Live data from Hacker News

Telegram messaging app proves crucial to Belarus protests

latimes.com

541–550 of 557 posts

Re: Telegram messaging app proves crucial to Belarus protests

#541
post #413
post #405

Earlier quoted context omitted.

Explain how this works. A blue party voter writes to another blue party voter: Hey, let's vote blue this year. NSA that intercepts the message and __________.

The thing being suggested here is that the campaign of the incumbent is reading all the communications of the campaign of the challenger. I don't think anything of the sort actually happens or is really that easy to (completely secretly!) make happen, but that's the proposed scenario.

People are doing that.

My kids tested sending https://kamalaharris.info and https://joebiden.info to each other on Instagram, in private messages. The sender would see that the message was successfully sent, but it would never arrive.

Another case is that the person who ran the primary campaign for Kamala Harris now works at Twitter, where he blocked an opponent's campaign account.

Re: Telegram messaging app proves crucial to Belarus protests

#542

Earlier quoted context omitted.

There are two parties in a conversation. Both 'own' the conversation. Both have a 'veto' right.

I disagree. I see my phone as an extension of my brain. If I have an in-person conversation, the other party can't force me to forget the conversation, and they shouldn't have that ability for my phone either.

What if only the other partys messages where deleted?

In telegram it is understood that 'secret chats' constitutes confidentiality. As such, both parties, I believe, ought to be able to delete everything.

I kind of see you point about non-secret chats.

But then we are back with a opt-in model for privacy.

Personally: what I tell you at the coffee machine, in confidence or not, is ephemeral. I would probably not talk to you at all if you where taperecording all conversations, as you want to do with messages... so I think both.parties.should be able to delete text conversations. And privacy should be on by default.

Re: Telegram messaging app proves crucial to Belarus protests

#543
post #388

Earlier quoted context omitted.

When you realize end-to-end encryption is a necessary property of all features, you realize Telegram lacks even basic things like desktop clients, syncable chats, and group chats. Not so feature rich anymore ;)

Not official, but Unigram for Windows 10 is the way to go for me. It has everything it should have and is not Electron. The best app of this kind there is at the moment. I'm not affiliated with Unigram in any way, just a happy user.

By the way, the official client doesn't use Electron either - it uses qt.

Re: Telegram messaging app proves crucial to Belarus protests

#544
post #523

Earlier quoted context omitted.

Does anyone know of good extension to use PGP on top of Telegram Web? So that whenever you chat with person X, if thats persons public key is saved, all messages with that person are PGP encrypted

It would probably be easier to just get that person a XMPP client that supports PGP.

Last time I checked(and I might be wrong) Telegram did not support XMPP, has that changed?

Re: Telegram messaging app proves crucial to Belarus protests

#545
post #544

Earlier quoted context omitted.

It would probably be easier to just get that person a XMPP client that supports PGP.

Last time I checked(and I might be wrong) Telegram did not support XMPP, has that changed?

No, but the person you were PGPing with would need to install something anyway. The thought that it might as well just be a separate client.

Re: Telegram messaging app proves crucial to Belarus protests

#546

Earlier quoted context omitted.

I disagree. I see my phone as an extension of my brain. If I have an in-person conversation, the other party can't force me to forget the conversation, and they shouldn't have that ability for my phone either.

What if only the other partys messages where deleted? In telegram it is understood that 'secret chats' constitutes confidentiality. As such, both parties, I believe, ought to be able to delete everything. I kind of see you point about non-secret chats. But then we are back with a opt-in model for privacy. Personally: what I tell you at the coffee machine, in confidence or not, is ephemeral. I would probably not talk…

In Signal ALL conversations are private.

> I would probably not talk to you at all if you where taperecording all conversations

You hit the nail on the head with this one. To me deletion is a nice compromise and why the coffee shop analogy isn't a good comparator. Similarly we don't record video calls (and Moxie himself doesn't like this). So why should every text be recorded and parties do not have control over that data? I do feel that each person in the conversation has a right to control that data (if anything the sender more so) and when policy fails it should fail in the direction that has more privacy (which is the message not existing within Signal's log^). But currently people aren't given this choice and there is no consideration of failure modes.

^ Careful wording because if I don't make this added comment people think I'm unaware that screenshots exist.

