Live data from Hacker News

Telegram has launched a pretty intense campaign to malign Signal as insecure

twitter.com

451–460 of 501 posts

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#451

Earlier quoted context omitted.

> Both services are relatively insecure because they require phone authentication. That hasn't been the case for Signal for some months: https://signal.org/blog/phone-number-privacy-usernames/ You still require a phone number for sign up for Signal, but your phone number isn't visible to anyone you chat with.

> but your phone number isn't visible to anyone you chat with. That's irrelevant - the phone number is known to Signal and can be request by law enforcement. And, since it's been made pretty much impossible to buy a SIM in the EU without showing identification [0], this will allow law enforcement to link the account to you. [0] IIRC the Netherlands is the only country left where you can buy SIMs without ID.

> [0] IIRC the Netherlands is the only country left where you can buy SIMs without ID.

As far as I know, in Romania you can still buy and activate a prepaid SIM card without having to show your ID. There was an attempt a few years ago to make it mandatory to tie the phone number to an ID, but it was overruled by the Constitutional Court.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#452
post #438

Earlier quoted context omitted.

> but your phone number isn't visible to anyone you chat with. That's irrelevant - the phone number is known to Signal and can be request by law enforcement. And, since it's been made pretty much impossible to buy a SIM in the EU without showing identification [0], this will allow law enforcement to link the account to you. [0] IIRC the Netherlands is the only country left where you can buy SIMs without ID.

> That's irrelevant - the phone number is known to Signal and can be request by law enforcement. So how does this work? Law enforcement asks signal if they have an account for a phone number, signal saying "yes, here's when they created it". Then what?

> Law enforcement asks signal if they have an account for a phone number, signal saying "yes, here's when they created it".

Law enforcement says that the suspect chatted with some username/told people to contact him by his Signal username, then they go to Signal and request the linked phone number, which is then linked to the ID shown when the card was bought.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#453

Earlier quoted context omitted.

Oh yeah, "both sides". Sure... Wanna ask the two orphans living at my cousin's where their parents are and who killed them? How many thousands of such examples do you need? I'm sure as hell I can supply you with a sufficient amount, even worse than straight up shooting a child's parents in front of their eyes.

> Wanna ask the two orphans living at my cousin's where their parents are and who killed them? Applying an emotional argument to shut up discussions against censorship is propaganda 101.

That would be a good argument if it wasn't for the thousands of videos of men, women and children getting raped and killed and russians gloating in the comment sections. Something which telegram is notorious for.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#454
post #438

Earlier quoted context omitted.

> That's irrelevant - the phone number is known to Signal and can be request by law enforcement. So how does this work? Law enforcement asks signal if they have an account for a phone number, signal saying "yes, here's when they created it". Then what?

> Law enforcement asks signal if they have an account for a phone number, signal saying "yes, here's when they created it". Law enforcement says that the suspect chatted with some username/told people to contact him by his Signal username, then they go to Signal and request the linked phone number, which is then linked to the ID shown when the card was bought.

This only works as long as the username is active/unchanged. It would probably be better if usernames were never linkable to phone numbers, but if your threat model requires a persistent, non-ephemeral username to remain anonymous when targeted by law enforcement that has access to your telecom records and warrants... that's going to require a pretty high level of opsec.

The UX on usernames in Signal might be non-ideal. It might be helpful to have a toggle that regularly cycles your username if that's important for your threat model.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#455

Not being in either Telegram/Signal camp I see a lot of tribalism in the comments. It seems that any arguments for/against either one end up in politics. Like I understand that Telegram is probably not very secure, but seeing what proponents of Signal are saying doesn't really make me trust Signal either.

It is political. As I mentioned elsewhere in HN, Telegram is now being promoted in the US by the political-right there because they have lost trust in US BigTech social media platforms who, they believe, are "unjustly" censoring them on their platform. That is why the right-leaning media are now heavily promoting Telegram ( https://www.youtube.com/watch?v=1Ut6RouSs0w ) and bashing other platforms ( https://www.city-journal.org/article/signals-katherine-maher... ).

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#456
post #438

Earlier quoted context omitted.

> That's irrelevant - the phone number is known to Signal and can be request by law enforcement. So how does this work? Law enforcement asks signal if they have an account for a phone number, signal saying "yes, here's when they created it". Then what?

"Get me all the numbers which talked to X, including all the numbers". You won't get the actual plaintext messages, but the contact graph + metadata (timestamps) are pretty sensitive.

Signal doesn't store the graph, nor does it log message timestamps.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#457

Earlier quoted context omitted.

Good for you, you probably do not live in a country under digital colonialism where the gov allowed facebook et al to force internet providers to tax the pop with absurdly low and expensive data limits and then "not count" things like facebook and whatsapp and one music app. In most of the global south, 100% of business have a whatsapp. In those places it pretty much replaced telephone and the green whatsapp icon is…

i completely agree with your sentiment, but i will also say this. As an expat, this feature has enabled me to transact with locals from the convenience of my phone, even though i don't have any local line and i will not bother to get a local SIM card, nor do i want to have a US SIM and a local one interchangeably. It also enables me to be very effective when requesting services on demand, and cutting thru the on-hold…

All of that can be achieved in the same way via email.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#458
post #75

Another thing that wasn't pointed out: Du Rove said "Signal messages have been exploited against them in US courts or media." This would be the same case for Telegram as well, if someone has your phone. I believe that Signal can have a lock on the client, and the database is encrypted. The other part that Du Rove conveniently left out: Signal went against the US courts and won [0]. When subpoenaed to give all user in…

[deleted]

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#459
post #338

Earlier quoted context omitted.

It's inherently risky – cryptography is hard and building secure software is hard, so starting it from scratch rather than re-using well-vetted code increases the risk unnecessarily. It's not inherently broken, but it's sufficiently risky that it may be fair to assume it is broken. History has proven that software that's not known to be secure is typically insecure when it gets to the really hard crypto implementatio…

It’s insecure if done by your average full stack developer, that barely passed high school math. That’s why the usual mantra. It’s waaay different when done by math experts specialized in this topic, as is the case with telegram.

Math experts are not necessarily good cryptographers, and authors of MTProto were not renowned cryptographers (unlike with Signal).

Most people in the cryptographic community agree that the Signal protocol is well-designed, is widely believed to be secure, and the authors react openly and swiftly to potential issues. Meanwhile, a lot of the MTProto crypto is just weird (that is, it does not follow standard practices of the field, without strong reasons to do so), and many cryptographers treat it with suspicion.

Re: Telegram has launched a pretty intense campaign to malign Signal as insecure

#460
post #451

Earlier quoted context omitted.

> but your phone number isn't visible to anyone you chat with. That's irrelevant - the phone number is known to Signal and can be request by law enforcement. And, since it's been made pretty much impossible to buy a SIM in the EU without showing identification [0], this will allow law enforcement to link the account to you. [0] IIRC the Netherlands is the only country left where you can buy SIMs without ID.

> [0] IIRC the Netherlands is the only country left where you can buy SIMs without ID. As far as I know, in Romania you can still buy and activate a prepaid SIM card without having to show your ID. There was an attempt a few years ago to make it mandatory to tie the phone number to an ID, but it was overruled by the Constitutional Court.

[deleted]
Post reply on HN