Live data from Hacker News

Mysteries of Telegram Data Centers (2022)

dev.moe

151–160 of 166 posts

Re: Mysteries of Telegram Data Centers (2022)

#151
post #50

Earlier quoted context omitted.

Agreed. I don’t see the appeal compared to Signal. Although, Signal is also sketchy with an operating cost in the tens of millions of dollars per year. Where does the money come from?

I’ve always been under the impression that Signal is for secure, private chats and group chats amongst friends and small groups. While telegram is often used more like discord or irc, with “secure” and “private” group chats that are extremely large and semi-public. “Invite only” but invites are handed out easily. Those chats are pretty obviously not as secure, as basically anybody can join them and decrypt the chat.…

The bigger issue is Telegram advertises it as more private option to WhatsApp although Telegram collects more metadata, and also the message content. People think Telegram is more private, they don't use it as a public forum replacement. Also, institutions running Telegram have people form closer working groups that become groups for friends, who don't necessarily realize they should be moving to Signal the moment the members start sharing things they don't want everyone to know.

Re: Mysteries of Telegram Data Centers (2022)

#152

Earlier quoted context omitted.

Wait, the open source cli of an E2E encrypted messenger seems untrustworthy, but the official API of a completely unencrypted messenger seems trustworthy? I guess "we can definitely spy on your messages" is a lot more honest than "we are very unlikely to spy on your messages", if it turns out spying takes place.

You're getting the issues confused. Signal does not have an official Signal CLI (or method of creating integrations) so users are compromising their use of Signal by using heavily patched and out-of-date code written by unknown third parties. Telegram has support for integrations and clients but isn't a service anyone should trust.

Telegram offering bells and whistles that leaks everything to the service provider is not an argument for Telegram the same way "it launches the video game" isn't an argument for video game cracks that carry ransomware.

Both are called Trojan Horses and are considered malware.

Re: Mysteries of Telegram Data Centers (2022)

#153
post #6

something smells suspicious about this kind of data routing

The Lex Fridman podcast episode with Pavel Durov is worth listening to. Their servers are built to be very secure — of course, it would be different for others, and they use some clever tricks

Very secure servers are openly documented (Kerckhoff's principle).

Snake oil purporting itself as secure is always very hush hush and comes with claims of security.

Besides, other messengers like Signal have already made the server open source, and they have native clients that end-to-end encrypt everything, so you don't even have to trust server.

Durov requiring you to trust the server shows he has no idea how to build secure systems. He and his team are amateurs in security engineering.

Re: Mysteries of Telegram Data Centers (2022)

#154

Earlier quoted context omitted.

A fee based service without site redundancy for one?

It’s quite easy to anycast an IP to multiple physical datacenters. Their DC nomenclature is probably a relic from when they really had a single datacenter for each region. On the other hand, it wouldn’t shock me if they had no site redundancy. It’s a free service, it’s not like there’s SLA agreements you paid for on signup.

The article says each user is associated with a single DC, and if that DC is down the user has no service. You kind of have to conclude from that the users data is not replicated across sites or there is some other architectural issue causing this. And they do have paid tiers.

Re: Mysteries of Telegram Data Centers (2022)

#155
post #39

Earlier quoted context omitted.

Heavily means the key is large so it takes longer to crack, but also longer to encrypt/decrypt, so the service is more costly to run and slower. At least I've seen it used that way

There's nothing slow about AES. In this context "heavily" means "we can't legally claim it's end-to-end encrypted because it's not". Also it's not even post quantum, so it's not heavy. Telegram's Diffie-Hellman breaks instantly with a quantum computer large enough to run Shor against it. Also, the keys sit on the servers' RAM, no matter what they lie. There is no global distributed RAM system, especially one that enc…

I've never claimed that anything about telegram's encryption is "heavy", because I don't even know what they use, I just said what "heavy" usually means

> In this context

In this context it's marketing bs for people that only seen action movies where hackers quickly cracked encryption. I'm sure whatever telegram uses is not that ridiculously easy to crack

Re: Mysteries of Telegram Data Centers (2022)

#156
post #126

Somebody already posted it but I wanted to mention it again, investigations that Telegram has not been able to dispute have revealed that Telegram's infrastructure is managed by a person who is also managing infra for FSB. And this is happening unbeknownst to Telegram employees. https://istories.media/en/stories/2025/06/10/telegram-fsb/

This just makes me realize that three letter agencies of basically every country probably have an extremely easy time getting access to things by simply getting people hired as regular employees through mundane and routine means.

