8 ms·
I don't know too much about Telegram but isn't it encrypted?
by mbowcutt 6y ago
I don't know too much about Telegram but isn't it encrypted?
- mauflows 6y agoI'm pretty sure Signal at least doesn't encrypt at rest on your phone. So the drive would have to be encrypted as well, which is not default on Android
- t0astbread 6y agoApart from that, regardless if you're on Signal or Telegram if authorities get hold of a protester's identity on such an app and have the power to access the app's servers they can gradually uncover social networks by reading metadata (if I'm not mistaken).
- voxic11 6y agoI think you are mistaken. Before your text is sent to Signal your sender information is encrypted with the receiver's public key. So while Signal's servers can see who to deliver the message to they cannot see who sent it. Only the receiving client can decrypt and authenticate the message. This feature was rolled out in late 2018 and is called "sealed sender". It was developed to prevent leakage of any social network information via the message metadata. But as far as I know Telegram has no equivalent feature.
- t0astbread 6y agoOh, that's nice! I didn't know that. Ammendment to my above statement: This does not apply to Signal.
- maqp 6y ago"So while Signal's servers can see who to deliver the message to they cannot see who sent it." Why can't they look at the TCP headers of incoming packets to determine source-IP? Also, why can't they look at session identifier or signal ID like phone number to determine who the sender is?
- voxic11 6y agoI assume if you are trying to hide your communications you aren't connecting directly to signals servers, so IP should get you nothing. There is no session identifier or signalID attached to your message, its contained within the encrypted part of the message so only the receiver can determine who the message was sent by. https://signal.org/blog/sealed-sender/ https://signal.org/blog/sealed-sender/
- seanieb 6y agoSignal is encrypted at rest. It uses a special encrypted version of Sqlite. https://www.zetetic.net/sqlcipher/ https://www.zetetic.net/sqlcipher/
- voxic11 6y agoSignal does encrypt your messages locally. Also Android supports file encryption you don't need to use full disk encryption anymore. Also I think the policy has changed in Android 10. > All compatible Android devices newly launching with Android Q are required to encrypt user data, with no exceptions.
- upofadown 6y agoSignal traditionally had an easy to get encryption key for the local encryption. Now there is a PIN but I don't think it is any protection against having access to the disk. The signal people would prefer that that you deal with the end point security yourself, because they really can't do much there.
- maqp 6y agoIndeed, the PIN is just for SVR. Exported message logs on Android use separate, client-generated, 30-digit, PINs. Unless the OS+HW provide API for some sort of TPM, it's not possible to provide strong protection for app databases without asking for strong password every time the app is opened. Android has had some sort of sandboxing for a while but it's not comparable to secure enclaves etc. AFAIK.
- boring_twenties 6y agoAndroid has encrypted storage by default since a few years ago. Of course, by default it uses a default key. But, the point is, enabling "encryption" just means changing that key, not reencrypting the entire device.
- polyomino 6y agoNot by default.
- dgellow 6y agoNot by default, no, because that has UX implications (e.g the chat will only be available on one on your device instead of being synced between all your devices). Though it’s quite easy to start an encrypted chat, and you can decide to have auto destructive messages.
- lol2143651 6y agoWell it's server software is closed-source, so you would never really know who has a backdoor. There are much better options than Telegram if you want real security. Signal for one.
- BelleOfTheBall 6y agoIt is encrypted by default but end-to-end is only for calls and Secret Chats (one-on-one). You can delete any message at any time without a trace for both sides, which protesters often do, really don't think the government needs messages to pin a crime on them. Hell, they've pinned crimes on people for literally no reason before.
- vel0city 6y agoSo when you try and go tell the other person's device to delete your message, how does it go into their iCloud backups and delete that message, or some other backup? Don't depend on asking someone else's device to delete the data as that data being gone.
- BelleOfTheBall 6y agoTelegram doesn't store messages on the device, you don't need to "tell the other person's device" anything, it's deleted from the Telegram cloud.
- throwaway8941 6y agoIt is stored locally, although only temporarily. I rarely connect my phone to the internet and still can scroll through quite a bit of message history.
- input_sh 6y agoBy default it's no more encrypted than HN (as in, traffic to their servers uses TLS, messages on the server are not encrypted at all). There's Secret Chats feature which they claim to be end-to-end encrypted, meaning that it's no more secure than Facebook's Messenger (also end-to-end encrypted in Secret Conversations). Even less so considering that they roll their own encryption (MTProto), while Facebook's Messenger uses Signal's protocol. Further info (which will also lead you to problems with their MTProto protocol, if you're interested): https://security.stackexchange.com/questions/49782/is-telegram-secure https://security.stackexchange.com/questions/49782/is-telegr...
- ConsiderCrying 6y agoCan we stop using 6-year-old info for apps that get updated monthly? The problems they have with MTProto have been patched literally 5 years ago, the only other criticism comes from a direct competitor, and they recommend WhatsApp despite the fact that it's closed-source and nobody can verify if its encryption truly works. Facebook is planning to merge Messenger, WhatsApp and Instagram, which makes it even more awful of a choice.
- input_sh 6y agoFair point, but from my perspective, even if it was absolutely the best end-to-end encryption there is, it wouldn't mean much unless everyone's using Telegram for 1-to-1 communication using Secret Chats feature. > Some of its channels helped unconnected, scattered rallies mature into well-coordinated action. This line alone makes their encryption rather meaningless for this use case, since Secret Chats only work between two people.
- skyyler 6y agoWhich is why I'm confused people are even talking about their encryption in this thread. This has nothing to do with secure chats and everything to do with Telegram's Channels feature. But a ton of people that have never used Telegram nor read the article don't know that.