Live data from Hacker News

Is Telegram really an encrypted messaging app?

blog.cryptographyengineering.com

261–270 of 609 posts

Re: Is Telegram really an encrypted messaging app?

#261
>One of the biggest privacy problems in messaging is the availability of loads of meta-data — essentially data about who uses the service, who they talk to, and when they do that talking.

>I am not specifically calling out Telegram for this, since the same problem exists with virtually every other social media network and private messenger.

In fact, https://simplex.chat/ is the only messenger with the least amount of metadata.

Re: Is Telegram really an encrypted messaging app?

#262
post #249

Earlier quoted context omitted.

> it's literally the thing that is inevitably used by decentralized systems to do proper accounting and reward the providers for providing any services. Or just like, advertisement. ActivityPub, Matrix, PeerTube, NextCloud and Urbit are all fully decentralized and let any instance host monetize themselves however they want. Decentralized services, even for-profit ones, are not synonymous with cryptocurrency. Stop spr…

Urbit uses NFTs as IDs, which can be transferred "Urbit IDs aren’t money, but they are scarce, so each one costs something. This means that when you meet a stranger on the Urbit network, they have some skin in the game and are less likely to be a bot or a spammer." https://urbit.org/overview Who pays for the hosting of ActivityPub and Matrix instances? What if one instance abuses other instances too much? How do you…

> Who pays for the hosting of ActivityPub and Matrix instances?

And

> What if one instance abuses other instances too much? How do you prevent it?

Simple, they get blocked by other instances?

How cryptos change anything to these three questions?

> Oh, look at that, Nextcloud and Sia announce "cloud storage in the blockchain"

That just means Sia wrote a Nextcloud integration for their stuff and somehow nextcloud decided to showcase this integration. That doesn't mean Nexctloud has much to do with blockchain stuff. Nextcloud integrates with anything and its dog.

> What if some spammer abuses Nexcloud?

What kind of spam are you imagining and how do you think crypto coins are going to solve this? You don't use cryptos for this, you use good old system administration and in particular antispam systems, which don't use coins.

> You are totally ignoring the part that people need to get paid for storing stuff, and at the same time the payment needs to happen automatically.

We're not.

First, they don't always need to, some people run stuff out of advocacy for instance.

Second, getting paid with regular money is not an unsolved problem, there are plenty of options, many of which also coming with some builtin guaranties against fraud. It's literally how the whole world works. Now, I can't say I'm a huge fan of our financial system but that's a social issue in need for a social solution, not a technical one.

I'm stopping here, it's pretty clear that I won't get a solid, reasonable argument in favor of cryptos here. And that since your top comment is flagged to death, nobody reads us anyway.

Re: Is Telegram really an encrypted messaging app?

#263

Thanks for the blog post, now I finally have a good resource I can point people to next time they claim Telegramm is secure. > I am not specifically calling out Telegram for this, since the same problem [with metadata] exists with virtually every other social media network and private messenger. Notably, Signal offers a feature called Sealed Sender[0]. While it doesn't solve the metadata problem entirely, it does at…

With Matrix, you can use your own (or trusted) server. Doesn't it solve the problem with the metadata? At least when two trusted servers interact.

This is part of what I love about Mastodon: if you PM someone, very often you're talking between two random servers and odds are good that the admin is a friend of a friend. No dragnet statistical analysis stuff, just friends running some software that normal people can also use. Distributed systems at their best

Re: Is Telegram really an encrypted messaging app?

#264

Are there any pointers for work to try to make metadata private (I.e encrypted)? I was recently very curious about this question and asked similar ones here: https://news.ycombinator.com/item?id=41267877 https://news.ycombinator.com/item?id=41270863 On a side note, I was just recommending Telegram as alternative to WhatsApp (but I did mention that we need to enable Private chats for E2E). It is definitely not an idea…

I know a bit about this topic.

For metadata you first want to remove the obvious identifiers, phone numbers, names. You'd want to use something like anonymous@jabbim.pl for your IM account.

Next, you'd want to eliminate the IP-addresses from server, so you'd want to connect exclusively through Tor. So you'd set the IM client proxy settings to SOCKS5 localhost:9150 and run Tor client to force your client to connect that way. This is error-prone and stupid but let's roll with it for a second.

Now jabbim.pl won't be able to know who you are, but unless you registered your XMPP account without Tor Browser, you're SoL, they already know your IP.

A better strategy is to use a Tor Onion Service based XMPP server, say 4sci35xrhp2d45gbm3qpta7ogfedonuw2mucmc36jxemucd7fmgzj3ad.onion (not a real one), and you'd register to it via IM client. Now you can't connect to the domain without Tor, so misconfiguring can't really hurt.

