Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

281–290 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#281
post #75

Another thing that wasn't pointed out: Du Rove said "Signal messages have been exploited against them in US courts or media." This would be the same case for Telegram as well, if someone has your phone. I believe that Signal can have a lock on the client, and the database is encrypted. The other part that Du Rove conveniently left out: Signal went against the US courts and won [0]. When subpoenaed to give all user in…

Telegram iirc moved it's lead developers to Dubai specifically because the FSB was demanding info from them, so you could argue that's an unfounded concern. The bigger problem with Telegram is that it by default has insecure encryption settings (as opposed to Signal, where encrypted is the default, you need to manually activate it with Telegram + I think it's not possible to enable for all chats and clients) and to m…

> because the FSB was demanding info from them

But they gave the FSB info they asked for -- the vk.com website (facebook clone, at that time it had way more massive amounts of user data than telegram). They could have deleted the data, but no, they handed it over to FSB.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#282

Earlier quoted context omitted.

and who runs privacyguides.net ? the FSB or CIA?

Well... if you scrolled up a bit you would have found https://discuss.privacyguides.net/t/according-to-elon-musk-s... which says Signal isn't great either.

No, it does not.

Let's enumerate the purported problems:

- "Elon Musk said so", which does not matter. - Signal attachments can be viewed by an attacker with local access to the client. This is not Signal's job to protect against. - Signal offers an optional `--no-sandbox` flag which only has security options if enabled on Linux. - Weaknesses in sealed sender. This is the only one that might be an actual problem (two theoretical and one empirical attack, but the latter comes from an 18 page paper that I have not read). But this does not compromise the integrity of the chats, and is not something Telegram improves on.

Given how the posted described the optional `--no-sandbox` flag as "no sandbox on Linux", it's clear that they don't understand anything they're sharing, and they just want to spread FUD.

---

edit: Per discussion below, I was wrong about the `--no-sandbox` flag. It's enabled by default. The risk is that an attacker could figure out how to use Signal to run arbitrary JavaScript. I take back my insult- it was I who did not understand the linked issue.

I still stand by Signal > Telegram. The risk here is that an attacker could figure out how to abuse Signal to run arbitrary Javascript, e.g. through a specially crafted message.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#283
post #205
post #157

Earlier quoted context omitted.

Your points have little to do with security (which is the main angle of Matthew Green's thread), especially because of reproducibility. Even then > You need to download it from the Google Play Store. Factually incorrect, just go to https://signal.org/android/apk/ (and the apk will then update itself) or build it yourself. > pushed the update to everyone but no one could inspect the source code. That was for the serve…

> Factually incorrect, just go to https://signal.org/android/apk/ (and the apk will then update itself) or build it yourself. That page tells me that the safest way is to have a Google account, with Google Play Services installed on my phone, and to download it from the Google Play Store. It then gives me an APK link after saying "Danger zone" and "most users should not do this". If the app developer tells me it's da…

Well, the page is correct. That's the safest way.

I don't know how to verify the SHA fingerprint without Googling (I know how it works, just don't do it often to know the exact openssl or equivalent command).

If I'm downloading the APK directly on the phone, there's a lot that's not under Signal's control that could happen.

What if I'm directly under attack, and I'm trying to move to Signal? The attacker could MITM the connection and intercept the download.

I think that's a fair warning to show a user, because indeed most users will likely want to install apps through Play Store, that'll reduce/remove supply chain risks. Users who know enough about APKs would be able to verify the hash, or build it themselves.

Even if I download the APK, I still have to accept a similar warning when installing it on my phone.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#285

Earlier quoted context omitted.

You need a phone number to sign up for Telegram as well. And you can correlate username to phone number not that hard in most standard setting cases.

Yeah, basically both super duper encrypted privacy oriented services want your phone number. Sorry, but that's not privacy. I don't care what they do to encrypt your messages, they are still tied to me, which makes the super duper encryption pointless.

You compare apples with oranges. Because if you'd compare the apples , you'd notice one of them has no usable E2E.

Yes oranges umm phone numbers is a problem. They have that both. Only one can additionally read the contents.

Thats for now the price for a normie interface.

First goalposts first.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#286
post #237

Earlier quoted context omitted.

Their problem is that F-Droid releases are signed by F-Droid, not by Signal. This way F-Droid could potentially insert a backdoor in an update.

That's not true tho. f-droid supports (true) https://f-droid.org/en/docs/Reproducible_Builds/ for quite some time now. Those are signed by both, f-droid and the author.

I should have checked before I posted something from memory. These are the reasons they list:

https://community.signalusers.org/t/signal-android-app-on-f-...

F-Droid with reproducible builds signed by both parties seems the best of both worlds to me, now I don't understand why Signal is so stubborn about this.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#287
post #63

This just seems like a knee-jerk reaction to Durov promoting his own platform as usual, what does Elon Musk have to do with this for example? Is there any evidence that the authorities have ever had access to private conversations? At the end of the day, the issue comes down to the fact that Telegram is such a superior messaging app compared to anything else.

See this other comment which contains links to Elon Musk’s comments about Signal[1].

[1] https://news.ycombinator.com/item?id=40342204

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#288
post #75

Another thing that wasn't pointed out: Du Rove said "Signal messages have been exploited against them in US courts or media." This would be the same case for Telegram as well, if someone has your phone. I believe that Signal can have a lock on the client, and the database is encrypted. The other part that Du Rove conveniently left out: Signal went against the US courts and won [0]. When subpoenaed to give all user in…

Telegram iirc moved it's lead developers to Dubai specifically because the FSB was demanding info from them, so you could argue that's an unfounded concern. The bigger problem with Telegram is that it by default has insecure encryption settings (as opposed to Signal, where encrypted is the default, you need to manually activate it with Telegram + I think it's not possible to enable for all chats and clients) and to m…

> Telegram iirc moved it's lead developers to Dubai specifically because the FSB was demanding info from them, so you could argue that's an unfounded concern.

I'd argue it's not giving us any certainty. They could've moved away to escape. They could've moved away to a nice FSB-sponsored location while making good publicity. Ideally the tech should be good enough for this issue to not matter.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#289
post #179

[flagged]

It's completely fair to criticise Signal for its weird decisions (like that time they stopped publishing part of their code for a while to surprise everyone with a crypto scheme. However, when this criticism comes from an insecure competitor that was forced to pay back immense amounts of money for misleading investors about crypto, I wouldn't take that at face value. Signal is mostly fine with some weird/bad decision…

[deleted]
Post reply on HN