Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

401–410 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#401
post #390

Earlier quoted context omitted.

Personally I've never received a scam or spam message on Signal.

I am in a Signal group which has an invite link discoverable on public internet (it's a local OpenStreetMap group). From time to time, a bot joins and proceeds to spam the group's members one-on-one.

The same happens on the Telegram OSM group. Now, the easy and 99% effective mitigation is to make a "bridge group" where you need to click something to join the real deal but changing that would invalidate any existing links.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#402
post #90

Telegram were claiming they were more secure even when they had their own home-rolled crypto. Security is not Telegram's strong point and it never was.

Technically Signal is using their own home-rolled crypto, too – right?

Sort of, but it's heavily peer reviewed and generally regarded as very good.

I really dislike the "hand rolled is bad" meme. Someone rolled all crypto. The questions are "who is doing the rolling," "do they know what they are doing," and "was it peer reviewed or directly and faithfully built from a peer reviewed design?"

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#403
post #377

Earlier quoted context omitted.

Of course. But the history of the Signal protocol and implementation traces back 20 years. It's good enough that Facebook, WhatsApp, and Skype use it for E2EE messages. Telegram's traces back 10 years, the first version was very bad, and both versions have had a lot of scrutiny for weird design decisions. Crypto schemes which get broken usually follow a pattern of "something smells wrong", "we have weakened it a litt…

> But the history of the Signal protocol and implementation traces back 20 years Are you sure about that? TextSecure was created more 10 years ago than 20. 20 years ago, we did not have smartphones. As I remember, TextSecure started with SMS (but that was not the Signal protocol) and added "internet" messages right after WhatsApp got bought (which was about when Telegram was started). I love the Signal protocol, but…

Signal/TextSecure (/DRA/Axolotl) has a pretty strong throughline from the "off-the-record" protocol (OTR) from 2004/2005. Signal themselves describes TextSecure as a derivative of OTR (https://signal.org/blog/simplifying-otr-deniability/).

It's close enough that if, say, a novel attack against OTR were discovered today, the first thing I'd want to know is if there are any implications against Signal.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#404

Let me set a few things straight: Telegram is for the most part tiktok for people that don't mind putting some effort into reading on a few odd occasions. Saying that I have a lot of Ukrainian friends would be an understatement and the are the only reason I have telegram-all of them favor it, which, all things considered, is a grave mistake. In practice, telegram is far more closely related to tiktok and twitter than…

And that's good, that's their strength. I use it to read information from all sides of the conflict and decide for myself what's "disinformation" and what's not. A grown person doesn't need a gatekeeper that pushes their own interests and shuts up anyone daring to contradict them.

Oh yeah, "both sides". Sure... Wanna ask the two orphans living at my cousin's where their parents are and who killed them? How many thousands of such examples do you need? I'm sure as hell I can supply you with a sufficient amount, even worse than straight up shooting a child's parents in front of their eyes.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#405
post #99

> An alarming number of important people I’ve spoken to remarked that their “private” Signal messages had been exploited against them in US courts or media. Any sources for this except the private testimony of a Signal competitor talking about his important friends? (ETA: Or is it when the court/media obtains your unlocked phone, in which case Telegram won't protect you either...)

My guess would be that their phone was taken from them, unlocked, and their messages were accessed that way.

I know several large IT orgs that have done this when Legal got involved. Literally using a 2nd phone to take pictures of Signal chats on the phone in question.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#406

They want to do this because they want more traction for their blockchain: TRON, which, IIRC, is the payment method for ads, usernames and "stuff" inside Telegram. However Du Rove is right about a bunch of things: - Signal clients suck, specially the Desktop one where they ship (or used to) pre-built binaries like their own lib: https://github.com/signalapp/ringrtc - Also you can't have Signal without Google Play Sto…

> you can't have Signal without Google Play Store

You can use Signal without the Play Store. Download the apk from Signal's website and it will use a background connection to receive calls and notifications. The downside is that it's heavier on the battery.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#407
post #141

Earlier quoted context omitted.

Does Telegram still use their own crypto algorithm? If so, up-to-date source code us pretty useless. How many people check their app's source code? With third party clients it's pretty easy to get malicious ones

[flagged]

But Telegram uses it's own protocol MTProto which isn't extremely well know and tested.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#408
post #179

[flagged]

It's completely fair to criticise Signal for its weird decisions (like that time they stopped publishing part of their code for a while to surprise everyone with a crypto scheme. However, when this criticism comes from an insecure competitor that was forced to pay back immense amounts of money for misleading investors about crypto, I wouldn't take that at face value. Signal is mostly fine with some weird/bad decision…

It's exactly as hidden/opt-in as the Stripe crypto settings, where Stripe was completely shit on in 20 comments about scams, scamming, and scam currencies.

Downvoters hate having their double standard revealed.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#409

Earlier quoted context omitted.

Good for you, you probably do not live in a country under digital colonialism where the gov allowed facebook et al to force internet providers to tax the pop with absurdly low and expensive data limits and then "not count" things like facebook and whatsapp and one music app. In most of the global south, 100% of business have a whatsapp. In those places it pretty much replaced telephone and the green whatsapp icon is…

Are you saying this is a worse alternative to other communication methods with businesses? What would you use with them that has better encryption?

The lack of encryption between myself and a business is less offensive than replacing an open standard (plain old telephone systems, eMail) with a proprietary and closed one, backed by a single, private corporation

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#410

Earlier quoted context omitted.

Why is MTProto considered "home-rolled" but the Signal Protocol isn't? Both are boutique and written from scratch to fit their respective systems.

Of course. But the history of the Signal protocol and implementation traces back 20 years. It's good enough that Facebook, WhatsApp, and Skype use it for E2EE messages. Telegram's traces back 10 years, the first version was very bad, and both versions have had a lot of scrutiny for weird design decisions. Crypto schemes which get broken usually follow a pattern of "something smells wrong", "we have weakened it a litt…

> It's good enough that Facebook, WhatsApp, and Skype use it for E2EE messages.

Wait if it's the same why don't we just use Facebook, WhatsApp and Skype instead of Signal?

Post reply on HN