Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

461–470 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#461

There are multiple layers where interception can happen: 1) On-screen keyboard - by default most phones do send what is being typed - a lot of phones also have 3rd party keyboards of doubtful origin preinstalled 2) "Enable backup" scam - on starting an app (like Google Photos or WhatsApp) chances you or your wife accidentally press "ok" on a pop up message 3) Hardware drivers - non open source binary blobs with back…

>by default most phones do send what is being typed That's extraordinary if true. Do you have anything to back it up, though? Even Google (!) wasn't brazen enough to log everything typed on Gboard, they implemented federated learning.

I wouldn't say "most phones", but perhaps most of them in China:

https://www.technologyreview.com/2024/04/24/1091740/chinese-...

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#462

Earlier quoted context omitted.

Telegram has moved to Dubai long ago so no idea where you get the idea that FSB can strong-arm them from.

Hardy har har har. How quaint. Guess you never heard of polonium either. https://www.theguardian.com/world/2016/mar/06/alexander-litv...

Much more recently using Novichok: https://en.wikipedia.org/wiki/Poisoning_of_Sergei_and_Yulia_...

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#463
I really like Telegram from a UI/UX standpoint (so much better than Signal), but Pavel Durov is such a sketchy character that it's starting to turn me off. How can he be touting about being secure when they still haven't implemented end-to-end encryption by default? Also so many other things if you follow Durov's channel.

(I use Telegram and Signal each for about 45% of my messaging, even though I'm in Europe where WhatsApp is so prevalent.)

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#464

Telegram is just as bullshit as WhatsApp etc as long as it requires: * A phone number * Access to your contacts WHY do messaging apps need ALL our contacts? Why can't we add only the people we want to stay in touch with on a particular app? WHY doesn't Apple let us choose WHICH contents to let an app steal, just like we can with limited photos access?

GrapheneOS allows you to do this. The downside is that it only runs on Pixel phones.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#465
post #75

Another thing that wasn't pointed out: Du Rove said "Signal messages have been exploited against them in US courts or media." This would be the same case for Telegram as well, if someone has your phone. I believe that Signal can have a lock on the client, and the database is encrypted. The other part that Du Rove conveniently left out: Signal went against the US courts and won [0]. When subpoenaed to give all user in…

> they gave them all that had: the unix timestamp of when the account was created, and the last date you connected to the signal service.

I'm confused. Signal also has your phone number because they require it, that's the primary privacy criticism against Signal.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#466

Earlier quoted context omitted.

Both services are relatively insecure because they require phone authentication. In the EU at least the number can always be traced back to you if you don't buy specific burner phones. The level of encryption isn't as important anymore at that point. It is less probable you get into problems by using a service that doesn't know your identity.

> Both services are relatively insecure because they require phone authentication. That hasn't been the case for Signal for some months: https://signal.org/blog/phone-number-privacy-usernames/ You still require a phone number for sign up for Signal, but your phone number isn't visible to anyone you chat with.

> That hasn't been the case for Signal for some months

Wrong. Because:

> You still require a phone number for sign up for Signal

So, they have your phone number. What is displayed is irrelevant.

If they have your phone number (which they do), they will have to disclose it for any subpoena/NSL, so they do.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#467
post #151

Earlier quoted context omitted.

Hm f-droid provides privacy friendly https://fdroid.gitlab.io/metrics/ for some time now. I'm not sure what sort of "control" they have over the Play Store compared to f-droid, but I'd rather have a trusted 3rd party do the building transparently and verifyable.

Their problem is that F-Droid releases are signed by F-Droid, not by Signal. This way F-Droid could potentially insert a backdoor in an update.

> This way F-Droid could potentially insert a backdoor in an update.

Google requires app developers on play store to give goole the keys that enable google to insert backdoors in any release. I can't trust anything on the play store for this reason. There is no way to tell which apps have been backdoored by google for whatever reason (the usual reason is a NSL).

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#468

Earlier quoted context omitted.

i completely agree with your sentiment, but i will also say this. As an expat, this feature has enabled me to transact with locals from the convenience of my phone, even though i don't have any local line and i will not bother to get a local SIM card, nor do i want to have a US SIM and a local one interchangeably. It also enables me to be very effective when requesting services on demand, and cutting thru the on-hold…

All of that can be achieved in the same way via email.

All of that can also be achieved by pigeon post.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#469

Earlier quoted context omitted.

Both Russians and Ukrainians use Telegram, including confidential messaging with their agents on the foreign territory. So that's a prove enough for me, that it's safe enough.

Which bits of this war scream “good judgement and opsec” to you? https://www.nytimes.com/2023/01/04/world/europe/ukraine-russ... > Ukrainian artillery targets Russian soldiers by pinpointing their phone signals. Despite the deadly results, Russian troops keep defying a ban on cellphone use near the front.

It's not about ordinary soldiers. It's about special services agents contacting their "partisans" agents, while other side special services trying to catch them. They're supposed to apply best security possible in the given circumstances.

If you claim that neither Russian, nor Ukrainian special services are competent, I'd disagree with you.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#470

Not being in either Telegram/Signal camp I see a lot of tribalism in the comments. It seems that any arguments for/against either one end up in politics. Like I understand that Telegram is probably not very secure, but seeing what proponents of Signal are saying doesn't really make me trust Signal either.

It is political . As I mentioned elsewhere in HN, Telegram is now being promoted in the US by the political-right there because they have lost trust in US BigTech social media platforms who, they believe, are "unjustly" censoring them on their platform. That is why the right-leaning media are now heavily promoting Telegram ( https://www.youtube.com/watch?v=1Ut6RouSs0w ) and bashing other platforms ( https://www.city-…

You mean the BigTech social media platforms that use Signal's protocol for messaging ? Wow I wonder why the people who don't trust BigTech social media don't choose Signal that is actually insane.

If it is indeed political don't try to bring some kind of technological merit into this, it makes you look really dishonest.

Post reply on HN