5 ms·
Can we stop using 6-year-old info for apps that get updated monthly? The problems they have with MTProto have been patched literally 5 years ago, the only other
by ConsiderCrying 6y ago
Can we stop using 6-year-old info for apps that get updated monthly? The problems they have with MTProto have been patched literally 5 years ago, the only other criticism comes from a direct competitor, and they recommend WhatsApp despite the fact that it's closed-source and nobody can verify if its encryption truly works.
Facebook is planning to merge Messenger, WhatsApp and Instagram, which makes it even more awful of a choice.
- input_sh 6y agoFair point, but from my perspective, even if it was absolutely the best end-to-end encryption there is, it wouldn't mean much unless everyone's using Telegram for 1-to-1 communication using Secret Chats feature. > Some of its channels helped unconnected, scattered rallies mature into well-coordinated action. This line alone makes their encryption rather meaningless for this use case, since Secret Chats only work between two people.
- skyyler 6y agoWhich is why I'm confused people are even talking about their encryption in this thread. This has nothing to do with secure chats and everything to do with Telegram's Channels feature. But a ton of people that have never used Telegram nor read the article don't know that.
- sam_lowry_ 6y agoAnd proxies. Telegram has great proxy support and virtually anyone can install their own MTProxy in 5 min. A multitude of proxies, shadow optic cables over the border and a bit of whitelisting from the government to allow payment processing made Telegram invincible.
- maqp 6y agoWhere is their MTProxy tutorial?
- sam_lowry_ 6y agohttps://github.com/TelegramMessenger/MTProxy https://github.com/TelegramMessenger/MTProxy
- heinrich5991 6y agoTelegram still doesn't encrypt chats end to end (by default¹), which means it's not a strictly superior choice to WhatsApp. Facebook can't read your WhatsApp messages (of course they can add an update any time to do that), but Telegram has access to all your messages right now. ¹ Yes, you can select the end-to-end encrypted sessions, but they're very crippled from a usability perspective. I don't remember the last time anyone used it with me, yet all my chats on WhatsApp are end-to-end encrypted without anyone doing anything.
- Mediterraneo10 6y agoCan’t Facebook read most people’s WhatsApp messages because cloud backups of chats are enabled by default, and only the tiny minority of users who disable that feature will get truly end-to-end encryption?
- heinrich5991 6y agoNo, that's not true as far as I'm aware. The backup is to Google, not Facebook.
- ConsiderCrying 6y ago> Facebook can't read your WhatsApp messages Are we sure it can't? Because WhatsApp is closed-source, its GDrive backups are unencrypted and Facebook's whole profit model is based around snooping. Unless they make the app open-source, I'm not trusting them even with a grocery list. People act like E2E is the be-all and end-all but trusting an incredibly shady company on its word is not something I'm comfortable with.
- heinrich5991 6y agoYes, people are reverse engineering the app. You can check the discussions on HackerNews when security of WhatsApp is discussed. GDrive backups are not readable by Facebook, they're readable by Google. End-to-end, if properly implemented is the be-all and end-all. Except for metadata, which is a problem, but a different one, and Facebook definitely abuses that. But they don't/can't read the contents of chat messages (for now). It's not merely trusting that shady company, but also realizing that the news of FB not having E2E-encrypted messages would definitely make the news, you'd be aware of it.
- saagarjha 6y agoI don't see the problem of using a hand-rolled encryption algorithm or the strange choices that went into that algorithm as "patched literally 5 years ago".
- AsyncAwait 6y ago> The problems they have with MTProto have been patched literally 5 years ag Really? I haven't seen a single credible audit, nor a clear reason for rolling their own
- maqp 6y ago"Can we stop using 6-year-old info for apps that get updated monthly?" The fact Telegram's E2EE has not been available 1. by default 2. on desktop apps 3. for group messages for seven years tells you exactly how secure it is. "the only other criticism comes from a direct competitor" Fuck this attitude. Everyone has the right to criticize. If Telegram can't own their mistakes it's their fault, not that of the people who are beating them. Also, impartial professional cryptographers like Bruce Schneier and Matthew Green have told people not to use Telegram. Why is that if not because it's so horribly insecure. Why isn't there a single recommendation for Telegram from ANY cryptographer on the entire planet? "they recommend WhatsApp despite the fact that it's closed-source and nobody can verify if its encryption truly works." Because they've helped implement the encryption? Also if proprietary tools doing encryption are not secure, then why do Telegram users think it's ok for Telegram to use closed-source server that's doing the "distributed datacenter encryption" for group messages' at-rest protection. There's not even documentation available for this let alone source code.