4 ms·
Ask HN: Why do you avoid Telegram, arguably one of the best cloud messengers?
- zapttt 6y agoRussia.
- HelenePhisher 6y agoNo end-to-end encryption per default, and if I activate it I’m not able to see the conversation on other devices. Signal does that better.
- vpEfljFL 6y ago- end-to-end encryption - able to see the conversation on other devices You can choose only one. Otherwise I can't see how it would be end-to-end encrypted. Your devices should create some sort of a group chat to make this work. Group chats have large enough attack surface and "end-to-end encryption" will create false sense of security.
- detaro 6y agoOther products manage, so it's clearly not a case of "You can choose only one".
- HelenePhisher 6y agoI use Signal on multiple desktops. It's a good experience and really works well. I can choose both.
- vpEfljFL 6y agoIn general there is a simple rule: either usability or security. All general consumer grade tools are fighting with this equation: How can we make an app which will appeal to the broad audience which will be easy to use. I can't say anything about signal but in general if something is easy to use and you can chat super secure with your grandma then most likely it isn't secure how you might think it is and it's actually an issue because you may want to send data which otherwise you wouldn't if you know you're on compromised channel. Sharing history between e2e encrypted devices is a tricky thing because you should have forward security with some ratchet keys.
- vekker 6y agoHuh, why? If you have the same private key on your devices, you can do E2E encryption on the same conversation on multiple devices, no?
- sdwolfz 6y agoSignal has end-to-end encryption and you are able to see the conversation on other devices from the point you link your devices. What it does not have is the ability to send your conversation history to your linked devices (which I find a bit odd, if you can trust a device with your present/future conversations, you should be able to trust it with your past, or at least be able to opt in in trusting it with sending over your past conversations). I hope they will provide this in the future.
- kdtsh 6y agoAll you need is for the two instances of the app to use separate sets of key pairs, where the keys have been generated on the device itself and the private keys never leave the devices, to share the private key for the conversation between the two devices. I don't know if Signal or any other app does this, but it's 100% conceptually possible.
- stereotactic 6y agoHow does end to end encryption make that better? I am genuinely curious. Is your threat model too severe that you really need to hide your conversations?
- HelenePhisher 6y agoI don’t want to discuss the reasons for encrypted communication, sorry. Citizenfour was a good movie though.
- vpEfljFL 6y agoCould you please "open source" all your conversations to provide ground for reasoning "I have nothing to hide". So, and we can discuss threat models. Thank you.
- stereotactic 6y agoI don't mind; in public groups its for everyone to see. Snooping by the government or by the corporations? Which one is more insidious?
- fsflover 6y agoI would prefer to have none, hence e2e encryption.
- m-p-3 6y agoHigh expectations of privacy. I prefer to hide everything, even mundane stuff, than wished I had and I didn't.
- hncensorsnonpc 6y agoWhy is this utterly stupid question coming up again and again? Go ask your peers/yourself why feel the need to share all of your conversations with the government and other 3rd parties who in the best case just want to sell you shit.
- cpach 6y agoI use Whatsapp, Messenger and iMessage. Simply because they are convenient and there I can reach ~95% of my friends.
- deleted 6y ago[deleted]
- jedieaston 6y agoI don't know anyone who uses Telegram. Everyone I talk to uses SMS/iMessage, or maybe Discord (but that's a pain in the butt for individuals).
- stevekemp 6y agoI recently signed up to an online course at Helsinki Open University, there is an online message-board for students (empty) and a Telegram group for the users of the course which has 350+ members. This is the only real time I've used telegram. Mostly people that I know here in Helsinki, Finland, use WhatsApp (friends, neighborhood kids-group, etc), or facebook messenger (pottery teacher, local companies).
- sdwolfz 6y agoI avoid everything else apart from Signal (this includes Telegram) because with Signal I trust that they have: - end-to-end encryption enabled by default, and as far as I know there is no possible way to disable this even if I wanted to. - no logs/state stored server side, or at least that's what they claimed. - no SPAM. The only people that talk to me on signal are the ones I actually intend to talk to. Not sure if this is just because so few people use Signal or because they don't have a chat-bot API they try to push as a commercial offer. - a non-profit organization structure, not that being a for-profit is bad, but I tend to trust non-profits more when it comes to things like respecting privacy as a core value of their business (a for-profit would scrap that and abuse their market share at the snap of a shareholder finger).
- sebastianconcpt 6y agoI'd agree with all that. An in the past I'd also tend to like non-profits more until I've realized that these are as vulnerable as a for-profit in terms of ideological contamination.
- Zenbit_UX 6y agoI don't. Why do you think people avoid it?
- throwaway6575 6y agoBecause moxie told me it's bad since it doesn't use secret chats by default. All the features in the world that no other messenger remotely approaches still don't make it usable when you actually have to manually toggle a button to start a secret chat with someone. The horror!
- j749342 6y agotheir encryption is closed source. If we don't know exactly how Telegram works at it's core, any encryption it might have is almost worthless IMHO. Signal and Keybase FTW