Live data from Hacker News

700M users and Premium

telegram.org

181–190 of 330 posts

Re: 700M users and Premium

#181
post #64
post #10

So who here is using Telegram and for what? I'm consider myself pretty well connected, but I don't have the app. Tell me what I'm missing.

I use it for something like 90% of all my social interactions with real-life friends. IMO, Telegram has by far the best UI/UX of any internet chat app. In terms of stuff like group management, working perfectly on any type of device with any OS, including maintaining accounts on multiple devices and keeping everything synced between them, organizing large numbers of chats in the UI, managing notifications, etc. Video…

For me, the value of messaging comes 99.99% from availability of people I'm messaging. For work, it's all Slack. For personal it's SMS. I haven't seen a compelling feature in a chat app since 1997.

Re: 700M users and Premium

#182
post #70

Many people are asking what are in Telegram that aren’t anywhere else? I can provide some answers. Telegram is my primary chat app. - It offers you to simply share an alphanumeric handle and you can connect with anyone in the world. I can do a voice chat or normal chat really quickly and easily. It is the only famous truly Instant Messenger there is. And I can do it without sharing my name (unlike FB), email address,…

Discord does all this too? + the server rooms.

Discord does not offer a native UI nor is anywhere near as responsive.

Re: 700M users and Premium

#183

Telegram blows my mind. Say what you want about their security; they have the absolute best UX of any (primarily 1-on-1) messaging app, bar none. Discord is a close second. But the quality and polish of telegram blows me away to this day. And it’s lots of small features and details such as built in translation for messages in a foreign language, all the smooth animations, quick look and summaries of channels with agg…

> Say what you want about their security; they have the absolute best UX of any (primarily 1-on-1) messaging app, bar none. That is precisely because they don't give a shit about security. While others like Whatsapp bother with e2ee and resulting device sync problems and inability to do server-side search, Telegram just stores everything on a server without (meaningful) encryption and boldly claims that 'it is the mo…

Telegram is not a tool for sensitive communications, there are far better options if you don't trust some company or have serious adversaries (Signal comes to mind).

But it does aggressively surface the P2P AES256 text chat feature, it does P2P AES256 encrypt voice and video by default (unless I'm badly mistaken), it's got the cute emoji key-verification affordance in voice and video, it does aggressively surface features for allowing people to contact you or not, which is the exact opposite of what a "growth-hacker" PM would do.

How it stands up to a serious security audit is beyond my pay-grade, Moxie seems to think it's weak-ish, and again, that makes it a bad choice if you have credible adversaries.

But I've worked in privacy-hostile settings. Telegram is not privacy-hostile.

Re: 700M users and Premium

#184
post #180

Earlier quoted context omitted.

Before being bought by Facebook I would believe it was e2ee. But believe it’s not e2ee between the client and Facebook. They just decrypt analysis and reencypt and forward. Since communication is not peer to peer and goes via FB the key exchange is prob with Facebook not the users.

>They just decrypt analysis and reencypt and forward. Since communication is not peer to peer and goes via FB the key exchange is prob with Facebook not the users. Do you have any evidence for this, or is this your "better safe than sorry" assumption for every e2e messenger that doesn't allow you to verify keys?

After FB bought WhatsApp I’ve had multiple occasions where shortly after having conversations with people about products I haven’t searched for. The only place I’ve discussed it. Is in a whats app conversation. I got advertising in Facebook for those products.

For example when looking for an apartment I told my agent (non business account) that I wanted safety catches on the windows. I immediately got advertising for safety catches and window gates.

I don’t own cats but in a conversation with a friend who owns cats I said she should get one of those cat tree things and scratch poles. Right away Facebook starts showing me adverts for cat toys.

This is not stuff I’ve searched or googled or anything. Just mentioned in WhatsApp. Maybe WhatsApp whats differently in America but in Singapore I get advertising in Facebook from conversations.

Re: 700M users and Premium

#185
post #180

Earlier quoted context omitted.

>They just decrypt analysis and reencypt and forward. Since communication is not peer to peer and goes via FB the key exchange is prob with Facebook not the users. Do you have any evidence for this, or is this your "better safe than sorry" assumption for every e2e messenger that doesn't allow you to verify keys?

After FB bought WhatsApp I’ve had multiple occasions where shortly after having conversations with people about products I haven’t searched for. The only place I’ve discussed it. Is in a whats app conversation. I got advertising in Facebook for those products. For example when looking for an apartment I told my agent (non business account) that I wanted safety catches on the windows. I immediately got advertising for…

None of this is evidence of decryption.

At best it’s circumstantial anecdotes pointing to Facebook extracting topic metadata out of your convos. This can be done clientside, no decryption necessary. (And it’s easy to prove that it’s being done if that’s the case)

Re: 700M users and Premium

#186
post #180

Earlier quoted context omitted.

>They just decrypt analysis and reencypt and forward. Since communication is not peer to peer and goes via FB the key exchange is prob with Facebook not the users. Do you have any evidence for this, or is this your "better safe than sorry" assumption for every e2e messenger that doesn't allow you to verify keys?

