Live data from Hacker News

Telegram is anything but secure; even Facebook is safer, says Signal founder

phonearena.com

41–45 of 45 posts

Re: Telegram is anything but secure; even Facebook is safer, says Signal founder

#41

Tweet thread from Signal's founder (that touches on some topics in the article) https://twitter.com/moxie/status/1474067549574688768

Read why is Marlinspike wrong.

https://threej.in/article/Signal-founder-criticizes-Telegram...

Re: Telegram is anything but secure; even Facebook is safer, says Signal founder

#42

Earlier quoted context omitted.

> Messages sent through Telegram are stored on Telegram's servers in their original form, or plain text, without going any sort of encryption to protect private user data, shared Marlinspike. It is not disingenuous to call data stored in plain text as stored in plain text. Transport security is very different from security at rest. > Here is the FBI's own datasheet on what message content they're able to obtain with…

> It is not disingenuous to call data stored in plain text as stored in plain text. Transport security is very different from security at rest. Data is not stored in plaintext. It is stored encrypted, at rest. Period. In the very Twitter thread posted at the top of the comments, Moxie states he uses "plaintext" as shorthand. So he is making up a new definition of plaintext to slander a competitor, something he loves…

Encrypted on a server where the company running it also has the key… It is accurate to say Telegram has access to plain text copies of everything. It’s also accurate to say anyone with access to Telegrams infrastructure has access to the plain text. Encryption at rest, that is not e2ee, really will only protect you against someone stealing a hard drive from a decommissioned server.

That’s the simple difference. Telegram is less encrypted than Facebook messenger is.

Re: Telegram is anything but secure; even Facebook is safer, says Signal founder

#43

Earlier quoted context omitted.

> It is not disingenuous to call data stored in plain text as stored in plain text. Transport security is very different from security at rest. Data is not stored in plaintext. It is stored encrypted, at rest. Period. In the very Twitter thread posted at the top of the comments, Moxie states he uses "plaintext" as shorthand. So he is making up a new definition of plaintext to slander a competitor, something he loves…

Encrypted on a server where the company running it also has the key… It is accurate to say Telegram has access to plain text copies of everything. It’s also accurate to say anyone with access to Telegrams infrastructure has access to the plain text. Encryption at rest, that is not e2ee, really will only protect you against someone stealing a hard drive from a decommissioned server. That’s the simple difference. Teleg…

No, it is not. And we need to get clear on our use of words and the games we play with words and their meaning to make others look bad.

People understand that when we say passwords were stored in plaintext on a company's breached servers it's a lot more severe than when we say passwords were stored encrypted on a company's breached servers. If the encryption key was also leaked, we're in as much trouble as scenario A.

It is an abuse of our understanding of these words, which stand related but differentiated to each other, to use the word "plaintext" from scenario A interchangeably for "encrypted" in scenario B.

That is, at best, manipulative of people like you and I and of a media which is all too willing to stoke the fires of outrage.

Re: Telegram is anything but secure; even Facebook is safer, says Signal founder

#44

Earlier quoted context omitted.

That doesn't help because the other end can be compromised.

If they verify their end, it does. What software would not be vulnerable to what you’re describing?

It's not about the software, it's about the distribution of the software. Signal distributes through Google as man-in-the-middle. So if you trust Google, you're OK. But if you're using Signal because you don't trust Google, it doesn't make sense.

In case you don't trust Google I really suggest OpenSSH or WireGuard, to establish a secure tunnel; and then run IRC, Jabber, SIP, or mumble (as needed) over the tunnel.

Re: Telegram is anything but secure; even Facebook is safer, says Signal founder

#45

Earlier quoted context omitted.

Encrypted on a server where the company running it also has the key… It is accurate to say Telegram has access to plain text copies of everything. It’s also accurate to say anyone with access to Telegrams infrastructure has access to the plain text. Encryption at rest, that is not e2ee, really will only protect you against someone stealing a hard drive from a decommissioned server. That’s the simple difference. Teleg…

No, it is not. And we need to get clear on our use of words and the games we play with words and their meaning to make others look bad. People understand that when we say passwords were stored in plaintext on a company's breached servers it's a lot more severe than when we say passwords were stored encrypted on a company's breached servers. If the encryption key was also leaked, we're in as much trouble as scenario A…

> No, it is not.

Which part are you referring to?

I made a couple claims.

A. Telegram has access to all plain text content B. Someone with access to Telegrams infrastructure has access to plain text content C. Telegram is less encrypted than Facebook messenger

The first, I stand by. The second does make a few assumptions.

The second assumption, that if you have access to the infrastructure you could get access to the private key, this may not be true. Depending on how well they manage their systems. Something that any user will have to trust vs a trust less e2ee system.

The final one is, admittedly, incorrect. I misspoke. It’s _as encrypted_ as Facebook Messenger, and _less encrypted_ than WhatsApp.

Post reply on HN