4 ms·
I, for one, shudder at the thought of Facebook getting my banking messages. Telegram has been a great alternative although it's not perfect.
by ENTP 11y ago
I, for one, shudder at the thought of Facebook getting my banking messages. Telegram has been a great alternative although it's not perfect.
- mcpherrinm 11y agoI'd be much more nervous about Telegram getting that data.
- ultramancool 11y agoIt's a toss up: - WhatsApp uses reputable cryptography from reputable sources, but combines it with a UI so much designed for ease of use that it throws out the possibility of real security - Telegram uses extremely questionable cryptography to begin with from people who probably shouldn't be designing cryptosystems If you want real security, go use Signal or better, OTR where socialist millionaire's is still an option for key verification.
- sayhar 11y ago> OTR where socialist millionaire's is still an option for key verification. Can you explain the socialist millionaire comment? I don't get it.
- 0xdada 11y agohttps://en.wikipedia.org/wiki/Socialist_millionaires https://en.wikipedia.org/wiki/Socialist_millionaires
- baghira 11y agohttps://en.wikipedia.org/wiki/Socialist_millionaires https://en.wikipedia.org/wiki/Socialist_millionaires
- ultramancool 11y agoOther people already linked the wikipedia article, but basically the thing it allows for is verification of a key without trust of it and provides effective proof you're not being MITM'd. I can ask a question or a series of questions to my friend and we can use zero knowledge proofs to determine we're talking about the same answer to verify his key without disclosing anything about that answer.
- jhasse 11y agoAlso WhatsApp is closed-source, but Telegram's client is open-source.
- free2rhyme214 11y agoNot everything with Telegram is open source like Signal. I still use Telegram because it's designed better and updated much more frequently.
- jhasse 11y agoI'm using both, too. :) But unfortunately I don't use Chrome, so I can't use Signal on my PC yet.
- Johnny_Brahms 11y agoThere are some FF-related pull requests on GitHub, but it seems that guy hasn't signed the contributor agreement. Maybe we'll get an FF-version soon.
- jhasse 11y agoWhy is a contributor agreement needed? Can you post the link to the PR?
- ex3ndr 11y agoTelegram is actually not open, they just throw some sources to github or as zip files at their's langing page. That's why i quit Telegram and built open source "Telegram" - https://actor.im https://actor.im and replaced spagetti-encryption with enhanced version of Signal's one.
- Johnny_Brahms 11y agoConsidering it is pretty much the gold standard for crypto, how did you enhance it?
- janpieterz 11y agoI've read up a while ago on the questionable cryptography (not an expert in that at all myself) but couldn't find a lot of actual substance. Certainly with claims [0] [1] being that Telegram offers nice sums for breaking it, which gives me as a consumer the idea that someone who actually knows this stuff would love to hit that down, if it was something in my area of expertise offering that I'd love to try and hit it. I get that it might all be some kind of cheat, but an actual cryptography researcher publishing that it is would, obviously, get a lot of bad karma going in the HN circles (for example) about these contests. [0] https://telegram.org/blog/winter-contest-ends https://telegram.org/blog/winter-contest-ends [1] https://telegram.org/blog/cryptocontest-ends https://telegram.org/blog/cryptocontest-ends
- ultramancool 11y agohttps://eprint.iacr.org/2015/1177.pdf https://eprint.iacr.org/2015/1177.pdf
- tptacek 11y agoWhat have you read about the questionable cryptography in Telegram that you found unpersuasive? That's a better starting point, because the formulation you use here is often used on message boards to bait people into doing research work that is then dismissed. Your comment includes an assertion that there aren't substantial complaints about Telegram's security (there very much are, BTW). I think the onus is on you to defend that argument.
- janpieterz 11y agoYou're absolutely right if my goal was to get people to post these papers, which reading back can easily be how it is interpreted. My point was more that, as a 'consumer' of this product without any background knowledge, their contests seem extremely convincing to the point of being slightly ridiculous. A 300,000 dollar bounty, while participants get quite some more access than they would normally get while attacking this system, gives me that feeling of it being actually quite secure, besides some possible attacks. If they're possible, if there are complaints, why can't they be made real and substantiated? My first post is indeed not delivering the message I intended, hope this one shows it better.
- maxerickson 11y agoDoesn't 'real security' quickly escalate to not having a cell phone at all? The best opsec advice for normal people seems to be not to op.
- ENTP 11y agoI wasn't advocating Telegram as an alternative transport for financial data. More that I'd rather use telegram for im than anything facebook owns.
- unsignedint 11y agoWhich reminds me of the announcement while ago about Whisper Systems is helping WhatsApp implementing E2E [0]. I don't think I've heard ever since about it, and not even sure if that functionality is built into WhatsApp now... [0]: https://whispersystems.org/blog/whatsapp/ https://whispersystems.org/blog/whatsapp/