Live data from Hacker News

Is Telegram really an encrypted messaging app?

blog.cryptographyengineering.com

271–280 of 609 posts

Re: Is Telegram really an encrypted messaging app?

#271

Does anyone have any reason to believe that Telegram's E2EE doesn't have a backdoor? Because if not, then I fail to see why it matters whether the E2EE even exists in the first place.

Telegram clients are open source. Anyone can verify that the client does the end-to-end encryption correctly.

Telegram has had its own history of really weird issues with its encryption protocol, like the IGE, 2^64 complexity pre-computation attacks, IND-CCA vulnerability and whatever the hell this was https://words.filippo.io/dispatches/telegram-ecdh/

But these are not the big issues here. The issues Green's blog post highlighted were

* Telegram doesn't default to end-to-end encryption.

* It makes enabling end-to-end encryption unnecessarily hard

* It has no end-to-end encryption for groups

Those matter gazillion times more than e.g. a slightly older primitive would.

End-to-end encryption matters because Telegram is not just a social media or Twitter wall. It's used for purposes that deserve privacy, and Telegram isn't providing.

Re: Is Telegram really an encrypted messaging app?

#272
post #249

Earlier quoted context omitted.

> it's literally the thing that is inevitably used by decentralized systems to do proper accounting and reward the providers for providing any services. Or just like, advertisement. ActivityPub, Matrix, PeerTube, NextCloud and Urbit are all fully decentralized and let any instance host monetize themselves however they want. Decentralized services, even for-profit ones, are not synonymous with cryptocurrency. Stop spr…

Urbit uses NFTs as IDs, which can be transferred "Urbit IDs aren’t money, but they are scarce, so each one costs something. This means that when you meet a stranger on the Urbit network, they have some skin in the game and are less likely to be a bot or a spammer." https://urbit.org/overview Who pays for the hosting of ActivityPub and Matrix instances? What if one instance abuses other instances too much? How do you…

I could go on for literal days. The blockchain isn't a panacea, and rationally most solutions don't ultimately settle on a bespoke transactional network with audited consensus protocols. It is stupid, overdesigned, and as a sign of its poor fitness it dies over time. I'm not relaying some "evil villain" speech from someone that wants to see decentralized services die, this is a reality check from your peers who also hate centralization. Borderline intervention if it has to be - you've echoed this same sentiment in several threads while apparently ignoring the self-evident failure of protocols that embody your vision.

This was a cutting-edge and untested concept in maybe 2011. You missed the boat by a decade and a half.

> LBRY is a genuine utility token being used for instance.

Yeah, last I heard of their brand was when a member of my graduating class became a neo-nazi for six months and incessantly uploaded videos detailing his hallucinations to the internet. You're in good company, it sounds like.

Re: Is Telegram really an encrypted messaging app?

#273
post #72

Earlier quoted context omitted.

Signal lost all credibility with their cryptobro bullshit

Only among people who pay attention to cryptobro bullshit. They remain the gold standard among cryptography engineers.

Is Session's also good? They had this cryptobro stuff from the beginning so I never paid attention despite their claims that security is on par with Signal and the like (probably not the SGX and sealed sender bits, but the message contents encryption). Nobody ever talks about it but yesterday they apparently got a million users. Makes me wonder whether to start paying attention

Re: Is Telegram really an encrypted messaging app?

#274

Earlier quoted context omitted.

Also, iMessage is very secure...but then all your stuff is backed up on iCloud servers unless you specifically disable it. That includes all your iCloud encryption keys and plaintext messages. Worse, iPhones immediately start backing up to iCloud when set up for a new user - the only way to keep your network passwords and all manner of other stuff from hitting iCloud servers is to set the phone up with no network con…

> That includes all your iCloud encryption keys and plaintext messages. Are these stored encrypted or in the clear? If the latter, please cite your source.

