6 ms·
I really like Telegram. Only end-to-end encryption by default and in group chats would make it perfect.
by SimplyUnknown 7y ago
I really like Telegram. Only end-to-end encryption by default and in group chats would make it perfect.
- tptacek 7y ago"I really like Telegram. It being a secure messenger would make it perfect". I'm not really snarking at you; a lot of things would be better if they were also secure messengers; Slack is an obvious example.
- ApolloFortyNine 7y agoThey have end to end encryption available but off by default because it affects searching (they can't index your chat if they don't know what you said). Since your average users would be fine with this, it seems fair to have it as an optional feature.
- vinay427 7y agoSignal (the messenger) and Tutanota (for emails) both have search on their mobile clients with end-to-end encryption. It's definitely feasible to implement client-side search.
- izacus 7y agoSignal will also lose all your messaging history and kick you out of all your group conversations if your phone breaks or you lose it. It also has no usable automated backup solution or sync. It's also completely unable to work on multiple devices. Not really comparable in usability.
- interfixus 7y agoAlso, it will snark on you to all contacts whenever you move to a new device. And plead with you to let it handle your ordinary sms texting, then hold your text messages hostage, not exportable back to any other app.
- jjeaff 7y agoIt doesn't plead. It asks one time. At least on Android. I said no and it has never asked me again.
- interfixus 7y agoIt asked me a number of times. And it never warned that this was a oneway process.
- interfixus 7y agoIdle curiosity: The above is a report of fact as observed by me. It's not really up for discussion - this is what happened. Could someone for our edification explain a bit about the reasoning behing their downvotes? Other than my having sinned in the church of moxie and his true disciple tptacek.
- bigwavedave 7y agoDo you mean "nark"? "Snark" is when you use humor to pick at someone or something. "Narking" is being a tattle-tale.
- interfixus 7y agoYes, that was a late-night typo. Interested, although not surprised, to see my factually indisputable comment getting massively downvoted.
- bigwavedave 7y agoI've never understood the culture with that on HN. I probably never will.
- prophesi 7y agoI don't think OP was recommending Signal / Tutanota as alternative apps to use, just showing that you can have your cake (E2E encryption) and eat it too (client-side search).
- checktheorder 7y ago>Signal will also lose all your messaging history and kick you out of all your group conversations if your phone breaks or you lose it. It also has no usable automated backup solution or sync. Depending on one's threat model, this could be considered a feature.
- damnyou 7y agoIf your point is that only people with a Mossad threat model should use Signal, I wholeheartedly agree.
- checktheorder 7y agoOh, please. If Mossad really wants my messages, they're not going to give up at the "Oh no, he uses Signal!" step. They're going to go full knee-wrench if they have to. And considering they have a habit of forging my country's passports, don't pretend that me living in another country is a barrier to that. The same goes for my country's government. Our laws are chock-full of "throw him in jail until he gives up the password" allowances to law enforcement. And that's not even getting into the fact that Signal's owners, OWS, are located within the jurisdiction of the "we'll star-chamber NSL you on a moment's notice" US government. But Signal is perfect to stay private against non-nation-state actors. If I want to make sure that my ISP, mobile carrier, etc. can't snoop on my messages, Signal is my phone messenger of choice. Until and unless Facebook is demonstrated to not be on the level regarding Whatsapp's implementation of the Signal protocol, then I'll keep Whatsapp on the list as well. Telegram is not on that list. If my threat model consisted solely of "that guy with the manbun and macbook working on his novel in the coffeeshop", then maybe Telegram would be acceptable. Let me know when Telegram has default and mandatory end-to-end encryption, using a properly-implemented and proven-secure protocol like Signal's, on all clients both mobile and desktop. Until then I'll consider it to be about as secure as SMS - "hilariously not".
- zzzcpan 7y ago> properly-implemented and proven-secure You don't seem to realize this, but your argument is essentially "I trust Signal more", a purely authoritative one. And I don't think there even exists a threat model where anything that Signal offers over competition is important, especially given their obsession with control.
- saagarjha 7y agoThey could index chats locally…
- arkadiyt 7y agoThey have it available only for 1:1 chats and cryptographers have criticized their odd encryption scheme. They do not have it available for group chat at all, Telegram always has access to all group chat content.
- paxys 7y agoSlack does have E2E (from their perspective) encryption available, but it's the company paying for it that holds the keys, not individual employees.
