Live data from Hacker News

‘I will show you how safe Telegram is’

twitter.com

71–80 of 206 posts

Re: ‘I will show you how safe Telegram is’

#71
post #20

Earlier quoted context omitted.

The only thing worse than SMS-2FA is SMS-1FA, which I believe is Telegram‘s default.

Well, what is WhatsApps default then?

What does WhatsApp‘s authentication model have to do with whether Telegram‘s is secure or not?

Additionally, if you take over somebody‘s WhatsApp account, you can send and receive new messages in their name and very visibly kick them out of their account themselves.

With Telegram, the legitimate owner stays logged in (so you can see what they write and read in addition to sending your own messages), and you get their entire chat history on top of that.

Re: ‘I will show you how safe Telegram is’

#72

Earlier quoted context omitted.

Yes it is. It’s worse for Telegram though because it gives the attacker access to the chat history too. Telegram does however send a message to all devices when a new device is logging in, so at least you would know. Signal does not do that but your contacts will get a message that your security code changed if they have the option for that enabled, but people generally ignore this message. Both services offer to set…

> people generally ignore this message. Because it's noisy. You get that message whenever your conversation partner switches phones or re-installs Signal. The reaction on seeing that message is more "enjoy the new phone, what did you get?" than "have you been hacked?"

For most people, sure. If you're conspiring with others to protest against the oppressive Russian government, you may want to pay closer attention, though. You may even want to do physical verification of the keys.

Re: ‘I will show you how safe Telegram is’

#73
post #57

Earlier quoted context omitted.

I don't think anyone can whatsapp chat. Somehow, whats app is the most reliable end-to-end encrypted messaging service today and many just don't know.

WhatsApp is closed source. For what it's worth, the protocol itself might be impenetrable, but the client itself has access to your decrypted messages and can still decide to send them back to Facebook without your knowledge. The system that depends on a good will and "trust me bro" is not secure by default, even if Meta/Facebook were the most trustworthy company in the world under the most honest legislation.

Open vs. closed source is a completely moot point in the context of iOS and Android if your threat model includes vendor/supply chain attacks.

Re: ‘I will show you how safe Telegram is’

#74
post #54

Earlier quoted context omitted.

Not only that but they've made suspicious ties with the Kremlin that resulted in it being unblocked in Russia and have a mysterious source of funding after TON collapsed.

I'd love to hear more about this. I thought Pavel Durov (founder) isn't really welcome in Russia. He seems to have a left a lot of money on the table with his previous company (VK) to get out of there. The interpretation of events with telegram I've always heard has been that Russia tried to block telegram but doing so blocked most of the rest of useful services as telegram was hosted on e.g. AWS. This meant that rea…

https://www.wired.com/story/the-kremlin-has-entered-the-chat...

Re: ‘I will show you how safe Telegram is’

#75
post #33

Earlier quoted context omitted.

> Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. No, not really _hacked_. You give your phone unlocked to the police, and they access your Telegram account. You can't refuse, and you probably can imagine why.

https://www.wired.com/story/the-kremlin-has-entered-the-chat...

I actually wrote to Telegram’s support team to get more info about this, and it seems the article has a lot of errors. The support rep linked me to this, https://telegra.ph/Wired-Errors which is Telegram’s response to all of it.

Re: ‘I will show you how safe Telegram is’

#76
post #54

Earlier quoted context omitted.

telegram isn't e2e encrypted (unless you use secret chats which nobody does (and those do not support more than 2 participants))

Not only that but they've made suspicious ties with the Kremlin that resulted in it being unblocked in Russia and have a mysterious source of funding after TON collapsed.

Interesting. Where can we read more?

Re: ‘I will show you how safe Telegram is’

#77

I monitor Russian war channels and some people there insist on using Telegram only for Russian military people. If you use Whatsapp, Ukrainian officers will get all chats from NATO. Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. My takeaway is that for truly private chat one should write his own software using simple crypto without all those fancy clients. Ideally ju…

> My takeaway is that for truly private chat one should write his own software using simple crypto without all those fancy clients.

That‘s actually pretty secure in practice, because you won‘t be communicating with anybody.

> Ideally just use one time keys and xor everything.

How do you generate the keys? How do you share them? And you only care about encryption, authentication does not matter to you at all?

The chance of getting this right as an individual developer, especially given this level of understanding of cryptography, is next to zero.

Re: ‘I will show you how safe Telegram is’

#78
post #19

Earlier quoted context omitted.

Cool. But are they still closed-source?

How out of date are you? Both server and client apps have been on GitHub for half a decade.

Signal did notoriously not update their repositories for a while when they implemented their cryptocurrency scheme into the app.

If you're basing your trust on their open source software, you should also run a client you've compiled yourself (after auditing the code, of course).

Re: ‘I will show you how safe Telegram is’

#80
post #69
post #63

Earlier quoted context omitted.

1 GB?

The size is fairly irrelevant. 1 GB fits on a microSD card many times smaller than a Roman General's hand-written cypher.

True, but it can be copied and returned quickly without the victim knowing, and you have to trust every device you put that SD card into to read the pad.
Post reply on HN