Live data from Hacker News

On the Security of WhatsApp and Telegram

germano.dev

1–10 of 22 posts

Re: On the Security of WhatsApp and Telegram

#4

Totally ignored Signal though?

Yeah, I thought the post was already too long to also talk about Signal!

My opinion on Signal is it should definitely be preferred if one cares about security more than usability. I really cannot wait for it to have a "standalone" client (that is, that does not require the phone to be online as well).

There are other messaging apps, like Element (and the now defunct Keybase) which try to solve the same problems. So, I decided to keep that discussion for another future article (maybe).

Re: On the Security of WhatsApp and Telegram

#5
This simply ignores the primary threat model.

Can govt or a company mass harvest chats to classify users into buckets? and use this data to manipulate people. We have seen this happen with Cambridge Analytica. Think of military having a list of all pro-democracy people before staging the coup.

Re: On the Security of WhatsApp and Telegram

#6
post #5

This simply ignores the primary threat model. Can govt or a company mass harvest chats to classify users into buckets? and use this data to manipulate people. We have seen this happen with Cambridge Analytica. Think of military having a list of all pro-democracy people before staging the coup.

That's the issue at hand. Telegram is popular in countries where their primary thread model is getting arrested, not being MITM'ed by their governments

Re: On the Security of WhatsApp and Telegram

#7
post #5

This simply ignores the primary threat model. Can govt or a company mass harvest chats to classify users into buckets? and use this data to manipulate people. We have seen this happen with Cambridge Analytica. Think of military having a list of all pro-democracy people before staging the coup.

Why do you think it is ignored? Feel free to suggest a way to improve the article, if you want :)

In my opinion this is partially addresses in the threat modelling section, where I mention the need to trust "The companies running the servers needed by the app to work".

Anyway I believe the threat you mention is a very difficult one to defend against, because probably even metadata alone is sufficient to construct a graph of relations. So, I maybe wrong, but if you do not want to trust any company at all, then even Signal may not be enough for you in this scenario. Regarding the choice of WhatsApp vs Telegram for this scenario, you simply have to decide if you trust more Facebook (which we already know supplies this kind of mass data to the US government) or the Telegram team. Or you can trust neither.

Re: On the Security of WhatsApp and Telegram

#8

Totally ignored Signal though?

No, it mentioned that Signal is more secure but less usable. They didn't seem to have any qualms with it. It seems to me the thesis here was basically comparing the tradeoffs that Telegram and WhatsApp made for usability, it seemed to imply that Signal didn't make any of these (I don't think it did).

Re: On the Security of WhatsApp and Telegram

#10
> Advanced users, which need end-to-end encryption and are willing to trade a bit of usability for improved security guarantees, are able to do so by using secret chats

Except when they want to chat with more than one person at once. Telegram does not have any support for encrypted group conversations.

Otherwise a good read. Telegram is not a bad app, but it does not suit my threat model. I'm willing to forgo cloud backups and some usability to have default encryption for all my conversations, which I think is something Signal provides. None of these apps are perfect, it comes down to what combination of trade-offs works best for you.

Post reply on HN