Live data from Hacker News

Is Telegram really an encrypted messaging app?

blog.cryptographyengineering.com

241–250 of 609 posts

Re: Is Telegram really an encrypted messaging app?

#241

Earlier quoted context omitted.

> It's the only messaging app where messages are stored on the cloud. Besides Slack and Discord and Teams and whatever the heck Google has these days and iMessage and... I think you mean it's the only messaging app that purports to have a focus on security where messages are stored in the cloud, which is true, but also sus. There's a reason why none of the others are doing it that way, and Telegram isn't really claim…

Matrix also keeps your message on the server. Except you can run your own server. And the messages are end to end encrypted. And you can keep a proper backup of the keys. Granted it can be clunky at times, but the properties are there and decentralised end to end encrypted messaging is quite and incredible thing. (Yes, Matrix nerds, it's not messaging per se it's really state replication, I know :))

My Matrix messages are, I presume, not encrypted, because every device I have prompts me to sign this device's keys with the keys of another device (which doesn't exist) and the option to reset the encryption keys and lose access to old messages doesn't work either (it just crashes Element).

Re: Is Telegram really an encrypted messaging app?

#242

Earlier quoted context omitted.

> If the answer is yes then law enforcement can too. Is it technically possible for them to see it: yes Does Telegram let them see it: I don't think so. That seems to be the core issue around Durov being arrested. They probably should implement E2EE for everything. Then they will have a good excuse not to cooperate, because they simply don't have the data.

Telegram is the only messaging app that I know of which brought attention to the fact that your messages go through Google/Apple notification APIs, which seems like it would utterly defeat any privacy advantage offered by E2EE

This claim is what really makes me skeptical of Telegram's privacy story. Their assertion is completely incorrect. (Source: have implemented end to end encrypted payload delivery over APNs / GCM.)

And if they are so off base on this, they must either be incompetent or liars. Neither of which builds trust.

Re: Is Telegram really an encrypted messaging app?

#243

Earlier quoted context omitted.

> If the answer is yes then law enforcement can too. Is it technically possible for them to see it: yes Does Telegram let them see it: I don't think so. That seems to be the core issue around Durov being arrested. They probably should implement E2EE for everything. Then they will have a good excuse not to cooperate, because they simply don't have the data.

Telegram is the only messaging app that I know of which brought attention to the fact that your messages go through Google/Apple notification APIs, which seems like it would utterly defeat any privacy advantage offered by E2EE

And yet Telegram doesn't allow to have e2ee chats on a Linux desktop or phone. You must rely on Google/Apple.

Re: Is Telegram really an encrypted messaging app?

#244
post #8

Telegram offers end-to-end encryption in the same way that McDonalds offers salads.

yes. in that if you want it it's there, but nobody's forcing it on you if you just want a burger.

Oh, I must have missed this. Please tell me how to enable secret chats for groups. And my desktop chats. Also I'd like to turn on the setting for defaulting to secret chats whenever I open a new one. Oh? I can't. Sounds like it's not there if I want it, after all. Good thing they didn't force it to me though /s

Re: Is Telegram really an encrypted messaging app?

#245
post #135
post #99

Earlier quoted context omitted.

> if you have to reason about how the operator will handle legal threats, you shouldn't bother reasoning about the messenger at all. That's true. You need to run your own platform people. XMPP is plenty simple, plenty powerful, and plenty safe -- and even your metadata is in your control. Just self host. There's no excuse in 2024. Wake up people! Why should the arrest of someone else affect YOU?

"You need to run your own platform people." What problem does this solve? I'm someone who's been on the business end of a subpoena for a platform I ran, and narcing on my friends under threat of being held in contempt is perhaps the worst feeling I'm doomed to live with. "XMPP is ..." not the solution I'd recommend, even with something like OMEMO. Is it on by default? Can you force it to be turned on? The answer to b…

Note in particular that the Ethernet connection to xmpp.ru/jabber.ru's server was physically intercepted by German law enforcement (or whatever-you-think-they're-actually-enforcing enforcement), allowing them to issue fraudulent certificates through Let's Encrypt and snoop on all traffic. This was only noticed when the enforcement forgot to renew the certificate. https://news.ycombinator.com/item?id=37961166

Re: Is Telegram really an encrypted messaging app?

