Earlier quoted context omitted.
Yes: End-to-end encryption is technically quite difficult, but politically and legally feasible (at least currently, at least in most countries). Simply not cooperating with law enforcement is technically moderately difficult, but politically and legally impossible. Between a difficult and an impossible option, the rational decision is to pick the difficult one.
Is there a nice solution for multiparty (n >= 3) end-to-end encryption?
Is Telegram really an encrypted messaging app?
101–110 of 609 posts
Re: Is Telegram really an encrypted messaging app?
#102Earlier quoted context omitted.
[flagged]
I downvoted for whataboutism
I wish the downvote button would require at least a private message to the person of why they are being downvoted. (Upvote could have an optional message).
Otherwise it's the most toxic feature on HN as it promotes extreme groupthink activism.
Re: Is Telegram really an encrypted messaging app?
#103It’s not encrypted by default, and even if it were encrypted, you should never trust any connected device with anything important. That being said, Telegram is hands down the best communication platform right now. It is feature-rich, with features implemented years ago that are only now being added to other platforms. It has normal chatting/video calls, groups, channels, and unlimited storage in theory, all for free.…
Re: Is Telegram really an encrypted messaging app?
#104Earlier quoted context omitted.
Problem with this claim is that it's hardly verifiable. Telegram's backend is closed source, and the only thing you can be sure of is that their backend sees every message in plaintext.
[flagged]
Decentralized protocols have existed for a very long time. Email have existed since the 70s. Telephone is also arguably decentralized and have existed for even longer.
Re: Is Telegram really an encrypted messaging app?
#105Earlier quoted context omitted.
Yes: End-to-end encryption is technically quite difficult, but politically and legally feasible (at least currently, at least in most countries). Simply not cooperating with law enforcement is technically moderately difficult, but politically and legally impossible. Between a difficult and an impossible option, the rational decision is to pick the difficult one.
Is there a nice solution for multiparty (n >= 3) end-to-end encryption?
Re: Is Telegram really an encrypted messaging app?
#106Earlier quoted context omitted.
You can coherently argue that encryption doesn't matter, but you can't reasonably argue that Telegram is a serious encrypted messaging app (it's not an encrypted messaging app at all for group chats), which is the point of the article. The general attitude among practitioners in the field is: if you have to reason about how the operator will handle legal threats, you shouldn't bother reasoning about the messenger at…
[flagged]
This is incorrect. The construction for group chats in Telegram is not e2e at all. The construction for dm’s is considered dubious by many cryptographers.
It does not matter if you can reproduce a non-e2e encrypted message scheme, you must still trust the servers which you have no visibility on.
Trustworthy e2e is table stakes for this for that reason. Reproducible builds aren’t because we can evaluate a bunch of different builds collected in the wild and detect differences in implementation. This is the same thing we’d do if reproducible builds were in effect.
There are lots of reasons splitting jurisdictions makes sense but you wrote a whole bunch of words that fall back to “hope Telegram doesn’t change their protections in the face of governmental violence”.
Re: Is Telegram really an encrypted messaging app?
#107Earlier quoted context omitted.
Yes: End-to-end encryption is technically quite difficult, but politically and legally feasible (at least currently, at least in most countries). Simply not cooperating with law enforcement is technically moderately difficult, but politically and legally impossible. Between a difficult and an impossible option, the rational decision is to pick the difficult one.
Is there a nice solution for multiparty (n >= 3) end-to-end encryption?
Re: Is Telegram really an encrypted messaging app?
#108Earlier quoted context omitted.
Stealing someone's phone number wouldn't give you any Signal data, as all the messages have perfect forward secrecy, though, right? And all contacts would see an alert that your security number had changed. Not completely foolproof, and I would like Signal to use something other than phone numbers for accounts, but it's pretty good.
Knowing someone's phone number is enough to potentially compromise it. Sophisticated methods can involve zero-click attacks, where just sending you an SMS that you won’t even see can lead to a compromised device. You can check how Tucker got his Signal conversation exposed. Matrix is far better in terms of security than Signal, but Matrix is far behind compared to Telegram features.
Re: Is Telegram really an encrypted messaging app?
#109Earlier quoted context omitted.
You can coherently argue that encryption doesn't matter, but you can't reasonably argue that Telegram is a serious encrypted messaging app (it's not an encrypted messaging app at all for group chats), which is the point of the article. The general attitude among practitioners in the field is: if you have to reason about how the operator will handle legal threats, you shouldn't bother reasoning about the messenger at…
[flagged]
What does this mean? How can "we" move away from centralized states to "a free market of agencies"? How can there be a "market" of police forces, even in principle? Who are the customers in this imagined market? Who enforces the laws to keep it a free market?
At first glance, this sounds like libertarian fan fiction, to be honest, but I am curious.
Re: Is Telegram really an encrypted messaging app?
#110Earlier quoted context omitted.
Anecdotal evidence, so take this with a grain of salt - I work with a bunch of people from Ukraine and almost all of them exclusively use Telegram to keep up with the news and family back home. From talking to them for a while, it's mostly because it's free, has excellent support for sync across multiple devices (including audio, video and other media), has support for proxies to circumvent any kind of blocking, publ…
> doesn't require any personal identifier Do they still not require ID when you buy a SIM card in Ukraine?