Live data from Hacker News

Telegram Became the Anti-Facebook

wired.com

181–190 of 257 posts

Re: Telegram Became the Anti-Facebook

#181

Earlier quoted context omitted.

How is that? Only you as a recipient can decrypt the messages, because they are sent e2ee to you. And this stays true if you use the backup, as only you know that password.

Encrypted backups are just that, encrypted backups. They are called end-to-end encrypted backups only by people who are ignorant of correct terminology. Even the Wikipedia entry on e2ee addresses this. Regarding the security theater, the backups encrypted with your password are far more vulnerable to being compromised than any of the popular e2e encryption protocols. But then again, most users do not need real securi…

I have nowhere called them end-to-end encrypted Backups, that's a straw man.

> Regarding the security theater, the backups encrypted with your password are far more vulnerable to being compromised than any of the popular e2e encryption protocols.

How, so? Are you aiming weak passwords? (One is provided for you ("security key"), however you can opt into a custom one that is not directly used for encryption ("security passphrase"))? Or are you referring to PFS, which isn't a property of all popular e2e protocols either, and "far" would be quite a stretch.

How does all that disprove that Element uses true e2ee?

Re: Telegram Became the Anti-Facebook

#182

Earlier quoted context omitted.

How is that? Only you as a recipient can decrypt the messages, because they are sent e2ee to you. And this stays true if you use the backup, as only you know that password.

Encrypted backups are just that, encrypted backups. They are called end-to-end encrypted backups only by people who are ignorant of correct terminology. Even the Wikipedia entry on e2ee addresses this. Regarding the security theater, the backups encrypted with your password are far more vulnerable to being compromised than any of the popular e2e encryption protocols. But then again, most users do not need real securi…

>Regarding the security theater, the backups encrypted with your password are far more vulnerable to being compromised than any of the popular e2e encryption protocols.

Hmm? How so? Surely this depends on the strength of your password.

Re: Telegram Became the Anti-Facebook

#183
post #119

Earlier quoted context omitted.

Are you sure? You can do what good password managers do: - Hash the password client-side - Send the hash to the server. The server treats it as a password, and gives you your blob of encrypted data - Decrypt the data client-side using the original password

That requires re-encoding all transmitted data with a single password and is potentially vulnerable to brute-force attacks. Encryption used in signal, etc relies on double ratchet mechanism that continuously regenerates keys as they move along. This way one compromised key will not allow to decode the rest of the messages. Also, downloading blob to client side and decoding it locally can hardly be done fast enough fo…

Most of that time is spent on downloading the data, which you have to do with any synchronization.

Re: Telegram Became the Anti-Facebook

#184

Earlier quoted context omitted.

Telegram is ridiculously smooth, runs on everything, doesn’t treat any platform as an afterthought (despite having the electron thing, Signal is still very mobile oriented), and isn’t Facebook. It’s about as good as you’re going to get without making big sacrifices somewhere.

Telegram is the only platform that "works" on Jolla. WA/Signal are both proprietary and will not work outside the Google-Apple "pleb sandbox".

Pffft. Signal is proprietary?

it is on https://Github.com/SignalApp

and i’ve got my own variant of Signal server and client running. and runs on not only mobile but Linux too.

Re: Telegram Became the Anti-Facebook

#185
post #174

Earlier quoted context omitted.

> we were talking about E2E encryption, weren't we? Exactly, and what is described is not e2ee at all.

How is it not E2EE? Are you going by a stricter definition than commonly used? > End-to-end encryption (E2EE) is a system of communication where only the communicating users can read the messages. [..] End-to-end encryption is intended to prevent data being read or secretly modified, other than by the true sender and recipient(s). The messages are encrypted by the sender but the third party does not have a means to d…

It is incorrect to refer to encrypted backups as e2ee. See the wikipedia article on the subject [0], at the bottom of the "Modern usage" section.

[0] https://en.wikipedia.org/wiki/End-to-end_encryption

Re: Telegram Became the Anti-Facebook

#186

Earlier quoted context omitted.

Encrypted backups are just that, encrypted backups. They are called end-to-end encrypted backups only by people who are ignorant of correct terminology. Even the Wikipedia entry on e2ee addresses this. Regarding the security theater, the backups encrypted with your password are far more vulnerable to being compromised than any of the popular e2e encryption protocols. But then again, most users do not need real securi…

I have nowhere called them end-to-end encrypted Backups, that's a straw man. > Regarding the security theater, the backups encrypted with your password are far more vulnerable to being compromised than any of the popular e2e encryption protocols. How, so? Are you aiming weak passwords? (One is provided for you ("security key"), however you can opt into a custom one that is not directly used for encryption ("security…

It is proven beyond doubt that whatever Element fetches from their own servers and decodes on application launch are not messages encrypted using e2ee protocols. It is also completely clear that it does reduce the privacy of user messages. I don't know what else to argue about here.

Re: Telegram Became the Anti-Facebook

#187

Earlier quoted context omitted.

Encrypted backups are just that, encrypted backups. They are called end-to-end encrypted backups only by people who are ignorant of correct terminology. Even the Wikipedia entry on e2ee addresses this. Regarding the security theater, the backups encrypted with your password are far more vulnerable to being compromised than any of the popular e2e encryption protocols. But then again, most users do not need real securi…

>Regarding the security theater, the backups encrypted with your password are far more vulnerable to being compromised than any of the popular e2e encryption protocols. Hmm? How so? Surely this depends on the strength of your password.

All messages are encrypted with one key. Break one key, and all messages will be accessible to an attacker. Proper encryption protocols rotate encryption keys and compromising one message will not compromise the rest.

Re: Telegram Became the Anti-Facebook

#188

Earlier quoted context omitted.

Not really strange, given what this country has done on social media to control foreign elections, allegedly, just saying.

As a Russian, this goes both ways. I really hate how the US tries its damnest to pretend they control the entire planet and meddles with internal politics of other countries, something they have no business even knowing about, all the time. Sovereignty? What sovereignty?

True, but that it happens on both sides is not really an argument that will make people more at ease with foreign social media apps, I suppose.

Re: Telegram Became the Anti-Facebook

#189

Earlier quoted context omitted.

How is that? Only you as a recipient can decrypt the messages, because they are sent e2ee to you. And this stays true if you use the backup, as only you know that password.

Encrypted backups are just that, encrypted backups. They are called end-to-end encrypted backups only by people who are ignorant of correct terminology. Even the Wikipedia entry on e2ee addresses this. Regarding the security theater, the backups encrypted with your password are far more vulnerable to being compromised than any of the popular e2e encryption protocols. But then again, most users do not need real securi…

>Some encrypted backup and file sharing services provide client-side encryption. The encryption they offer is here not referred to as end-to-end encryption, because the services are not meant for sharing messages between users[further explanation needed].

This wikipedia entry? So client-side encrypted backups are not called end-to-end encrypted, because the backup service is not a messenger?

Re: Telegram Became the Anti-Facebook

#190

Earlier quoted context omitted.

As someone mentioned somewhere, there are more articles in mainstream media mentioning Ku Klux Klan than there actually are KKK members. The far right exists and is potentially dangerous, but overconcentrating on it will let other dangers fly under the radar.

To respond to your first point, I mean there are more articles mentioning members of congress than there are members of congress. Or more articles mentioning Taylor Swift than there are Taylor Swifts. Not sure how quantity of articles is a unit of measurement here.

True, but the Congress has enormous power and Taylor Swift is at least creative enough to merit some attention.
Post reply on HN