11 ms·
Video Messages and Telescope on Telegram
- castratikron 9y agoWhat I thought was more interesting was the ability to send money to Telegram bots. Maybe they are trying to take on WeChat as the "everything" app.
- jnmandal 9y agoDefinitely. This is the biggest development of the recent release. They have one of the best bot APIs out there but bot developers have been waiting for this for 2 years.
- CiPHPerCoder 9y agoRegular reminder that Telegram's encryption protocol, MTProto, is not secure, and you should not ever rely on it for privacy. Use Signal or WhatsApp instead. https://eprint.iacr.org/2015/1177.pdf https://eprint.iacr.org/2015/1177.pdf http://www.cryptofails.com/post/70546720222/telegrams-cryptanalysis-contest http://www.cryptofails.com/post/70546720222/telegrams-crypta...
- gergles 9y agoRegular reminder that any time Telegram is mentioned on HN people pop out of the woodwork to launch a smear job against it because it isn't Signal. From 1: "We stress that this is a theoretical attack on the definition of security and we do not see any way of turning the attack into a full plaintext-recovery attack." The second paper is a huge wall of text that boils down to "the protocol is too hard to analyze and doesn't use what I have declared as crypto best practices, therefore I declare that it is insecure." There isn't, in either of these, any actual attacks showing any actual problems with the protocol. I'm really sick of people jumping down the throat of anyone who tries to use Telegram by declaring it as insecure without even the first whit of evidence. "This isn't best practice" != "This is insecure and you should never use it."
- roywiggins 9y agoWhen it comes to cryptography, I don't think the burden of proof is on the critics to prove it's insecure. Everything is best assumed to be insecure unless there's convincing evidence otherwise. I gather that there are enough experts in this sort of thing that aren't convinced that it seems fair to say it's insecure. Ex: If someone built a bridge, but wasn't an actual engineer, I would assume the bridge was unsafe. I don't need an engineer to actually inspect the bridge before I make that assumption, and I would probably tell everyone I knew not to use that bridge.
- reitanqild 9y agoWhen it comes to cryptography... then - like in a lot of other fields - it depends on your threat model. Point is: If your life or anything valuable really depends on provably strong encryption: you probably shouldn't use Telegram. My rule for WhatsApp (one of his recommendations) however is even simpler: I don't use it if I can avoid it.
- thewhitetulip 9y agoIt is highly ironic that those who careabout privacy suggest using whatsapp
- jolux 9y agoGranted, it's owned by Facebook, but it's definitely better than Telegram and unlike Signal people actually use it. I try to get people to use Signal when I can but so many people already use WhatsApp and that counts for something too.
- msl09 9y agoIt's not just because it's owned by facebook. It's also because it's closed source which means that the floor can be removed from under your feet when you least expect and they can weaken the security whenever they like to make way for whatever social feature they want. In theory telegram is insecure because it doesn't follow the best tried standards in security even though no viable attack have been made. In theory whatsapp is secure because the last time a third party audited the source code no gross infringements existed. Almost every chat app is insecure next to signal but indeed the only merit of whatsapp is that it's popular in some countries.
- reitanqild 9y agoRegular reminder that while CiPHPerCoder might very well be correct about MTProto - technically speaking - I find the recommendation to just use Whatsapp weird. Haven't we agreed that metadata is data? Isn't everyone aware that Facebook has stopped charging for WhatsApp? Has anyone presented a good reason for what their reasons for running WhatsApp for free? Because I doubt it's because of the goodness of Zuckerbergs heart. I.e. to spell it out: they find you metadata so valuable they are willing to spend billions (!) to get hold of them. Now I guess I wouldn't care much if it wasn't for the fact that WhatsApp used to be the fantastic. Nice, user friendly, robust and with a sane and user friendly way to generate income.
- CiPHPerCoder 9y ago> I find the recommendation to just use Whatsapp weird. For most WhatsApp users, the alternative to WhatsApp for most people is unencrypted SMS, which gives metadata and the contents of the communication to anyone with modest skill and a $50 budget. I like to think WhatsApp's use of the Signal protocol makes it preferable to SMS.
