27 ms·
Telegram Isn't for Sale
- rkachowski 9y agoI haven't used telegram for a while, but the last time I used it e2e encryption was only an optional feature (secret conversation) instead of the default option. How does this compare to Signal or Whatsapp which both have e2e enabled by default?
- samat 9y agoThey have opted for user convinience on this matter. Fully searchable history of all communication synced on all your devices. A nightmare for a dissident attacked by state, but convinience 90% of the population should not be stripped of.
- slazaro 9y agoIs it technically impossible to have end to end encryption with full history, even synced? As long as you have the decryption key, you could have synced encrypted history, the best of both worlds, right?
- samat 9y agoConsider you’ve lost all your devices and logged in to a service. It either can decipher your history or it can’t. And if it can (which is convinient) - why have a e2e in the first place?
- drdaeman 9y agoRevoke the key, so the lost device won't be able to read the new messages. What the device already knows - it just can't be helped. This is irrelevant to E2E or even PFS. Basically, it's about message archive security - either it's leaked (and no amount of encryption and authentication would help) or not. E2E systems can sync message history - by mutually verifying device keys and then propagating data across such trusted links. I mean, if someone can send you a large file there is no reason one of your devices can't send a message to another your device, with a large encrypted blob of what it knows about the past. And if all devices (including possible server-kept archive private key derivation passphrase) are lost, then message history is gone.
- niij 9y ago>And if all devices (including possible server-kept archive private key derivation passphrase) are lost, then message history is gone. If a server can decrypt your messages, then it's not really E2E anymore, is it?
- drdaeman 9y agoI believe E2E means that data is encrypted and decrypted on endpoints and nothing else. It doesn't imply how the keys are produced or who else knows the keys. But I was thinking about a scheme, where the key is encrypted with a passphrase (that user's ought to remember) and kept on server. You fetch the blob, decrypt it (server can't), get the key and thus are able to decrypt the existing data (message archive). This lowers security, but adds a significant convenience of being able to recover history if the only device is broken or lost. Which may be important for casual users.
- shalmanese 9y agoIt's not technically impossible but it is tricky. Signal hasn't figured it out yet but a university research group has a fork of Signal that claims to support it in a privacy preserving way but it hasn't undergone a thorough security audit.
- Double_a_92 9y agoA good encryption doesn't let you decode old messages even if you know the key. That's to prevent "the enemy" from recording everything in the hope of getting the key someday.
- peterburkimsher 9y agoHe is getting "buy-in offers like those he's received from some of Silicon Valley's biggest names". I got one of those this week, and I'm very excited. I haven't yet chosen how to respond. Please discuss it at my Ask HN: https://news.ycombinator.com/item?id=15902196 https://news.ycombinator.com/item?id=15902196
- IBalic 9y ago> A lot of people in the western world don’t realize how much taxes limit their options. You can end up paying almost half your income in taxes, which basically means you’re working for the government for 180 days a year. I think I can find better ways to use the money I make for the benefit of society. ok, so he's basically suggesting to get of rid government. I respect different stands on the size/role of the government in society, but this is just a weak argument. What works out for him, won't work out for everybody.
- kaushikt 9y ago> ok, so he's basically suggesting to get of rid government Really doesn't feel like it.
- mrwong 9y agoTax burden in Germany for middleclass is at around 70%. Beeing a software engineer in germany means that you code 8months for the government and 4months for yourself. The western governments introduced more and more “hidden” taxes. So just looking at income tax is not fair. Just because he advocates for lower taxes doesn’t mean he want anarchy.
- fabian2k 9y agoYou're almost certainly including social security here, health care and retirement. This is not exactly a fair comparison, as in countries with lower tax burden you have to pay for those yourselves.
- aaronbrethorst 9y agoYou're implying that government does nothing—or at least nothing positive, which is a specious argument at best.
- _s 9y ago> Tax burden in Germany for middleclass is at around 70%. Beeing a software engineer in germany means that you code 8months for the government and 4months for yourself. > The western governments introduced more and more “hidden” taxes. So just looking at income tax is not fair. Please don't pluck figures like that out of thin air - I worked in Berlin as a developer and I easily took home ~60% of my monthly salary (placing tax at around 40%). Those taxes already comprise of Social Security* (roughly 20%) and income tax (the remainder 20%). * Health, Retirement, Unemployment etc.
- baybal2 9y agoFIY: While they claim being hounded back in Russia, and that they will be instantaneously jumped upon by 3 letter services if they were to run there, they were proven to have a huge office there as well as their main server infrastructure. Another red flag, is that they were never blocked in Russia. They look suspicious.
- eps 9y agoGot a source for the first claim? Second would've been a red flag if the Russian gvmnt would've been routinely blocking other chat systems.
- Terr_ 9y agoThe first claim? The "hounded by Russia" one? I'm not familiar with the story, but some quick searching reveals this: https://www.engadget.com/2017/10/16/telegram-fined-by-russian-court/ https://www.engadget.com/2017/10/16/telegram-fined-by-russia... The prime source seems to be founder Durov's social-media posts, retelling his communications to/from regulators.
