3 ms·
> I don't really have the technical knowledge to evaluate it myself, and I suspect 99% of the people in HN are in the same position. Therefore, if I were to say
by CiPHPerCoder 9y ago
> I don't really have the technical knowledge to evaluate it myself, and I suspect 99% of the people in HN are in the same position. Therefore, if I were to say "Signal's security is excellent" I would be falling for the cult of Moxie myself, not an informed opinion.
Sure, but that's not what's happening when people whose day-to-day involve applied cryptography and/or application security are commenting on MTProto and Telegram.
Here's a good read on why Telegram's "contest", which is a challenge meant to create the illusion of resilience, is totally bogus in the context of real-world cryptography: http://www.cryptofails.com/post/70546720222/telegrams-cryptanalysis-contest http://www.cryptofails.com/post/70546720222/telegrams-crypta...
The things that the Signal Protocol does well:
1. It maximizes forward secrecy,
2. while working for mobile devices that may be offline or unreachable,
3. and uses authenticated encryption.
https://tonyarcieri.com/all-the-crypto-code-youve-ever-written-is-probably-broken https://tonyarcieri.com/all-the-crypto-code-youve-ever-writt...
https://paragonie.com/blog/2015/05/using-encryption-and-authentication-correctly https://paragonie.com/blog/2015/05/using-encryption-and-auth...
Disclaimer: The last link (the paragonie.com one) was my writing on the subject.