One hopes that the usual defenses against insider risk provide some help here.

Re: Mysteries of Telegram Data Centers (2022)

#157
post #146

Earlier quoted context omitted.

> You people are just racist towards Russians and need help. >> That doesn’t exclude the statements about Telegram to be correct though. just attack the telegram from the technical standpoint, then no complains about "racist towards russians" will be given. Like, mentioning the lack of user-friendly E2EE is great already. Saying things like "Durov who supposedly lives in exile has visited Russia over 50 times" is meh…

>Durov who supposedly lives in exile has visited Russia over 50 times Durov's exile marketing makes him look like he's Alexei Navalny. Navalny was a true dissident and critic and he was first poisoned, and then later arrested when he returned. He was was then imprisoned and he died in prison. Durov has been visiting Russia more than I've been visiting my friends over the same period. Him returning to Russia that many…

I've never had a twitter account so all these people hating durov for his exile marketing look weird to me. I'm not disagreeing with what you say but it's like a whole another subsection of world opened to me

Re: Mysteries of Telegram Data Centers (2022)

#158
post #98

Earlier quoted context omitted.

In Telegram, I can open a chat, find a sticker, send a sticker, post a circle story, and shitpost in another group chat. All while WhatsApp loads my chat history. That is on any platform and any network condition, except for fully offline. Their desktop apps are just Qt and not WebView inside a Qt. Mobile apps are native and not React.

Ok I don't know what finding a sticker has to do with speed. Whatsapp and Signal have stickers too. Kids use them sometimes. They are like in a list. You open the list. Chose one and then it appears. Don't know what there is to accelerate. ...and yeah, whatever language they are. I don't really care because, as said: there is no problem...

> Ok I don't know what finding a sticker has to do with speed.

You don't know that it takes time to load graphical assets? And you can't comprehend that I'm using it as an example of how much more stuff Telegram clients manage to do/load in the time it takes WhatsApp to load one screen?

Re: Mysteries of Telegram Data Centers (2022)

#159

Earlier quoted context omitted.

The appeal of Telegram over Signal or WhatsApp is that it is not an American or BigTech service. (And, ofcourse, it's really good). Signal is funded by 2 rich American entrepreneurs who made their fortune when their services were acquired by Twitter (TextSecure / RedPhone) and Meta (WhatsApp), respectively. Whether it is indeed altruism behind this, you'll have to judge for yourself ...

Would you explain why "American or BigTech" is worse than some sketchy bro sitting in tax haven? Would be good if we can compare technologies rather than feelings. I hate what US tech has turned into, but presence of E2EE on whatsapp makes it incredibly way better than telegram to that matter. Even though undoubtedly Meta farms metadata on WA.

Ideally, yes, if all else were equal we would only be making a purely technical comparison. But that's not how it works. People also factor in the business model and values of the company before making purchase decisions. (That applies to countries too - see https://en.wikipedia.org/wiki/Boycotts_of_Israel ). For many of us, Meta and its founders score very low on the "trustworthy" factor, when it comes to privacy. As for E2EE, despite allegations that Telegram's encryption is weak, nobody has yet demonstrated that by breaking it. And, those who care about E2EE should perhaps use Signal over WhatsApp, as WhatsApp itself uses their technology.

Re: Mysteries of Telegram Data Centers (2022)

#160
post #158

Earlier quoted context omitted.

Ok I don't know what finding a sticker has to do with speed. Whatsapp and Signal have stickers too. Kids use them sometimes. They are like in a list. You open the list. Chose one and then it appears. Don't know what there is to accelerate. ...and yeah, whatever language they are. I don't really care because, as said: there is no problem...

> Ok I don't know what finding a sticker has to do with speed. You don't know that it takes time to load graphical assets? And you can't comprehend that I'm using it as an example of how much more stuff Telegram clients manage to do/load in the time it takes WhatsApp to load one screen?

No I can't since I've never experienced any delay which would justify this amount of criticism and I mean, Germany is outside of big cities quite messy in it's coverage.
Post reply on HN