Re: Telegram messaging app proves crucial to Belarus protests

#547
post #421

Earlier quoted context omitted.

I think you are mistaken. Before your text is sent to Signal your sender information is encrypted with the receiver's public key. So while Signal's servers can see who to deliver the message to they cannot see who sent it. Only the receiving client can decrypt and authenticate the message. This feature was rolled out in late 2018 and is called "sealed sender". It was developed to prevent leakage of any social network…

"So while Signal's servers can see who to deliver the message to they cannot see who sent it." Why can't they look at the TCP headers of incoming packets to determine source-IP? Also, why can't they look at session identifier or signal ID like phone number to determine who the sender is?

I assume if you are trying to hide your communications you aren't connecting directly to signals servers, so IP should get you nothing. There is no session identifier or signalID attached to your message, its contained within the encrypted part of the message so only the receiver can determine who the message was sent by. https://signal.org/blog/sealed-sender/

Re: Telegram messaging app proves crucial to Belarus protests

#548

Earlier quoted context omitted.

I disagree. I see my phone as an extension of my brain. If I have an in-person conversation, the other party can't force me to forget the conversation, and they shouldn't have that ability for my phone either.

What if only the other partys messages where deleted? In telegram it is understood that 'secret chats' constitutes confidentiality. As such, both parties, I believe, ought to be able to delete everything. I kind of see you point about non-secret chats. But then we are back with a opt-in model for privacy. Personally: what I tell you at the coffee machine, in confidence or not, is ephemeral. I would probably not talk…

> I kind of see you point about non-secret chats.

I don't really make that distinction, I think it's harmful to have E2E as optional, and only use platforms than have either mandatory E2E encryption (Signal, WhatsApp), or no E2E encryption (SMS, email).

If you have an in-person conversation with me in confidence, that doesn't grant you any additional powers to make me forget details of the conversation.

> Personally: what I tell you at the coffee machine, in confidence or not, is ephemeral. I would probably not talk to you at all if you where taperecording all conversations, as you want to do with messages...

What if I have a very good memory, and follow conversations by writing up their details in personal memos that you can't delete? (e.g. Comey's contemporary memos of conversations he had with Trump.)

> so I think both.parties.should be able to delete text conversations. And privacy should be on by default.

The problem for you is that I'm not going to agree to that - if you won't use Signal, I'm going to force a downgrade to SMS or email, and then you get even worse security and privacy.

If you want to have a conversation that can't be recorded in an automated way, you basically need to meet in a sauna.

Re: Telegram messaging app proves crucial to Belarus protests

#549

Earlier quoted context omitted.

What if only the other partys messages where deleted? In telegram it is understood that 'secret chats' constitutes confidentiality. As such, both parties, I believe, ought to be able to delete everything. I kind of see you point about non-secret chats. But then we are back with a opt-in model for privacy. Personally: what I tell you at the coffee machine, in confidence or not, is ephemeral. I would probably not talk…

> I kind of see you point about non-secret chats. I don't really make that distinction, I think it's harmful to have E2E as optional, and only use platforms than have either mandatory E2E encryption (Signal, WhatsApp), or no E2E encryption (SMS, email). If you have an in-person conversation with me in confidence, that doesn't grant you any additional powers to make me forget details of the conversation. > Personally:…

> If you won't use Signal, I'm going to force a downgrade to SMS or email, and then you get even worse security and privacy.

Or we will set up e2e encrypted telegram. Or not talk.

> What if I have a very good memory, and follow conversations by writing up their details

You saying that you remember I said something, even took a screenshot vs you can prove I said something, is a big difference.

If I am doing a snowden, I might go to a sauna. If I am planning to overthrow my boss, I think e2e telegram is okay. Because I can delete the conversation it might even be preferable to signal.

Use cases and threat models...

Re: Telegram messaging app proves crucial to Belarus protests

#550
post #544

Earlier quoted context omitted.

Last time I checked(and I might be wrong) Telegram did not support XMPP, has that changed?

No, but the person you were PGPing with would need to install something anyway. The thought that it might as well just be a separate client.

In the ideal scenario I'd be using Telegram as the transport for my messages, while PGP encrypting and signing all messages client side.
Post reply on HN