So that covers name and IP. We'll assume the content was already end-to-end encypted so that leaks no data.

Next, we want to hide the social graph, and that requires getting rid of the server. After all, a server requires you to always route your messages through it and the service can see this account talks to this account, then to these ten accounts, and ten minutes later, those ten accounts talk to ten accounts. That sounds like a command structure.

So for that you want to get rid of the server entirely, which means going peer-to-peer. Stuff like Tox isn't Tor-only so you shouldn't use them.

For Tor-only p2p messaging, there's a few options

https://cwtch.im/ by Sarah Jamie Lewis (great, really usable, beautiful)

https://briarproject.org/ (almost as great, lots of interesting features like forums and blogs inside Tor)

https://onionshare.org/ by Micah Lee. Also has chats between user and hoster

https://github.com/maqp/tfc by yours truly, crude UX but the security is unparalleled.

>On a side note, I was just recommending Telegram as alternative to WhatsApp

Don't. Telegram and WhatsApp both leak meatadata, but WhatsApp is always end-to-end encrypted. Telegram is practically never end-to-end encrypted. I'd use WhatsApp over Telegram any day. But given that unlike WhatsApp, Signal is open source so you know the encryption works as advertised, it's the best everyday platform. The metadata free ones I listed above are for people in more precarious situations, but I'm sure a whistleblower is mostly safe when contacting journalists over Signal. Dissidents and activists might find Cwtch the best option however.

Re: Is Telegram really an encrypted messaging app?

#265

Earlier quoted context omitted.

But that's literally the entire point of this article. That is, in this day and age, when people talk about "secure messaging apps" they are usually implying end-to-end encryption, which Telegram most certainly is not for the vast majority of usages.

Also, iMessage is very secure...but then all your stuff is backed up on iCloud servers unless you specifically disable it. That includes all your iCloud encryption keys and plaintext messages. Worse, iPhones immediately start backing up to iCloud when set up for a new user - the only way to keep your network passwords and all manner of other stuff from hitting iCloud servers is to set the phone up with no network con…

> That includes all your iCloud encryption keys and plaintext messages.

Are these stored encrypted or in the clear? If the latter, please cite your source.

Re: Is Telegram really an encrypted messaging app?

#266
post #94

Earlier quoted context omitted.

It indirectly has a lot to do with encryption, in that if Telegram was actually encrypted, they'd probably have no grounds on holding him in the first place. (At least at the moment, in most countries) it's not illegal to not ship a backdoor in your end-to-end-encrypted software upon government request, but in most it is illegal to not share data you're holding in a form accessible to you when you receive a warrant f…

Anyone can join these channels. How would encryption change anything?

> Anyone can join these channels.

Doesn't mean that the server operators could. Think Mega (the new version of MegaUpload): they have these hash/fragment parts in the URL which aren't sent to the server and so you can send links around but Mega can claim they can't read anything because nobody gave them the "join" link to the data they host

But that's not what Telegram does and so they might reasonably have to implement automatic scans if there are an oddly high number of crimes being coordinated on the platform. (Sarcasm coming up:) It's really strange this would happen after they said it's for privacy nerds and then never implemented encryption for any of the useful/standard features

Re: Is Telegram really an encrypted messaging app?

#268
post #110

Earlier quoted context omitted.

Actually I was wrong. Just checked and Telegram does require a phone number to sign up. I haven't used it myself much, but was relaying the general reasons why regular people use it.

You need it to register, but afaik it's not shown to anyone in any way. You can just grab any prepaid SIM and use it if that's your style

Yeah but the server can correlate it to all messages sent by you, and law enforcement can link server logs to your real identity thrpugh your telco.

Re: Is Telegram really an encrypted messaging app?

#269

Earlier quoted context omitted.

Telegram is the only messaging app that I know of which brought attention to the fact that your messages go through Google/Apple notification APIs, which seems like it would utterly defeat any privacy advantage offered by E2EE

And yet Telegram doesn't allow to have e2ee chats on a Linux desktop or phone. You must rely on Google/Apple.

Most of Telegram clients except initial mobile apps was actually open source projects that was choosen by company to become "offcial" ones.

They just dont implement E2EE since almost no one uses it on Telegram.

Re: Is Telegram really an encrypted messaging app?

#270

Earlier quoted context omitted.

I heard whatsapp is better in low signal conditions, so they use both

I've also seen Discord being used on video footage from the war so I'm not surprised they'd use Whatsapp as well.

We had a client who wanted us to do a security audit and communicate the results—unpatched vulnerabilities mind you—via Discord. They could not be dissuaded.
Post reply on HN