Live data from Hacker News

Is Telegram really an encrypted messaging app?

blog.cryptographyengineering.com

161–170 of 609 posts

Re: Is Telegram really an encrypted messaging app?

#161

Thanks for the blog post, now I finally have a good resource I can point people to next time they claim Telegramm is secure. > I am not specifically calling out Telegram for this, since the same problem [with metadata] exists with virtually every other social media network and private messenger. Notably, Signal offers a feature called Sealed Sender[0]. While it doesn't solve the metadata problem entirely, it does at…

Sealed sender doesn't really solve the metadata problem at all:

* https://www.ndss-symposium.org/wp-content/uploads/ndss2021_1...

Generally you need something like TOR to hide who is talking to who.

Re: Is Telegram really an encrypted messaging app?

#162
post #153
post #133

Earlier quoted context omitted.

The technology has potential to be decentralized, but telephones were famously considered a "natural monopoly" and ended up centralized under Ma Bell. Government split Ma Bell into multiple smaller pieces, but they still operated as a cartel and kept prices high. They had centralized telephone switchboard operators etc. It is only when authors of decentralized file-sharing networks like Kazaa (who built them to get a…

> and earning some crypto You are not answering my main concern. Again, you snick in crypto into the discussion. Why? We have decentralized stuff. Email, xmpp, matrix, the fediverse, all this works without this web3/crypto stuff. Those things are not perfect, including their decentralized aspect (sometimes to the point of doubting that decentralization really works well, although I personally think decentralization i…

Because crypto is literally how entities on a decentralized network get paid in an autonomous network. It's not via cash transfers. It's not via bank transfers. Or having accounts in some central bank.

Look at FileCoin and IPFS, for instance. Once you automate the micropayments and proofs of spacetime, it becomes a cryptocurrency. And then the providers of services can sell it to the next consumers.

Just because you hear the word "crypto" doesn't mean it's automatically off-topic, when it's literally the thing that is inevitably used by decentralized systems to do proper accounting and reward the providers for providing any services. Without it, you'll still be sitting -- as you are -- with no viable alternatives to Twitter and Facebook.

Re: Is Telegram really an encrypted messaging app?

#163

Reads like a hit piece on Telegram from a crypto expert who couldn't be bothered to explain in more than one paragraph why the app he is calling not an encrypted app (according to how he personally thinks everyone refers to when talking about encryption) actually uses some encryption technology that he's not exactly sure of but suspects is insecure.

Double that. The entire article reads to me as handpicked and manipulative.

Re: Is Telegram really an encrypted messaging app?

#164

Try the mud puddle test: log into your account on a new device using the password recovery flow. Can you see your old messages? If the answer is yes then law enforcement can too. https://www.forbes.com/sites/anthonykosner/2012/08/05/how-se...

> If the answer is yes then law enforcement can too.

Is it technically possible for them to see it: yes

Does Telegram let them see it: I don't think so. That seems to be the core issue around Durov being arrested.

They probably should implement E2EE for everything. Then they will have a good excuse not to cooperate, because they simply don't have the data.

Re: Is Telegram really an encrypted messaging app?

#165

Earlier quoted context omitted.

But that's literally the entire point of this article. That is, in this day and age, when people talk about "secure messaging apps" they are usually implying end-to-end encryption, which Telegram most certainly is not for the vast majority of usages.

Also, iMessage is very secure...but then all your stuff is backed up on iCloud servers unless you specifically disable it. That includes all your iCloud encryption keys and plaintext messages. Worse, iPhones immediately start backing up to iCloud when set up for a new user - the only way to keep your network passwords and all manner of other stuff from hitting iCloud servers is to set the phone up with no network con…

Well summed-up. Its crazy how efficient theese things are at working together to strip users of any agency or control, across many different domains.

Re: Is Telegram really an encrypted messaging app?

#167

Only the secret chat is e2e encrypted. All the other chat options are not. I think calls are also not encrypted since they appear in the normal chat history not in the e2e chat. Obviously if your phone is compromised your e2ee chat is not safe.

> Obviously if your phone is compromised your e2ee chat is not safe.

Yes, and that's where the 'practical' argument pops up. With all the E2EE buzz, is it really helping in the scenarios where it's supposed to work the best?

This thread gives an overview on why Signal and other apps are not really practical: https://x.com/Pinboard/status/1474096410383421452

> The broader problem of ephemeral or spur of the moment protest activity leaving a permanent data trail that can be forensically analyzed and target individuals many years after the fact is unsolved and poses a serious risk to dissent. But E2E is not the solution to it.

> I feel like Moxie and a lot of end-to-end encryption purists fall into the same intellectual tarpit as the cryptocurrency people, which is that it should be possible to design technical systems that require zero trust, and that the benefits of these designs are self-evident

Re: Is Telegram really an encrypted messaging app?

#168

Earlier quoted context omitted.

But that's literally the entire point of this article. That is, in this day and age, when people talk about "secure messaging apps" they are usually implying end-to-end encryption, which Telegram most certainly is not for the vast majority of usages.

Also, iMessage is very secure...but then all your stuff is backed up on iCloud servers unless you specifically disable it. That includes all your iCloud encryption keys and plaintext messages. Worse, iPhones immediately start backing up to iCloud when set up for a new user - the only way to keep your network passwords and all manner of other stuff from hitting iCloud servers is to set the phone up with no network con…

iCLoud can be disabled by MDM profile installed by Apple Configurator at setup.

Re: Is Telegram really an encrypted messaging app?

#169
post #88

Earlier quoted context omitted.

> Is it simply that telegram is the only one without backdoors for five eyes? Do you honestly think that any backdoor would be used for such mundane crimes? Even more so, it being in any way acknowledged that there might be a backdoor? On that topic, it's highly likely Telegram is cooperating with Russian LE. Services and people that don't get thrown out quickly in Russia. > The arrest cites that he was not cooperati…

https://www.zdnet.com/article/russia-unbans-telegram/ and even eventually ended to become a major propaganda tool for the Russian army.

Would you say that it's possible that the answer to the article's question is:

- Telegram is not encrypted from Putin's perspective

- Telegram is encrypted from everyone else's perspective

Re: Is Telegram really an encrypted messaging app?

#170

Earlier quoted context omitted.

Well of course, but this is a feature of Telegram. It's the only messaging app where messages are stored on the cloud. This of course has security implications, but also allows you to have a big number of chats without wasting your device memory like WhatsApp does, or having to delete old conversations, and allows you to access your chats from any device. By the way you can also set a password to log in from another…

>It's the only messaging app where messages are stored on the cloud. So do all the others with the exception of something like IRC.

Not really. WhatsApp only keep them temporarily (and E2EE!) until they're delivered to each device. Signal too. Telegram keeps everything for all time. Which is kinda handy too I have to say.

Of course you can send your backup to Google for WhatsApp and signal but that's optional. You can keep it locally too. And it's encrypted too. With WhatsApp you can even choose to keep the key locally only.

Post reply on HN