There seems to be a concerted effort to discredit Matthew's claims. Even here on HN. I find this suspicious. The Signal protocol has been heavily audited by many different people from many different countries. It's usually found to be sound. The telegram protocol has been found to have issues that are, if not malicious, amateur level mistakes. Once again, this is not my opinion. This is the result of independent audi…
> The telegram protocol has been found to have issues that are, if not malicious, amateur level mistakes. Please provide evidence of such issues. Because at most, the issues with MTProto were at the level of "we are not familiar with this, but seems ok". Which seem to be inflated by Signal activists into maliciousness. You do make bear service here.
Telegram has launched a pretty intense campaign to malign Signal as insecure
171–180 of 501 posts
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#172Earlier quoted context omitted.
Telegram Foss clients exist only because of unpaid volunteers that take Telegrams messy mix of open and closed parts and rip closed parts out and replace them. The Telegram organisation is notoriously late to release the source code to their current release. If they do, its a giant squashed commit without proper changelog. These releases must then be first wrangled by volunteers to be well buildable. The Telegram Org…
Telegram has fully reproducible builds and is not that complicated to build, no issues there. They even have a guide on how to build & verify. [0] No need to wrangle or modify, generally builds as is (at least from my experience). Granted yes, the version commits are squashed like you said. [1] However I haven't seen source release to lag behind store releases, any sources on that? 0: https://core.telegram.org/reprod…
Release lag -> Telegram foss needs to wrangle the release every time. Fdroid CI takes its time.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#173https://twitter.com/matthew_d_green/status/17883860908411619... https://twitter.com/evacide/status/1788040276331884593 https://twitter.com/naomibrockwell/status/178863495226900939... https://twitter.com/paulmillr/status/1788563576455610552
(I'm pretty sure the list goes on)
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#174As far as we can tell, they are both insecure: Telegram is closed source and Signal published their source but basically forces users to use the Google Play version which lags behind the OS version and you can never be 100% sure what it does, not to mention things like SGX.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#175I don't know about Telegram being nasty towards Signal but Signal brought this upon themselves. Metadata are more important than the content of the messages and yet Signal has always been about knowing your phone number, with handwaving when the subject is mentioned. Sessions, a Signal fork, had its tagline right: "Share encrypted messages, not metadata" . Signal is a metadata exchanging app and it's about collecting…
I'm sure reactionists will immediately drop Signal because Elon the great said they should without considering that it still might be their best solution to communicate privately with their friends and family. But X makes *all* of it's money from collecting a lot more than metadata from their users, Tesla collects driving data and metadata from all of its customers, Grok trains it's AI on all of the data collected from X, Tesla and other sources without asking if users want to opt out of those training datasets. So I'm not sure Elon has a leg to stand on in this conversation.
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#176Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#177isn’t telegram the one that uses a wonky/sus custom encryption algorithm? https://words.filippo.io/dispatches/telegram-ecdh/
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#178Earlier quoted context omitted.
Telegram has fully reproducible builds and is not that complicated to build, no issues there. They even have a guide on how to build & verify. [0] No need to wrangle or modify, generally builds as is (at least from my experience). Granted yes, the version commits are squashed like you said. [1] However I haven't seen source release to lag behind store releases, any sources on that? 0: https://core.telegram.org/reprod…
That repo is not fully open. Release lag -> Telegram foss needs to wrangle the release every time. Fdroid CI takes its time.
A couple months ago I actually verified a build of Telegram on my friend's phone as he thought something might be off and didn't have any issues there (the build matched).
Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#179Re: Telegram has launched a pretty intense campaign to malign Signal as insecure
#180However Du Rove is right about a bunch of things:
- Signal clients suck, specially the Desktop one where they ship (or used to) pre-built binaries like their own lib: https://github.com/signalapp/ringrtc - Also you can't have Signal without Google Play Store - Signal client suck in usability. I wish I had Telegram client (android) and desktop (qt) instead of this electron garbage. Telegram clients are super-duper-awesome - I would say that removing phone number requirement is their #1 request. yet they take so much time to address it, specially when they cry about phone number validation SMS costs - BTW, telegram is implementing a very nice idea of a crowd sourced sms validation, where they use their users phone numbers to send the validation sms - They have a very questionable crypto integration with MobileCoin, which have a obscure value: they depend on IntelSGX and is 95% pre-mined