Earlier quoted context omitted.
If i remember correctly, Telegram pre-dates Signal by several months. It was well-established by the time Signal became usable. This said, the relationship between Telegram and the cryptography community has always been rocky, probably because they touted their E2E support as a differentiator from the start (Whatsapp, Messenger, and whatever-Google-had were not e2e at the time) but quite a few people pointed out thei…
I think Textsecure[1], the predecessor of Signal, is even older (2010) And Wikipeida also says that the first version of the Signal Protocol is from 2013[2] [1] https://en.wikipedia.org/wiki/TextSecure [2] https://en.wikipedia.org/wiki/Signal_Protocol
The Most Backdoor-Looking Bug I’ve Ever Seen
121–130 of 222 posts
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#122Earlier quoted context omitted.
> Telegram does not encrypt most conversations, you cannot compare it to Signal. I wish people will stop repeating this nonsense. Just because they don't do end to end encryption by default, doesn't mean they don't encrypt, which implies messages are sent in plaintext. There are plenty of reasons why they did what they did, and these questions are all available publicly in their FAQ or the founder's Telegram channel.…
Do you really consider an "encrypted conversation" if you just do TLS to a central server that has everything in plaintext? Is Facebook Messaging encrypted messaging? Because that's the kind of thing we already had before this wave of apps and Telegram is marketed within this new wave but doesn't have any more security than what the previous wave already had, even if you trust their homegrown protocol.
> Is Facebook Messaging encrypted messaging?
Facebook messaging is not "encrypted messaging" AFAIK.
But if you say it sends the messages unencrypted like people claim Telegram does I will probably point out that you are wrong even if I don't like Facebook at all.
end Edit.
--------
Tell me then: If you call point-to-point-encrypted "unencrypted", what do you call the old WhatsApp protocol from before Moxie helped them, which actually sent messages unencrypted? [1]
What do you call the files that Whatsapp store on my phone (messages.db or something) that I can transfer to my computer and open without any tooling besides a zip tool and SQLite?
Unencrypted -- ?
Even more unencrypted?
There is a reason why we keep repeating our plea to differ between unencrypted, point-to-point-encrypted and end-to-end-encrypted and it is not because we adore all of Telegrams decisions, at least not for all of us.
It is because precision often matters in engineering and I think especially for security work.
[1]: Irony over irony, I used to love them back then. I knew fixing the crypto part would be doable and they were such a nice company with such a nice business model which aligned so nicely with our interests as users.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#123> Most backdoor looking bug While a backdoor is not a bug but a feature, it helps to disguise a backdoor as a bug (i.e. plausible deniability). I know of one instance (in MS Windows) where the backdoor feature was not even hidden so much: https://en.wikipedia.org/wiki/NSAKEY That's why we need opensource. It's a hedge against tyranny.
It’s been two decades, and nobody has been able to explain how it would’ve been used.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#124- Clickbait title: Check. - Half-admission that the clickbait title might not apply (at the end of the article by mentioning Hanlon's Razor): Check. - Actual good criticism on "don't roll your own crypto": Check (this is not a sarcasm, I liked that part of the article very much). - Casual mention that the incident is from 7 years ago but implying that today there's a backdoor: Check. - HN going crazy negative when Te…
What saddens me is that Signal seems to be the go to alternative. Which is obviously more secure but still centralised and has a terrible UX (e.g. drains the battery of my laptop very fast when I tried it the last time). Why not directly go for Matrix / Element.io for a secure and decentralised (like eMail) approach? Do you really want to upload your contacts?
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#125If the dead comment by user ‘paveldurov’ is the actual Pavel Durov, then I just found extremely solid reasons never to go near Telegram. Yikes.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#126Earlier quoted context omitted.
Do you really consider an "encrypted conversation" if you just do TLS to a central server that has everything in plaintext? Is Facebook Messaging encrypted messaging? Because that's the kind of thing we already had before this wave of apps and Telegram is marketed within this new wave but doesn't have any more security than what the previous wave already had, even if you trust their homegrown protocol.
Edit, first things first: > Is Facebook Messaging encrypted messaging? Facebook messaging is not "encrypted messaging" AFAIK. But if you say it sends the messages unencrypted like people claim Telegram does I will probably point out that you are wrong even if I don't like Facebook at all. end Edit. -------- Tell me then: If you call point-to-point-encrypted "unencrypted", what do you call the old WhatsApp protocol fr…
Yes?
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#127Earlier quoted context omitted.
Well, sue them. I don't think all other messengers save for maybe Matrix and Signal are any better. Even better, make a messenger that does encrypt chats. Make it paid. Prove its end-to-end encryption properties. I'll buy it and advocate for it to my friends and family. In any case, the constant hate is (a) very tiring and (b) very uncharacteristic for HN.
Why are you so bothered by Telegram receiving some well deserved criticism? It’s weird. There are lots of posts on HN I don’t care about, but I don’t think I’ve ever had the urge to make comments like yours. > In any case, the constant hate is (a) very tiring and (b) very uncharacteristic for HN. There are people who trust their life and liberty on these apps, I don’t think the “hate” towards Telegram is inappropriat…
I see some people linking old articles and cryptography research, and some historic incidents. Good! That's arguing in good faith and I've read those with an interest, and upvoted them. "I don't trust Durov", which many of the HN comments about Telegram boil down to, is just noise. I don't want noise in threads where I want to find objective information. I am doing my part to improve HN by downvoting / flagging comments I see as noise or non-constructive attacks.
> Usually I see comments criticizing it get downvoted. Funny, no?
Filter bubbles then, I suppose. Seems we are both in our own and apparently neither of us is right in their generalization. ¯\_(ツ)_/¯ I can live with that.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#128Earlier quoted context omitted.
I don’t think your paraphrase is an accurate representation of the article.
It's not. (I'm the author.)
Case in point: the Hanlon's Razor mention definitely did mislead me in terms of your stance.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#129> PitM attack I see we've arrived at the point where we're re-naming commonly established acronyms in order to remain politically correct.
Re: The Most Backdoor-Looking Bug I’ve Ever Seen
#130Earlier quoted context omitted.
That's not saying anything of substance unless you offer your own interpretation. "You're wrong" is not a discussion, it's a kick in the gut. > The lady doth protest too much, methinks. Solid criticism with well laid-out arguments from you, no doubt. > Besides, look at Pavel Durovs flagkilled reply here. Since when do upvote / downvote count mean anything at all about somebody's opinion or statements? (I haven't read…
>I haven't read the comment though Maybe do that. Not being snarky, you’re missing important context.
Still, he's an official public face and should know better. That I fully agree with.