Elon Musk who used to be very direct and later learned to be smart these days.

I strongly recommend reading the original post yourself first.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#432

Earlier quoted context omitted.

And that's good, that's their strength. I use it to read information from all sides of the conflict and decide for myself what's "disinformation" and what's not. A grown person doesn't need a gatekeeper that pushes their own interests and shuts up anyone daring to contradict them.

Oh yeah, "both sides". Sure... Wanna ask the two orphans living at my cousin's where their parents are and who killed them? How many thousands of such examples do you need? I'm sure as hell I can supply you with a sufficient amount, even worse than straight up shooting a child's parents in front of their eyes.

> Wanna ask the two orphans living at my cousin's where their parents are and who killed them?

Applying an emotional argument to shut up discussions against censorship is propaganda 101.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#433
post #409

Earlier quoted context omitted.

The lack of encryption between myself and a business is less offensive than replacing an open standard (plain old telephone systems, eMail) with a proprietary and closed one, backed by a single, private corporation

I don't think they've been replaced, though?

De jure or de facto?

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#434

Earlier quoted context omitted.

> Both services are relatively insecure because they require phone authentication. That hasn't been the case for Signal for some months: https://signal.org/blog/phone-number-privacy-usernames/ You still require a phone number for sign up for Signal, but your phone number isn't visible to anyone you chat with.

> but your phone number isn't visible to anyone you chat with. That's irrelevant - the phone number is known to Signal and can be request by law enforcement. And, since it's been made pretty much impossible to buy a SIM in the EU without showing identification [0], this will allow law enforcement to link the account to you. [0] IIRC the Netherlands is the only country left where you can buy SIMs without ID.

> That's irrelevant - the phone number is known to Signal and can be request by law enforcement.

Maybe I'm missing something here, but if usernames are treated as ephemeral, what's the threat model here?

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#435
post #402

Earlier quoted context omitted.

Sort of, but it's heavily peer reviewed and generally regarded as very good. I really dislike the "hand rolled is bad" meme. Someone rolled all crypto. The questions are "who is doing the rolling," "do they know what they are doing," and "was it peer reviewed or directly and faithfully built from a peer reviewed design?"

> I really dislike the "hand rolled is bad" meme. Crypto is notoriously easy to get wrong, even if you know a lot about it - and most people do not. Secondly, proving something secure is pretty hard as well. If the crypto isn't a bog-standard algorithm in a well-known and reviewed implementation, assuming it to be insecure is a pretty good rule of thumb.

My take on "don't roll your own" is:

The people who take this advice are people who have respect for the difficulty of things like crypto and should be the ones implementing it, or at least on-ramped into learning how to do so.

The sorts of people who ship bad crypto because they don't bother to learn anything about the field are going to ignore this advice.

So I think as a strategy for fighting bad crypto it's neutral or maybe even net-negative by discouraging the right people from learning crypto and having no effect on overconfident fools.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#436
post #58

This is a response to the following post from Telegram creator Durov https://t.me/durov/274

- "I don't like where one of their board worked" (find someone high up in the cryptography ecosystem who hasn't been involved in this sort of thing somewhere in their career) - "I don't like where their funding comes from" (US govt regularly funds secure software because they depend on it for their own operations, see: Tor) - "An alarming number of people think their chats were leaked". It's easy to state things with…

[dead]

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#437

Earlier quoted context omitted.

> because the FSB was demanding info from them But they gave the FSB info they asked for -- the vk.com website (facebook clone, at that time it had way more massive amounts of user data than telegram). They could have deleted the data, but no, they handed it over to FSB.

I will point out, in their defence, they handed it over to an organisation that has a habit of assisting people in learning how to fly from windows. This isn't to say Telegram is secure but that it's unlikely they "could have deleted the data" and remained alive.

FSB mostly wanted to prevent people organizing, and that would serve it well. They already had another popular service (odnoklassniki.ru) where to direct people.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#438

Earlier quoted context omitted.

> Both services are relatively insecure because they require phone authentication. That hasn't been the case for Signal for some months: https://signal.org/blog/phone-number-privacy-usernames/ You still require a phone number for sign up for Signal, but your phone number isn't visible to anyone you chat with.

> but your phone number isn't visible to anyone you chat with. That's irrelevant - the phone number is known to Signal and can be request by law enforcement. And, since it's been made pretty much impossible to buy a SIM in the EU without showing identification [0], this will allow law enforcement to link the account to you. [0] IIRC the Netherlands is the only country left where you can buy SIMs without ID.

> That's irrelevant - the phone number is known to Signal and can be request by law enforcement.

So how does this work? Law enforcement asks signal if they have an account for a phone number, signal saying "yes, here's when they created it".

Then what?

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#440
post #435

Earlier quoted context omitted.

> I really dislike the "hand rolled is bad" meme. Crypto is notoriously easy to get wrong, even if you know a lot about it - and most people do not. Secondly, proving something secure is pretty hard as well. If the crypto isn't a bog-standard algorithm in a well-known and reviewed implementation, assuming it to be insecure is a pretty good rule of thumb.

My take on "don't roll your own" is: The people who take this advice are people who have respect for the difficulty of things like crypto and should be the ones implementing it, or at least on-ramped into learning how to do so. The sorts of people who ship bad crypto because they don't bother to learn anything about the field are going to ignore this advice. So I think as a strategy for fighting bad crypto it's neutr…

> should be the ones implementing it

Someone (Bruce Schneier?) said that the best way to get into actually inventing/implementing crypto is to first get handy inventing attacks / hacking into other algorithms and tools.

Post reply on HN