After FB bought WhatsApp I’ve had multiple occasions where shortly after having conversations with people about products I haven’t searched for. The only place I’ve discussed it. Is in a whats app conversation. I got advertising in Facebook for those products. For example when looking for an apartment I told my agent (non business account) that I wanted safety catches on the windows. I immediately got advertising for…

That's... not really good evidence. Your story sounds almost identical to the "facebook/google is eavesdropping on me" stories that frequently make the rounds on popular discourse. Unfortunately, that's basically the Sasquatch of the privacy world (ie. there are many people with anecdotes claiming it exists, but very little in the way of actual evidence like network captures or decompiled binaries). If anything, it's worse than Sasquatch because at least with Sasquatch you could claim that there aren't many of them and/or they're actively avoiding humans so they're hard to photograph, but the "facebook/google is eavesdropping on me" stories implies it's happening to everyone so capturing an instance should only be a matter of technical skill rather than luck.

Re: 700M users and Premium

#187

Earlier quoted context omitted.

After FB bought WhatsApp I’ve had multiple occasions where shortly after having conversations with people about products I haven’t searched for. The only place I’ve discussed it. Is in a whats app conversation. I got advertising in Facebook for those products. For example when looking for an apartment I told my agent (non business account) that I wanted safety catches on the windows. I immediately got advertising for…

None of this is evidence of decryption. At best it’s circumstantial anecdotes pointing to Facebook extracting topic metadata out of your convos. This can be done clientside, no decryption necessary. (And it’s easy to prove that it’s being done if that’s the case)

E2EE plus arbitrarily invasive clent-side sniffing/reporting should not be considered "E2EE" by any means. Even if reports to the mothership are strongly encrypted (at which point it becomes harder to determine what's in the reports).

Re: 700M users and Premium

#188

Telegram blows my mind. Say what you want about their security; they have the absolute best UX of any (primarily 1-on-1) messaging app, bar none. Discord is a close second. But the quality and polish of telegram blows me away to this day. And it’s lots of small features and details such as built in translation for messages in a foreign language, all the smooth animations, quick look and summaries of channels with agg…

The translation feature that sends your messages to Google - via an undocumented API and a random selection of User-Agents. This is who you trust your messaging security to?

Re: 700M users and Premium

#189
post #186

Earlier quoted context omitted.

After FB bought WhatsApp I’ve had multiple occasions where shortly after having conversations with people about products I haven’t searched for. The only place I’ve discussed it. Is in a whats app conversation. I got advertising in Facebook for those products. For example when looking for an apartment I told my agent (non business account) that I wanted safety catches on the windows. I immediately got advertising for…

That's... not really good evidence. Your story sounds almost identical to the "facebook/google is eavesdropping on me" stories that frequently make the rounds on popular discourse. Unfortunately, that's basically the Sasquatch of the privacy world (ie. there are many people with anecdotes claiming it exists, but very little in the way of actual evidence like network captures or decompiled binaries). If anything, it's…

Can you explain why advertising shows only in facebook, for keywords only used inside an apparently private conversation?

Unless WhatsApp is audited completely, not just looking at some source code but also how all information passes through facebook and back to a receiver. Then we can only assume the e2ee is just marketing fluff and not something that is done in favour of privacy.

Re: 700M users and Premium

#190

Earlier quoted context omitted.

> Say what you want about their security; they have the absolute best UX of any (primarily 1-on-1) messaging app, bar none. That is precisely because they don't give a shit about security. While others like Whatsapp bother with e2ee and resulting device sync problems and inability to do server-side search, Telegram just stores everything on a server without (meaningful) encryption and boldly claims that 'it is the mo…

>...and yes, nobody of them used Secret chats... Pretty much no one does any sort of identity verification anyway on any E2EE messaging system. So that means that the people running the servers can MITM if they feel like it to get the content. So in practice Telegram might be the best of something or another for all it matters. It's sort of a con. Yes our E2EE encryption app is perfectly secure assuming you do this t…

> Pretty much no one does any sort of identity verification anyway on any E2EE messaging system. So that means that the people running the servers can MITM if they feel like it to get the content.

Signal makes some cruddy decisions that makes identity verification happen way more often than necessary. Keybase did it better, too bad Zoom bought them just to kill them. Here's their blog post: https://keybase.io/blog/chat-apps-softer-than-tofu . TL;DR:

> Is there a good solution, one that doesn't involve trusting servers with private keys? At Keybase, we think yes: true multi-device support. This means that you control a chain of devices, which are you. When you get a new device (a phone, a laptop, a desktop, an iPad, etc.), it generates its own key pair, and your previous device signs it in. If you lose a device, you "remove" it from one of your remaining devices. Technically this removal is a revocation, and there's also some key rotation that happens automatically in this case.

> The net result is that you don't need to trust the server or meet in person when a partner or teammate gets a new device. Similarly, you don't need to trust the server or meet in person when they remove a device, unless it was their last. The only time you need to see a warning is when someone truly loses access to all their installs. And in that case, you're met with a serious warning, the way it should be:

Post reply on HN