4 ms·
> Broken crypto ("bunch of randoms have rolled their own crypto", to be precise [0]) is pretty much the only argument HN has against Telegram. Also that there'
by ikawe 6y ago
> Broken crypto ("bunch of randoms have rolled their own crypto", to be precise [0]) is pretty much the only argument HN has against Telegram.
Also that there's no crypto for every group chat and every default 1:1 chat.
- wyuenho 6y agoDefault 1:1 chat and group chat are secured by the server-client protocol. No e2e encryption by default is deliberate https://telegram.org/faq#q-why-not-just-make-all-chats-39secret-39 https://telegram.org/faq#q-why-not-just-make-all-chats-39sec...
- bjoli 6y agoWell, anyone releasing a serious communication app in the last 11 years that didn't do at least that should have been flogged...
- wyuenho 6y agoI disagree with this. A point the FAQ didn't mention is user psychology. Technically, the correct way to use e2ee chat on both Signal and Telegram is to verify the key fingerprint using a secure channel separate from Telegram. In reality, few people do it, so the default makes a huge difference. If all of my Signal chats are e2ee by default, and I operate under the assumption that most if not all of my chats are encrypted and secure by default, when a chat that really needs to be secured comes in, I wouldn't think of verifying the fingerprint in a separate channel first, because Signal didn't train me to do so. If it did, Signal would have been a lot more annoying to use, because it'll have to pop up warnings and all that. Enabling e2ee in Telegram is an explicit act, which means that what that mean is enabled, I know for sure I need to make sure it's really secure, and it will trigger my memory about verifying fingerprints. I would argue this trains the user to think more about operational security instead of just theoretical information security. As far as I can understand, Telegram's secrecy by default is __good enough__. They control all of their data centers and internal networks, and they have been known to refuse to comply with government orders. Given that I continue to use Apple and Google services with similar or lessor guarantees, I consider that good enough, and I'll choose my messaging app based on secondary factors such as usability and features. Telegram wins hands down in these areas.
- hiq 6y agoA lot of users just think that Telegram is E2EE by default. I really don't see why a user would make a conscious choice to activate E2EE on Telegram but not verify the fingerprints on Signal. In both cases a manual step is involved. As others have pointed out, there's no good reason to have no E2EE by default in 2020. Signal also protects against a whole lot of passive attacks (e.g. bulk collection), which Telegram doesn't. Any vulnerability in Telegram's servers and all your chat history is made public. I don't know how Signal secures their servers, and I don't have to care. Security-wise there's no good reason to use Telegram vs Signal.
- wyuenho 6y agoThere sure are many technical reasons to not have e2ee by default. In Signal, at least as recently as in August, you may still get messages from the group you just quit if a member send a message to the group before the group metadata is reconciled. This happens because every group message is an e2ee message to every other group member. If you have signed in from two devices, disappearing messages that have disappeared on one device will still show up on another. This happens because the server cannot store or sync the states of two sessions participating in the same chat. Signal is full of little distributed system data consistency bugs that you just wouldn't expect in traditional client-server model application.
- bjoli 6y agoI'd argue that no-one having access to my messages should be the default case. The fact that a government could potentially get access to all unencrypted telegram messages sent by everyone is pretty off-putting. If they want my signal messages they would have to hack my phone, or MITM me and face potential discovery since verification status is unknown to the server. And that would only get them access to messages sent from thereon. I understand your argument about the marketing and UI blurring the definitions, but I disagree on the fundamental issue. My messages should be readable only to me and whomever I sent them to.
- ikawe 6y agoYes... just like this message I'm typing into hacker news right now is client-server encrypted. Having any trouble reading it? If your point is that telegram is no more private than a public message forum like, well then OK. But I think that's at odds with the "only problem is hand rolled crypto" comment I was replying to.
- wyuenho 6y agoThen you may be very disappointed to learn that most of the Internet, I'd wager >90% of it, is, in fact, unencrypted by your definition.
- ffpip 6y agoThe reasons given by them are reasonable. Whatsapp ain't e2ee since all chats are backed to google drive and iCloud. I'd rather Telegram be able to read my chats with a way I can control, that use whatsapp and feed all my messages into google drive with no way for me to control my contact's backup settings. Durov has answered this multiple times. He even explained it yesterday. https://t.me/durovschat/527081 https://t.me/durovschat/527081
- RaitoBezarius 6y agoIt is such a shame that we have, in 2021, no way to perform secure computations in untrusted environment. Signal at least had the decency to try for Secure Value Recovery even if Intel SGX as a technology is not really mature. So, what is the Telegram excuse for not being able to put the same amount of effort? That sounds dubious to say it is reasonable when in fact it is only the very bare minimum that everyone does. As a matter of fact, trusted computing is a very active and practical field as far as I know.
- hiq 6y ago> The reasons given by them are reasonable. Whatsapp ain't e2ee since all chats are backed to google drive and iCloud. That's up to the user, I've never backed up my WA data to any cloud service.
- sudosysgen 6y agoDo you make sure that in group chats no one there ever enables it by accident? Because it's really, really easy to inadvertently do. Telegram's UX is better for security. You know when you can expect difference levels of security, and the best that can be done is just as good if not better.
- hiq 6y ago> Do you make sure that in group chats no one there ever enables it by accident? Because it's really, really easy to inadvertently do. Fair comment. Still, at that point, you're trusting a third party just like in Telegram case. In any case, if anything, the default settings in WA are closer to an ideal E2EE than Telegram.
- tinus_hn 6y agoSo you can be 100% sure Russia gets a copy of every message you send.
- ffpip 6y agoThey have been banned for not giving the messages to Russia. How can be be so confident that Russia gets copies of the messages. https://en.wikipedia.org/wiki/Blocking_Telegram_in_Russia https://en.wikipedia.org/wiki/Blocking_Telegram_in_Russia Please don't post such accusations without sources.