#246

Earlier quoted context omitted.

>It's the only messaging app where messages are stored on the cloud. So do all the others with the exception of something like IRC.

Not really. WhatsApp only keep them temporarily (and E2EE!) until they're delivered to each device. Signal too. Telegram keeps everything for all time. Which is kinda handy too I have to say. Of course you can send your backup to Google for WhatsApp and signal but that's optional. You can keep it locally too. And it's encrypted too. With WhatsApp you can even choose to keep the key locally only.

WhatsApp? The closed source app that AFAIK has never been externally audited, owned by one of the most privacy-disrespecting corporations in the world? You say I can trust it wholeheartedly as long as I don't upload backups to the cloud?

Re: Is Telegram really an encrypted messaging app?

#247
post #228

Earlier quoted context omitted.

defcon and blackhat are hacker/computer security conferences started by Jeff Moss (aka DT or Dark Tangent) in 1993 and held at the end of July or early August every year in Las Vegas.... The reason you don't bring your phone is it might get hacked

[dead]

For the lulz

Re: Is Telegram really an encrypted messaging app?

#248
post #174

Earlier quoted context omitted.

Also, iMessage is very secure...but then all your stuff is backed up on iCloud servers unless you specifically disable it. That includes all your iCloud encryption keys and plaintext messages. Worse, iPhones immediately start backing up to iCloud when set up for a new user - the only way to keep your network passwords and all manner of other stuff from hitting iCloud servers is to set the phone up with no network con…

That is the correct default. Every day users are far more likely to accidentally lose their data than to run into government snooping.

It might be the correct default, but it doesn't make it secure (makes it insecure actually).

Re: Is Telegram really an encrypted messaging app?

#249
post #162

Earlier quoted context omitted.

Because crypto is literally how entities on a decentralized network get paid in an autonomous network. It's not via cash transfers. It's not via bank transfers. Or having accounts in some central bank. Look at FileCoin and IPFS, for instance. Once you automate the micropayments and proofs of spacetime, it becomes a cryptocurrency. And then the providers of services can sell it to the next consumers. Just because you…

> it's literally the thing that is inevitably used by decentralized systems to do proper accounting and reward the providers for providing any services. Or just like, advertisement. ActivityPub, Matrix, PeerTube, NextCloud and Urbit are all fully decentralized and let any instance host monetize themselves however they want. Decentralized services, even for-profit ones, are not synonymous with cryptocurrency. Stop spr…

Urbit uses NFTs as IDs, which can be transferred

"Urbit IDs aren’t money, but they are scarce, so each one costs something. This means that when you meet a stranger on the Urbit network, they have some skin in the game and are less likely to be a bot or a spammer." https://urbit.org/overview

Who pays for the hosting of ActivityPub and Matrix instances?

What if one instance abuses other instances too much? How do you prevent it?

What if some spammer abuses Nexcloud? Oh, look at that, Nextcloud and Sia announce "cloud storage in the blockchain": https://nextcloud.com/blog/introducing-cloud-storage-in-the-...

Now we come to your ActivityPub stuff, including PeerTube. The question is, who pays for storage? What are the economics of storage?

I literally go into detail here: https://community.intercoin.app/t/who-pays-for-storage-nfts-...

I met the founders of LBRY / Odysee and other tokens that are actually being used for actual streaming. LBRY is a genuine utility token being used for instance.

You are totally ignoring the part that people need to get paid for storing stuff, and at the same time the payment needs to happen automatically.

Any other examples?

Re: Is Telegram really an encrypted messaging app?

#250

Earlier quoted context omitted.

Interesting, I feared Sealed Sender might be susceptible to statistical analysis (hence my phrasing "reduce it a bit") but it's worse than I expected ("Signal could link sealed sender users in as few as 5 message"). Thanks for the link! As for TOR, that wouldn't really help much, would it, given that the described attack is at the application level of Signal. Or are you talking about not using Signal altogether?

Yeah, I used TOR as a general example. Briar uses TOR for example to hide the connections between users.

Some other options

https://cwtch.im/ (has better UX and security than Briar) https://onionshare.org/ chat feature

Also https://github.com/maqp/tfc by yours truly if you need hardware-enforced endpoint security for your keys.

Post reply on HN