- arkadiyt 7y agoCustomer managed keys are not the same thing as end-to-end encryption. With CMK Slack employees still have access to your message content and can still respond to subpoenas / FISA orders / national security letters / etc.
- stochastic_monk 7y agoIt’s secure but only if you choose it to be explicitly.
- scubbo 7y agoI'm not really sure what you're saying. It looks like you're humorously drawing attention to the fact that the user considers the app to be extremely good and just lacking one nice-to-have feature (encryption), whereas you believe that they have misjudged the importance of that feature and it is, in fact, essential?
- andai 7y agoYes.
- dlor 7y agoAnd, just to guess, he's also pointing out that security is not a feature that can be "bolted on" to a chat app later. Secure messaging is an incredible deep space, and any attempts to add security to a chat application will have far reaching implications on features and usability.
- eitland 7y agoUnlike WhatsApp that IIRC you've advertised until earlier this year Telegram doesn't upload unencrypted chat history to Google. Telegram has its issues, yes, but it would be nice if we could agree at some point that it is possible to discuss security outside the context of E2E encryption. > I'm not really snarking at you; Well I'll have to take your word for that but you have a long history of showing up on Telegram discussions.
- Fnoord 7y agoWhatsApp does not upload unencrypted chat history to Google for me. In fact, I don't even have a Google Account on my LineageOS device, so it can't upload to Google either...
- berns 7y agoIf you're using a custom ROM or rooted phone, your messages won't be protected with end-to-end encryption. https://faq.whatsapp.com/en/android/26000005/?category=5245235 https://faq.whatsapp.com/en/android/26000005/?category=52452...
- StavrosK 7y agoWait wait wait what? Does this mean they disable encryption, or just that the messages will be as "unprotected" as being affected with a key logger?
- gsich 7y agoIt's FUD.
- dodobirdlord 7y agoPresumably they expect the OS security primitives to work in a particular way, and since they can't rely on that from a rooted device they just don't bother.
- 7y ago
- merlinsbrain 7y agoThere’s a pretty clear distinction between slack and telegram - telegram offers a secure messenger channel with private messages. Slack does not do this, and publicly does not plan on doing this. The parent comment is requesting that an existing feature be switched on as default and not introduce a whole change in the communication layer of the app. Unfortunately you then lose syncing across devices, so I understand where telegram wants to make less secure the default.
- tazjin 7y agoThere's another clear distinction: Telegram has proper native clients and an open protocol.
- zenexer 7y agoAs someone who’s worked on Telegram clients for years, I can assure you that the protocol isn’t open. It’s quite opaque, and the FOSS thing is mostly a facade.
- Aloha 7y agoI mean the protocol is documented enough to create an implementation of it from scratch - that meets the metric of open. I suspect there is enough implementation there to write a server implementation too, at least a simple one.
- zenexer 7y agoI mean the protocol is documented enough to create an implementation of it from scratch It's not. If you want to write your own, you have to reverse engineer most of the protocol. The clients aren't fully open source, and when they are, the public code usually lags behind the actual binaries that are released, often by months. It's nearly impossible to write a client that keeps up with the features in Telegram. You may be thinking of the bot API documentation, which is documented. Many bots don't use that, though, as it's very limiting. I suspect there is enough implementation there to write a server implementation too, at least a simple one. The servers behave in very strange, unexpected ways, and the official clients expect these quirks. Most of the third-party clients either use TDLib, which is official and not fully open source, or have also grown to expect these quirks. Just as a quick example, pretty much everything in Telegram has a numeric ID. Clients, bots, etc. have come to expect that IDs within certain ranges represent certain objects--users have a range, private chats have a range, channels have a range. These ranges aren't documented and may not be obvious even in a fully open source client, but if you don't adhere to them, stuff will break.
- codedokode 7y agoSlack is an Electron app, taking about 400-500 Mb of memory and it won't be good no matter if it is secure or not. Also, its UI is over-complicated and looks like it was made by a programmer instead of a designer (by the way, Telegram is the opposite: it is written with Qt and has nicer UI).
- skinnymuch 7y agoSlack is only an electron app on desktops. It’s not just an electron app, at all.
- gsich 7y agoDesktop first is a sane assumption.
- mattnguyen 7y agoIf you use Telegram a lot, you should check out Telefuel.com. We're building Telefuel for power users and teams, and recently rolled out a feature to filter for unread messages. Might be useful for you!