- thewhitetulip 9y agoSo you'd rather give y;ur metadata to whatsapp which gives it to facebook than use telegram because there is a little chance that you'd be hacked? Strange choice as far as I am concerned
- mullen 9y agoThe majority of people want privacy in their messages and are not really concerned with their metadata. Whatsapp fills that role and much better than telegram.
- thewhitetulip 9y agoWhat definitive proof do you have that Whatsapp does really use encryption? Facebook's word?
- kitsunesoba 9y ago>Use Signal or WhatsApp instead. I might if either of those had proper desktop clients (they don't). I spend most of my day sitting in front of a computer, so chat apps that offer only wonky web app "phone bridges" for desktop users don't make much sense for me. The best part of iMessage and Telegram is that their desktop clients are as capable as their mobile clients, and they're real independent clients. Until WhatsApp and Signal offer that, I have little interest in them. Maybe the majority of the internet connected world conducts their communication primarily through a smartphone, but that's not me.
- 45h34jh53k4j 9y agoSignal has a chrome app that performs as a desktop client.
- kitsunesoba 9y agoYes, it's one of the web app bridges I was referring to. It's tethered to your phone, ugly, and feels a lot like an afterthought. Last I checked, it also doesn't work with the iOS version of Signal, so if you use an iPhone you don't get any desktop support at all. In short, it needs a lot of work before it'll be usable for anybody in a similar position to myself.
- lorenzhs 9y agoIt's not tethered to your phone. It does work with the iOS version of Signal. It's really easy to set up, too. Everything in your comment is incorrect or out of date.
- kitsunesoba 9y agoIt's good that's changed, but that wasn't the case the last time I saw any kind of news about Signal (maybe a few months ago). It would serve them well to publicize these changes.
- 9y ago
- thewhitetulip 9y agoI'd rather use telegram and get blown than trust anything in the hands of Zuckerberg and Facebook. If the rumours are correct, NSA has a backdoor to both signal and whatsapp but when they have to hack telegram they use state telexom providers, get the password and access the telegram acc. Again, not sure. Just a rumour I heard
- CiPHPerCoder 9y ago> If the rumours are correct, NSA has a backdoor to both signal and whatsapp The rumors you heard are both wrong and stupid.
- jolux 9y agoProbably based off of that awful article in The Guardian at a guess.
- SpartanMindset 9y agoWhat makes them stupid and wrong? Can you with 100% certainty say WhatsApp isn't backdoored?
- tptacek 9y agoI don't even believe this is a real rumor. (It's obviously not true).
- skrowl 9y agoRegular reminder that Signal has had 0 messages ever provably decrypted and that Telegram has had 0 messages provably decrypted. All of the MTproto weaknesses are theoretical and have 0 working proof of concept attacks.
- Johnny_Brahms 9y agoWell, there was this glaring hole that let the server MITM secret chats on every key negotiation back when they were all cocky on HN. That was not theoretical at all, and very much something that could be used without detection, even if the users verified fingerprints, since it made clients create insecure keys. The guy who found it got their maximum bounty IIRC. Whereas the best attack on signal was somewhat sort of relay thing of very questionable usability to an attacker.
- jhasse 9y ago> That was not theoretical at all, and very much something that could be used without detection, even if the users verified fingerprints, since it made clients create insecure keys. It could have been done by Telegram. No proof it was. Still sound theoretical to me. I doubt they knew it was possible. Also: Was Telegram's source used to find the vulnability? If so, it's unfair to compare WhatsApp and Telegram like that. Also WhatsApp doesn't bait with a bounty like Telegram does (see https://www.linkedin.com/pulse/whatsapp-security-vulnerabilities-bug-bounty-osman-do%C4%9Fan https://www.linkedin.com/pulse/whatsapp-security-vulnerabili... for example).
