Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

211–220 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#211

So, who has actually launched "a pretty intense" campaign here? https://twitter.com/matthew_d_green/status/17883860908411619... https://twitter.com/evacide/status/1788040276331884593 https://twitter.com/naomibrockwell/status/178863495226900939... https://twitter.com/paulmillr/status/1788563576455610552 (I'm pretty sure the list goes on)

That was my impression too, that this was more of a thread to slander Telegram than anything.

The main leg that Signal has to stand on is it uses standard encryption, but it has all kinds of shady components like it used to require sharing phone number to contact someone, and the cofounder Moxie launched some MOB crypto scam which went to 0 and he has now quit the project too.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#212

I don't know about Telegram being nasty towards Signal but Signal brought this upon themselves. Metadata are more important than the content of the messages and yet Signal has always been about knowing your phone number, with handwaving when the subject is mentioned. Sessions, a Signal fork, had its tagline right: "Share encrypted messages, not metadata" . Signal is a metadata exchanging app and it's about collecting…

You are speaking of metadata as if all metadata is equal. Signal does collect phone numbers (even though, since usernames have been introduced [1], this can be made opt in from now on), but not the contacts or social graph, neither many other relevant metadata [2]. What they can gather from this, is only when the specified phone number registered to signal services and its last connection to the server [3].

So, if you can call "metadata exchanging app" an app that simply has a list of numbers registered to the service, without any metadata assigned to them except their last access, the same label could be assigned to a much larger number of services.

It may not be anonymous, but it can hardly be disregarded as private.

[1] https://signal.org/blog/phone-number-privacy-usernames/

[2] https://signal.org/blog/sealed-sender/

[3] https://signal.org/bigbrother/central-california-grand-jury/

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#213

I don't know about Telegram being nasty towards Signal but Signal brought this upon themselves. Metadata are more important than the content of the messages and yet Signal has always been about knowing your phone number, with handwaving when the subject is mentioned. Sessions, a Signal fork, had its tagline right: "Share encrypted messages, not metadata" . Signal is a metadata exchanging app and it's about collecting…

Signal is still a significant improvement in security and privacy over SMS, Telegram, Discord, X, Whatsapp... It achieved the level of privacy that solutions like PGP tried and mostly failed to achieve for decades. Being tied to a phone number was part of the convenience of their solution. Allowing for nicknames now, might improve on the metadata leakage problem slightly. I'm sure reactionists will immediately drop S…

> I'm sure reactionists will immediately drop Signal because Elon the great said they should

Signal got a massive boost in popularity because "Elon the great" literally told people to "Use Signal".

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#214
post #199

So, who has actually launched "a pretty intense" campaign here? https://twitter.com/matthew_d_green/status/17883860908411619... https://twitter.com/evacide/status/1788040276331884593 https://twitter.com/naomibrockwell/status/178863495226900939... https://twitter.com/paulmillr/status/1788563576455610552 (I'm pretty sure the list goes on)

this is honestly quite surprising... why are they so adamant? we know telegram is not super safe, but at least is not facebook.

It’s ultimately a distinction without a difference, as it is an appeal to the morality of the corporation behind the product, which can change from based on their incentives. E2EE protects against that.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#215

So, who has actually launched "a pretty intense" campaign here? https://twitter.com/matthew_d_green/status/17883860908411619... https://twitter.com/evacide/status/1788040276331884593 https://twitter.com/naomibrockwell/status/178863495226900939... https://twitter.com/paulmillr/status/1788563576455610552 (I'm pretty sure the list goes on)

Yeah, the pro-encryption and pro-privacy people sure seem to be trying to tell us something about Telegram

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#216
post #179

[flagged]

It's completely fair to criticise Signal for its weird decisions (like that time they stopped publishing part of their code for a while to surprise everyone with a crypto scheme.

However, when this criticism comes from an insecure competitor that was forced to pay back immense amounts of money for misleading investors about crypto, I wouldn't take that at face value.

Signal is mostly fine with some weird/bad decisions. Telegram is worse in every single way.

All of that said, I've never seen any of the cryptocurrency shit show up in my phone. Is it geofenced or something?

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#217
post #211

So, who has actually launched "a pretty intense" campaign here? https://twitter.com/matthew_d_green/status/17883860908411619... https://twitter.com/evacide/status/1788040276331884593 https://twitter.com/naomibrockwell/status/178863495226900939... https://twitter.com/paulmillr/status/1788563576455610552 (I'm pretty sure the list goes on)

That was my impression too, that this was more of a thread to slander Telegram than anything. The main leg that Signal has to stand on is it uses standard encryption, but it has all kinds of shady components like it used to require sharing phone number to contact someone, and the cofounder Moxie launched some MOB crypto scam which went to 0 and he has now quit the project too.

As I recall they went out of their way to hide that they were working on that shitcoin integration as well, Signals open source releases went dark for a year or so without explanation and then it turned out to be because they didn't want people to know about MobileCoin. Compromising the transparency of the project to obfuscate the development of a feature that they surely knew would be unpopular isn't a good look.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#218
post #75

Another thing that wasn't pointed out: Du Rove said "Signal messages have been exploited against them in US courts or media." This would be the same case for Telegram as well, if someone has your phone. I believe that Signal can have a lock on the client, and the database is encrypted. The other part that Du Rove conveniently left out: Signal went against the US courts and won [0]. When subpoenaed to give all user in…

Telegram iirc moved it's lead developers to Dubai specifically because the FSB was demanding info from them, so you could argue that's an unfounded concern. The bigger problem with Telegram is that it by default has insecure encryption settings (as opposed to Signal, where encrypted is the default, you need to manually activate it with Telegram + I think it's not possible to enable for all chats and clients) and to m…

> security dark pattern - make privacy a big selling point, but then don't activate the security by default

pretty similar to whatsapp. they boast end to end encryption, but business account (all of them now) uses the facebook server's key, so that the business can give access to several other clients to answer customers. they still call it end to end encryption, and this was actually the last crap the original founder accepted before leaving with lots of money on the table.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#219
post #190

Earlier quoted context omitted.

Can you sign up for Telegram without a phone number?

Yes: https://telegram.org/blog/ultimate-privacy-topics-2-0

Without "SIM card" and "without a number" are different things. Apparently you still need a number, a "blockchain-powered" number:

"[...] You can have a Telegram account without a SIM card and log in using blockchain-powered anonymous numbers available on the Fragment platform."

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#220

Go on, keep defending the overlord you believe have your best interests at heart while the other 57 of us go worry-free, using Matrix or XMPP.

You will eventually revise your opinion once you find your chat logs 20 years later in some randomly occuring IRC logs because that one guy was using an IRC bridge.

You cannot critique missing guaranteed end to end encryption when effectively matrix cannot guarantee it either.

Post reply on HN