They are stored encrypted but whether Apple has the key depends on whether you've turned on "Advanced Data Protection" (aka "I don't expect Apple to bail me out when I lose access to all my devices"). The table in this support article details the treatment of various data categories under the two options:

https://support.apple.com/en-us/102651

The default for many categories is that your keys are in iCloud so Apple can recover them for you. With Advanced turned on, the keys are only on your personal devices. A few categories, like the keychain, are always only on your devices.

Specifically, see Note 3: "If you use both iCloud Backup and Messages in iCloud, your backup includes a copy of the Messages in iCloud encryption key to help you recover your data." Under normal protection, Apple has the key to your backups, but with Advanced they don't.

Re: Is Telegram really an encrypted messaging app?

#275

Does anyone have any reason to believe that Telegram's E2EE doesn't have a backdoor? Because if not, then I fail to see why it matters whether the E2EE even exists in the first place.

Reason to believe is that all their apps are open source and have reproducible builds:

https://core.telegram.org/reproducible-builds

Their custom encryption is questionable, but since it open source someone would find out by now if there was obvious backdoors.

Re: Is Telegram really an encrypted messaging app?

#276
post #99
post #48

Earlier quoted context omitted.

You can coherently argue that encryption doesn't matter, but you can't reasonably argue that Telegram is a serious encrypted messaging app (it's not an encrypted messaging app at all for group chats), which is the point of the article. The general attitude among practitioners in the field is: if you have to reason about how the operator will handle legal threats, you shouldn't bother reasoning about the messenger at…

> if you have to reason about how the operator will handle legal threats, you shouldn't bother reasoning about the messenger at all. That's true. You need to run your own platform people. XMPP is plenty simple, plenty powerful, and plenty safe -- and even your metadata is in your control. Just self host. There's no excuse in 2024. Wake up people! Why should the arrest of someone else affect YOU?

  > Just self host. There's no excuse in 2024.
I hate to break it to you, but there's plenty of excuses. We live in a bubble on HN.

May I remind you what the average person is like with this recently famous reddit post:

https://archive.is/hM2Sf

If you want self hosting to happen, with things like Matrix, and so on, the hard truth is that it has to not be easy for someone who can program, but trivial for someone who says "wow, can you hack into " if they see you use a terminal

Re: Is Telegram really an encrypted messaging app?

#277

It's not e2e encrypted, so what? It's something the majority of users does not need, and that doesn't increase security that much given their downsides. Of course for Telegram is much more convenient to not have end2end encryption. Given that they store everything on their servers, it means years of chat history that probably weights Gb for each user, contrary to what WhatsApp/Signal do, of course if 10 million peopl…

> By the way, end2end encryption it's not that safe as they claim. Sure, the conversation can not be intercepted, however: [...]

> - you can make a MITM attack on the server (don't know if they do that, but technically possible)

No it's not technically possible, by its very definition. The fundamental principle behind E2EE is that the server can be malicious or compromised all you want, but this does not impact message confidentiality or integrity.

Re: Is Telegram really an encrypted messaging app?

#279

I am null at cryptography but thie following does not sound too bad as a default tbh. And I think it is misleading to focus solely on e2ee and not mention the distributed aspect. https://telegram.org/faq#q-do-you-process-data-requests > To protect the data that is not covered by end-to-end encryption, Telegram uses a distributed infrastructure. Cloud chat data is stored in multiple data centers around the globe that…

I am wondering if there was any incident that disproved the “we have disclosed 0 bytes of user data to third parties, including governments.” statement.

Yes, https://www.androidpolice.com/telegram-germany-user-data-sur...

Re: Is Telegram really an encrypted messaging app?

#280
post #50

Are there any pointers for work to try to make metadata private (I.e encrypted)? I was recently very curious about this question and asked similar ones here: https://news.ycombinator.com/item?id=41267877 https://news.ycombinator.com/item?id=41270863 On a side note, I was just recommending Telegram as alternative to WhatsApp (but I did mention that we need to enable Private chats for E2E). It is definitely not an idea…

Why didn't you recommend signal?

Signal really needs a good bot support... that's the only thing keeping me on telegram.
Post reply on HN