- Johnny_Brahms 9y agoIt wasn't theoretical in the sense "this could potentially be a problem" as with most crypto vulnerabilities. We don't know that it was performed, but we know that the protocol was vulnerable, either because of malice or because their world champion programmers thought it was a good idea to let the server provide the client with entropy to create keys. I don't know which one is worse. There is also a pretty substantial branch of the computer security industry that thrives on security problems found in software they don't have the source code of. And good luck keeping up reviewing telegram. They release sources every 6 months. Last one was for 3.18 which had something like 170k additions and 90k deletions.
- krick 9y agoUsing a messenger bound to your phone number "for security" is funny any way you look at it.
- codedokode 9y agoWhy WhatsApp? It is closed source (Telegram has open source clients). It belongs to Facebook. And Zuckerberg doesn't look like a person who can stand against government, while Durov has been saying several times that he is not going to cooperate with any government. The disadvantage of Telegram is that it requires you to provide a phone number (and this is much more important than some rare cases when encryption could fail). It means you cannot stay anonymous while using it. If there is an error in Telegram server code then your phone number can be leaked. A messenger that cares about privacy should never require a phone number and should not have history enabled by default (because your history will be used against you as an evidence). As I understand WhatsApp doesn't match these requirements.
- skdotdan 9y agoAwesome update. By the way, any update on how are they planning to make money? It is still true that they don't plan to make money at all?
- reitanqild 9y agoI don't know but I would guess a natural place to make some money would be around the payments API that was also mentioned.
- GranPC 9y agoThey now have a donation bot, as a demo of their payment API.
- otalp 9y agoThey've stated that they have enough cash from Durov's funding to last 4-5 years comfortably, and that if they ever need cash, they will introduce non-essential paid features.
- otalp 9y agoTelegram is definitely the most feature-rich, customisable messaging app out there. The stuff you can do with it is amazing. Aside from having a true desktop client not dependant on your phone, I've set it up so that I receive my favourite comics(XKCD, Dilbert) when a new one releases. I can also see and delete my mail through another bot, and I can get sport scores too. The new instant view also opens up links immediately without loading times(Medium a few other sites only so far, but most major websites are apparently coming with the new update). It also allows you to quickly go to any date in a chat you've had with someone else(What did you talk about on 2nd June 2015?) and it has a self chat feature which is essentially an unlimited cloud service. Since you can upload files unto 1.5 GB, you can store links, photos, text and files in your self-chat, and have it available on all your devices.
- thewhitetulip 9y agoMay I know how to get xkcd on telegram?
- deleted 9y ago[deleted]
- giomasce 9y agohttp://lmgtfy.com/?q=xkcd+telegram http://lmgtfy.com/?q=xkcd+telegram
- lavezzi 9y agoI would imagine this would be through a personalised bot that you can create very easily through IFTTT or Zapier. https://core.telegram.org/bots https://core.telegram.org/bots
- skiman10 9y agoI use this channel to get xkcd comics on Telegram. https://t.me/xkcdchannel https://t.me/xkcdchannel
- sturmen 9y agoThe "Instant View for every site" update is here: it's part of the big 4.0 release. Basically you make a "template" to parse your site and Instant View will handle it. They're also crowdsourcing Instant View templates in, I must admit, a clever fashion.
- penetrarthur 9y agoIt's amazing how they entered the dense market of messaging apps and with superior UX, native clients and a bit of luck(brazil banning whatsapp for couple of days), they managed to get 100m MAU.
- jyrkesh 9y agoTotally. All crypto concerns aside--though I am on the side of the fence that says, while Signal is clearly superior, MTProto still hasn't really been cracked, and WhatsApp's server-side key reset is a bigger deal--the UX for Telegram's mobile (iOS AND Android) and Desktop clients (Windows, Mac, AND Linux) all kick ass. They're blazing fast, sync works phenomenally (except for secure chats, RIP), the ability to share arbitrary files up to 1500 MBs is awesome, Instant View is everything FB Instant Articles should have been, and the (admittedly gray-area copyright) stickers ROCK. My closest friends/family all use Telegram now because it's just better. When I want truly secure messaging, I use Signal or PGP