2 ms·
> They do encrypt group messages to their servers, just not E2E. Transport-layer encryption that leaves messages totally readable to the service operator shoul
by CiPHPerCoder 9y ago
> They do encrypt group messages to their servers, just not E2E.
Transport-layer encryption that leaves messages totally readable to the service operator should not be classified as "they do encrypt". It muddies the water and will confuse users.
For the sake of communicating risk effectively, only E2E should count when we talk about encryption. Lack of transport-layer security (TLS, Noise, etc.) simply demonstrates severe negligence and/or incompetence.
> I'm not offering security advice.
Above you said:
> WhatsApp had a severe vulnerability for groups disclosed not so long ago. Telegram has had no such vulnerabilities as far as I'm aware.
A casual observer might read this and think, "Wow, WhatsApp is vulnerable and Telegram isn't. I should use Telegram" despite being even more at risk by choosing Telegram.
Whether it was your intention or not, it will have the same effect on HN readers as formal security advice from any other commenter.
- fwdpropaganda 9y ago> Transport-layer encryption that leaves messages totally readable to the service operator should not be classified as "they do encrypt". In that case, you should consider WhatsApp's group security issue as severe.
- CiPHPerCoder 9y agoI don't know how many different ways I can explain why this conclusion is false, but I suspect none of them would sink in. Maybe the question to your "true or false?" comment to 'tptacek will elucidate adequately why the worst case of the WhatsApp vulnerability is still miles above what Telegram offers in terms of privacy, and even aside from Telegram, would be most generously a sev:medium (but by most measurements a sev:low).