Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

171–180 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#171

There seems to be a concerted effort to discredit Matthew's claims. Even here on HN. I find this suspicious. The Signal protocol has been heavily audited by many different people from many different countries. It's usually found to be sound. The telegram protocol has been found to have issues that are, if not malicious, amateur level mistakes. Once again, this is not my opinion. This is the result of independent audi…

> The telegram protocol has been found to have issues that are, if not malicious, amateur level mistakes. Please provide evidence of such issues. Because at most, the issues with MTProto were at the level of "we are not familiar with this, but seems ok". Which seem to be inflated by Signal activists into maliciousness. You do make bear service here.

https://eprint.iacr.org/2023/469.pdf

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#172
post #167

Earlier quoted context omitted.

Telegram Foss clients exist only because of unpaid volunteers that take Telegrams messy mix of open and closed parts and rip closed parts out and replace them. The Telegram organisation is notoriously late to release the source code to their current release. If they do, its a giant squashed commit without proper changelog. These releases must then be first wrangled by volunteers to be well buildable. The Telegram Org…

Telegram has fully reproducible builds and is not that complicated to build, no issues there. They even have a guide on how to build & verify. [0] No need to wrangle or modify, generally builds as is (at least from my experience). Granted yes, the version commits are squashed like you said. [1] However I haven't seen source release to lag behind store releases, any sources on that? 0: https://core.telegram.org/reprod…

That repo is not fully open.

Release lag -> Telegram foss needs to wrangle the release every time. Fdroid CI takes its time.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#173
So, who has actually launched "a pretty intense" campaign here?

https://twitter.com/matthew_d_green/status/17883860908411619... https://twitter.com/evacide/status/1788040276331884593 https://twitter.com/naomibrockwell/status/178863495226900939... https://twitter.com/paulmillr/status/1788563576455610552

(I'm pretty sure the list goes on)

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#174

As far as we can tell, they are both insecure: Telegram is closed source and Signal published their source but basically forces users to use the Google Play version which lags behind the OS version and you can never be 100% sure what it does, not to mention things like SGX.

Signal self publishes their apk. You can drink directly from the source.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#175

I don't know about Telegram being nasty towards Signal but Signal brought this upon themselves. Metadata are more important than the content of the messages and yet Signal has always been about knowing your phone number, with handwaving when the subject is mentioned. Sessions, a Signal fork, had its tagline right: "Share encrypted messages, not metadata" . Signal is a metadata exchanging app and it's about collecting…

Signal is still a significant improvement in security and privacy over SMS, Telegram, Discord, X, Whatsapp... It achieved the level of privacy that solutions like PGP tried and mostly failed to achieve for decades. Being tied to a phone number was part of the convenience of their solution. Allowing for nicknames now, might improve on the metadata leakage problem slightly.

I'm sure reactionists will immediately drop Signal because Elon the great said they should without considering that it still might be their best solution to communicate privately with their friends and family. But X makes *all* of it's money from collecting a lot more than metadata from their users, Tesla collects driving data and metadata from all of its customers, Grok trains it's AI on all of the data collected from X, Tesla and other sources without asking if users want to opt out of those training datasets. So I'm not sure Elon has a leg to stand on in this conversation.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#177

isn’t telegram the one that uses a wonky/sus custom encryption algorithm? https://words.filippo.io/dispatches/telegram-ecdh/

Well, if you think that AES-256 that MTProto uses[1] is some wonky algorithm...

[1] https://core.telegram.org/mtproto

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#178
post #167

Earlier quoted context omitted.

Telegram has fully reproducible builds and is not that complicated to build, no issues there. They even have a guide on how to build & verify. [0] No need to wrangle or modify, generally builds as is (at least from my experience). Granted yes, the version commits are squashed like you said. [1] However I haven't seen source release to lag behind store releases, any sources on that? 0: https://core.telegram.org/reprod…

That repo is not fully open. Release lag -> Telegram foss needs to wrangle the release every time. Fdroid CI takes its time.

Which parts are missing?

A couple months ago I actually verified a build of Telegram on my friend's phone as he thought something might be off and didn't have any issues there (the build matched).

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#180
They want to do this because they want more traction for their blockchain: TRON, which, IIRC, is the payment method for ads, usernames and "stuff" inside Telegram.

However Du Rove is right about a bunch of things:

- Signal clients suck, specially the Desktop one where they ship (or used to) pre-built binaries like their own lib: https://github.com/signalapp/ringrtc - Also you can't have Signal without Google Play Store - Signal client suck in usability. I wish I had Telegram client (android) and desktop (qt) instead of this electron garbage. Telegram clients are super-duper-awesome - I would say that removing phone number requirement is their #1 request. yet they take so much time to address it, specially when they cry about phone number validation SMS costs - BTW, telegram is implementing a very nice idea of a crowd sourced sms validation, where they use their users phone numbers to send the validation sms - They have a very questionable crypto integration with MobileCoin, which have a obscure value: they depend on IntelSGX and is 95% pre-mined

Post reply on HN