Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

441–450 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#441

There are multiple layers where interception can happen: 1) On-screen keyboard - by default most phones do send what is being typed - a lot of phones also have 3rd party keyboards of doubtful origin preinstalled 2) "Enable backup" scam - on starting an app (like Google Photos or WhatsApp) chances you or your wife accidentally press "ok" on a pop up message 3) Hardware drivers - non open source binary blobs with back…

>by default most phones do send what is being typed

That's extraordinary if true. Do you have anything to back it up, though? Even Google (!) wasn't brazen enough to log everything typed on Gboard, they implemented federated learning.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#443

Earlier quoted context omitted.

“All of them” in what sense? I use WhatsApp dozens of times a day, and interact with business accounts every couple months at most.

Good for you, you probably do not live in a country under digital colonialism where the gov allowed facebook et al to force internet providers to tax the pop with absurdly low and expensive data limits and then "not count" things like facebook and whatsapp and one music app. In most of the global south, 100% of business have a whatsapp. In those places it pretty much replaced telephone and the green whatsapp icon is…

i completely agree with your sentiment, but i will also say this.

As an expat, this feature has enabled me to transact with locals from the convenience of my phone, even though i don't have any local line and i will not bother to get a local SIM card, nor do i want to have a US SIM and a local one interchangeably.

It also enables me to be very effective when requesting services on demand, and cutting thru the on-hold time, disconnected calls, or the needless chitchat.

I have many bad things to say about WA, but making living more difficult in a foreign country is not one of them.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#444

Earlier quoted context omitted.

Signal was the last place she worked. https://christopherrufo.com/p/signals-katherine-maher-proble...

Still not seeing any connection here. Seems like a reach to attack Rufo.

Agreed. There's no solid evidence presented.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#445
post #438

Earlier quoted context omitted.

> but your phone number isn't visible to anyone you chat with. That's irrelevant - the phone number is known to Signal and can be request by law enforcement. And, since it's been made pretty much impossible to buy a SIM in the EU without showing identification [0], this will allow law enforcement to link the account to you. [0] IIRC the Netherlands is the only country left where you can buy SIMs without ID.

> That's irrelevant - the phone number is known to Signal and can be request by law enforcement. So how does this work? Law enforcement asks signal if they have an account for a phone number, signal saying "yes, here's when they created it". Then what?

"Get me all the numbers which talked to X, including all the numbers".

You won't get the actual plaintext messages, but the contact graph + metadata (timestamps) are pretty sensitive.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#446
post #99

> An alarming number of important people I’ve spoken to remarked that their “private” Signal messages had been exploited against them in US courts or media. Any sources for this except the private testimony of a Signal competitor talking about his important friends? (ETA: Or is it when the court/media obtains your unlocked phone, in which case Telegram won't protect you either...)

My guess would be that their phone was taken from them, unlocked, and their messages were accessed that way. I know several large IT orgs that have done this when Legal got involved. Literally using a 2nd phone to take pictures of Signal chats on the phone in question.

Or some sort of spyware like Pegasus

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#447
post #58

This is a response to the following post from Telegram creator Durov https://t.me/durov/274

- "I don't like where one of their board worked" (find someone high up in the cryptography ecosystem who hasn't been involved in this sort of thing somewhere in their career) - "I don't like where their funding comes from" (US govt regularly funds secure software because they depend on it for their own operations, see: Tor) - "An alarming number of people think their chats were leaked". It's easy to state things with…

> An alarming number of people think their chats were leaked

Easily explained by direct access to the phone or Pegasus (or Pegasus-like) spyware. Both of which Telegram is also vulnerable to.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#449

Earlier quoted context omitted.

On Signal vs Telegram: Telegrams Encryption is off most of the time. They have serverside access to messages. The optional E2E is annoying to use and isnt even available on every platform. For example Tdesktop afaik still has no E2E support. (And has a very brittle software architecture.) You can't register Telegram accounts with the open source client anymore. This should be a non-Discussion. MG implying that just b…

Both services are relatively insecure because they require phone authentication. In the EU at least the number can always be traced back to you if you don't buy specific burner phones. The level of encryption isn't as important anymore at that point. It is less probable you get into problems by using a service that doesn't know your identity.

Anonymity and Encryption aren't flip sides of the same coin, they can be used together or separately, and are orthogonal in lots of use cases.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#450
post #9

https://nitter.poast.org/matthew_d_green/status/178968789886...

Woah, people are still doing that thing where they break a post into 10+ tweets?

Of course, it's either that or a png of the text from a text editor or pay for blue check account, neither of which are optimal for most people
Post reply on HN