4 ms·
It's not just because it's owned by facebook. It's also because it's closed source which means that the floor can be removed from under your feet when you least
by msl09 9y ago
It's not just because it's owned by facebook. It's also because it's closed source which means that the floor can be removed from under your feet when you least expect and they can weaken the security whenever they like to make way for whatever social feature they want.
In theory telegram is insecure because it doesn't follow the best tried standards in security even though no viable attack have been made.
In theory whatsapp is secure because the last time a third party audited the source code no gross infringements existed.
Almost every chat app is insecure next to signal but indeed the only merit of whatsapp is that it's popular in some countries.
- kasey_junk 9y ago> the only merit of whatsapp is that it's popular in some countries whatsapp has a fairly impressive set of merits that check lots of points for people who actually do security work: - uses a known and vetted protocol - protocol was implemented with help from known and competent security professionals - is supported by one of the most resourced and competent private security teams on the planet - is easy to drive uptake and has impressive network effects Its major drawback is that it shares metadata with facebook. This may or may not be a big deal to individual users, but on the balance its fairly easy to see why people recommend it. The closed source thing is largely not a consideration that comes up when you talk with professional security folks, and is a pretty obvious red herring when you think about it. [note: i'm not a security folk, but i have drinks with them occasionally. I don't use whatsapp or telegram and only very occasionally use signal]
- jolux 9y agoWhatsApp uses the Signal Protocol though and its implementation was overseen by Moxie Marlinspike, the creator of Signal. >even though no viable attack have been made. All of these references to "in theory" obscure what's actually going on here. Signal is well known to be extremely secure and the code is well-audited. Moxie is a man of integrity and says that WhatsApp is similarly safe. That's worth a lot more than the statement that no viable attack against Telegram has been demonstrated. That's true of every system until it's not. Once you reach that point, you've already failed. If that's the best proof you can give of a system's security, you've failed as a security communicator.