5 ms·
I would normally opt for Signal because it's open source. This is inherently more trustworthy. The fact that so many authoritarian governments ban/are hostile
by s_dev 6y ago
I would normally opt for Signal because it's open source. This is inherently more trustworthy.
The fact that so many authoritarian governments ban/are hostile to Telegram suggests they actually do have some integrity.
- jdu9 6y agoYour comment is misleading: Telegram is open source (Desktop, iOS, Android), but the server isn't. It would certainly be nice to run your own Telegram server, sure. IMHO the only good argument against Telegram is that direct messages don't use end-to-end encryption by default.
- input_sh 6y ago...except Telegram X, their alternative Android client. > IMHO the only good argument against Telegram is that direct messages don't use end-to-end encryption by default. I'd add two more: 1. End-to-end encryption being device-specific. Example: if you start a secret chat from your phone, you can't view it on your other devices. Other end-to-end encrypted solutions don't have this drawback. 2. End-to-end encryption being available only in one-to-one communications. Take this with a grain of salt, but I don't think it's available at all in group chats and channels.
- leetcrew 6y agotaken individually, these all seem like minor nitpicks. but together, they make for a pretty high-friction E2E experience on telegram. the first time I try to have a "secret chat" with someone, it's often the first time they realize that telegram isn't E2E by default or that it even has that feature! I have to wonder about the design decisions made here. it seems pretty obvious that the combination of limitations is going to result in the vast majority of messages not being E2E. in practice, "secret chat" on telegram is only worth the trouble when both participants understand they are doing something shady.
- vbezhenar 6y agoFor me device-limited E2E is actually a feature as I'm sure that no kind of weird sync stuff will leak my data from the device.
- eznzt 6y agoAlso, E2E chats are not available on the desktop version of Telegram.
- deleted 6y ago[deleted]
- ffpip 6y agoTelegram X is made by a different unofficial dev. Telegram has an open API. You can build your own clients.
- input_sh 6y agoIt's published by Telegram LLC on Google Play. Can't be more official than Telegram itself distributing it.
- ffpip 6y agoTelegram's official dev account is 'Telegram FZ-LLC'. https://play.google.com/store/apps/developer?id=Telegram+FZ-LLC https://play.google.com/store/apps/developer?id=Telegram+FZ-... Telegram X is not the official version.It is an unofficial client for testing design and app speed. It has a different UI
- ivanbakel 6y agoIn what way is the comment misleading? While "Telegram" might refer to "the Telegram app" or "the Telegram service", when talking about open-source, it nearly always refers to the service. Of the two, the source of the central server is arguably much more important, since it's possible to at least track if the app tries to exfiltrate any data.
- eznzt 6y agoThe source of the central server is useless since if they release it there is no way to prove they are running the same software on their servers.
- ivanbakel 6y agoThe source isn't "useless", it allows you to run your own server.
- romwell 6y agoYeah, and then you need to modify the client to use that server, have everyone you communicate with install that client, and also not brand it as "Signal" because it has nothing to do with the Signal network anymore, and you can't communicate with "regular" Signal users. So, from the point of view of anyone using the Signal service, the utility of the source is near-useless.
- NateEag 6y agoSignal has a fascinating blog post from 2017 about how to use Intel's Software Guard Extensions (SGX) to actually let clients confirm that the software they're communicating with is the exact version they expect it to be. https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/ SGX is definitely not bulletproof (https://medium.com/@maniacbolts/signal-increases-their-reliance-on-sgx-f46378f336d3 https://medium.com/@maniacbolts/signal-increases-their-relia...), but it exists to do exactly this job, and Signal is using it.
- leetcrew 6y ago
- jjones2 6y agoI wouldn't trust Signal for the sole fact that the USG promotes its use. Think CryptoAG and how hostile Swiss law is to data privacy. Kids seem to think just because they were once known for banking secrecy doesn't mean they treat data the same way (they don't).
- Craighead 6y ago"Kids" know what works for USG will work for them
- junon 6y agoNevermind that Signal is entirely open source and has been openly audited several times. Lol.
- Frondo 6y agoAs others have pointed out, we users of Signal have no way of verifying that the code running on the server we connect to is the code they've released. We are very much trusting the Signal team to do what they're saying (not logging, not leaking) and to make no mistakes in doing it (not logging accidentally, not leaking accidentally). Which is in general a fair trade-off, but it is very much a trade-off, open audits notwithstanding.
- junon 6y agoWhere does Signal prevent you from using your own server? Spin up your own and use it if you'd like. https://github.com/signalapp/Signal-Server https://github.com/signalapp/Signal-Server
- NateEag 6y agoAs I pointed out elsewhere in the thread, Signal uses SGX to let clients confirm exactly what version of the contact discovery server software they're running against: https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/ It's not bulletproof by any means (https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/ goes into this, and also points out several features they've used SGX for since), but it's certainly something, and they're doing it.
- marianov 6y agoWhat makes opposition movements adopt telegram? What's the key feature that makes them adopt it instead of WhatsApp or Signal? People are not crypto nerds by default, so there must be a simpler answer.
- boomboomsubban 6y agoThere isn't necessarily am answer at all. As these people aren't cryotonerds they likely just use the first one their associates use. Telegram was one of the earliest e2e encrypted chats to gain some notoriety as a means to avoid surveillance, and the publicity from that and countries banning it provide advertising others lack.
- Canada 6y agoThink of it like a big public message forum. Technically it works like one: You post messages and they're stored on the server and served up to everyone else at any point in the future. It's perfect for coordinating big groups of strangers. It has a good reputation for refusing to kick people off when governments demand it. Although accounts are tied to phone numbers it doesn't show them by default and users can choose a unique username, so unlike WhatsApp or Signal it's easy to recognize the pseudo anonymous identity of people you don't know. It's much easier for many people to use than Twitter. When running an opposition movement it doesn't matter if there's no encryption. Since you are open to the public your adversaries are going to be in your groups anyway. Another bonus is that most of your followers aren't already using it, which makes them more free to act. If a different messenger is popular in your country you might not want to tie the long held account that everyone in real life knows you as to your freedom fighting activity.
- agumonkey 6y agoOr is it just a matter of market share ? lots of people use telegram, it's encrypted, 'strict' government decides to block it because they don't know much else about the field. Let's see how long until they hear about signal