- eps 9y agoNo, the OP's claim, not theirs. Re: a huge office & a server farm.
- baybal2 9y ago>Got a source for the first claim? Here: https://medium.com/@anton.rozenberg/pavel-durov-sued-senior-tech-lead-for-1-7-b24961dec503 https://medium.com/@anton.rozenberg/pavel-durov-sued-senior-...
- baybal2 9y agoIn the very end of the article, there are photos of the Telegraph LLC, the company behind Telegram, just a floor below the currently government owned VKontakte
- sitepodmatt 9y agocue ICO...
- yeukhon 9y ago> The locations of his servers are a secret, as are many of the names of his employees, several of whom he’s said are fellow millionaires. How is that possible? Are the servers behind an onion network?
- em3rgent0rdr 9y agoIf the locations of his servers are merely a secret, isn't that just security through obscurity? Isn't that a serious weakness? Or is there a more advanced way his servers are kept secret than merely being a secret?
- chrisper 9y agoI think it is against physical seizure and tampering. A good part of security against that is obscurity, don't you think?
- em3rgent0rdr 9y agoI wasn't just thinking about security against seizure or tampering of messages, but rather that since the servers could be taken down if discovered by a powerful adversary, then the network would no longer be functional. So it is not a very secure messaging tool to use if the threat model is to provide a reliable means of communication against a powerful adversary who could identify and take down the servers.
- simooooo 9y agoHow do you know the lack of location info is to stop you knowing if its distributed or not?
- jperry 9y agoWhy would you assume it's "just security though obscurity" and not "security plus obscurity"? Or that "obscurity"" as a security measure is a tragic weakness. This is a trap a lot of people fall into and I don't know why.
- thisisit 9y ago>He sees Telegram as a charity that he’ll start to monetize early next year, but only enough to fund expansion. Charity and monetization don't go hand in hand.
- simonbarker87 9y agoYeah they do, charities are just businesses that don’t distribute profits to share holders. Making money or not has nothing to do with charity status - it’s about what you do with the profits.
- randomThoughts9 9y agoThis is a very recent interpretation. It is legally true, but it goes against the true meaning of the word. When you work for a charity, do you ask for a raise? Do you get a bonus if you collect more money? How much to you get to keep? Not even mentioning that sometimes the money goes through a chain of charities, all making a living out of it, but leaving almost nothing for the final beneficiary.
- HatchedLake721 9y agoFor you - https://www.ted.com/talks/dan_pallotta_the_way_we_think_about_charity_is_dead_wrong/up-next https://www.ted.com/talks/dan_pallotta_the_way_we_think_abou...
- simonbarker87 9y agoSalaries are an operating cost and have nothing to do with the disbursement of profits. Some people at charities are very well paid but that has nothing to do with the charitable status.
- askafriend 9y agoAlmost all charity orgs have operational expenses...
- 9y ago
- b3lvedere 9y agoI'm still not sure which one is better: Signal or Telegram.
- borski 9y agoSignal. Peer reviewed and open source crypto on both client and server.
- samat 9y agoDepends on yours needs. If you need top level security - you use Signal. If speed and stability and features are of more importance - use telegram.
- omnimus 9y agoSignal. Telegram is a business run by a millionare who is having fun. Signal is run by well known security expert / activist and his very transparent company Open Whisper systems. The way Signal tackles the problems is smart gradual development and they are the closest to making the holy grail - e2e encryption without users even noticing it. There are no "secure" and "not secure" messages in signal - it is all encrypted and you can't turn it off. That's awesome.
- Mithaldu 9y agoYou're making the mistake of assuming "better" is a single vector. Signal is more secure, yes. However its UI, UX, accessibility, feature sets and performance are absolutely in baby shoes.
- Veratyr 9y agoNeither. Both require tying your identity to a phone number. You're better off with Matrix/Riot or XMPP. Neither requires a phone number, both offer the ability to communicate securely, even with a compromised server. Both also support multiple devices, group chats and federation.
- b3lvedere 9y agoAccording to Signal's FAQ: Signal periodically sends truncated cryptographically hashed phone numbers for contact discovery. Names are never transmitted, and the information is not stored on the servers. The server responds with the contacts that are Signal users and then immediately discards this information. Your phone now knows which of your contacts is a Signal user and notifies you if your contact just started using Signal. However; I don't know if their server is peer-reviewed on a regulary basis, nor do i know if the software (besides the used ciphers) is also peer-reviewed. Can't find anything on it.
- buovjaga 9y ago> Telegram, which is open-sourced The server-side code is not open.
- samat 9y agoAnd mobile app repos are not updated regularly, too.
- Aoyagi 9y agoWell, I wouldn't trust Telegram with something really secret and/or sensitive, but as an every day IM/calling client, it sure got even more sympathy from me by this.
- alien2003 9y agoTelegram is FSB's spyware. Their main office is in St. Petersburg and telegrams are still not blocked in Russia but in Russian television they always talk about ducking crazy super duper Telegram security and how difficult is to beat for FSB