8 ms·
Telegram is anything but secure; even Facebook is safer, says Signal founder
- shagunsodhani 5y agoTweet thread from Signal's founder (that touches on some topics in the article) https://twitter.com/moxie/status/1474067549574688768 https://twitter.com/moxie/status/1474067549574688768
- johnisgood 5y agoOf which there is a submission on HN. See my other comment. :)
- cryptpal 5y agoRead why is Marlinspike wrong. https://threej.in/article/Signal-founder-criticizes-Telegram-and-compares-it-with-facebooks-messenger https://threej.in/article/Signal-founder-criticizes-Telegram...
- johnisgood 5y agoRelated: https://news.ycombinator.com/item?id=29665494 https://news.ycombinator.com/item?id=29665494
- hammyhavoc 5y agoGive me Matrix protocol or death.
- egberts1 5y agoI have not yet begun to IM!
- 3np 5y agoEither that or XMPP.
- paulryanrogers 5y agoDoes Matrix have consistent E2E yet? Or is it still leaking for some resources and features?
- ViViDboarder 5y agoSenders and recipients aren’t encrypted on Matrix, are they? As I understand it, Matrix is a great chat product, but it’s not targeting the same use case.
- deleted 5y ago[deleted]
- selfhoster11 5y agoOf course he'd say that, having have a great many questionable decisions around Signal. Honestly I'm inclined to treat this as FUD until the same points are raised by someone with a more impartial (or at the very least, fair) expertise.
- johnisgood 5y agoI have many comments about Telegram and how not-so-secure it is. Again, it does not have E2EE on desktop.[1] This secret chat is only for 1 on 1 conversations (IIRC), and it is not the default. I cannot comment on their E2EE because they may have changed it by now. Telegram is fancy, it is a great replacement for WhatsApp, but it cannot replace Element, Conversations/Gajim (XMPP), Briar, Ricochet, or Wire. Please avoid Telegram for actually "secure chats". I recommend checking out https://secushare.org/comparison https://secushare.org/comparison. I disagree with "Telegram can be among the least worse [for smartphones]" though. It is Briar. I have also used Briar on desktop, I wonder where that will go. [1] https://tsf.telegram.org/manuals/e2ee-simple#2-why-are-there-no-secret-chats-on-desktop-apps https://tsf.telegram.org/manuals/e2ee-simple#2-why-are-there...
- 3np 5y agoYou’re right to be wary of Signal. Here, Moxie is spot on, though. Everything he’s saying is based on public information. There’s no FUD and nothing new under the sun. Telegram is spyware wrapped in clever marketing and branding.
- ViViDboarder 5y agoThe issue with Telegram has been brought up many times by many people. It defaults to insecure and is advertised as “encrypted messaging”. It’s a great messaging tool that offers one way to send e2ee chats, but the default is not and group chats aren’t. The comparison to Facebook messenger is apt.
- DarylZero 5y agoSignal is just as insecure because they can push any code they want to anyone they want to spy on.
- tablespoon 5y ago> Signal is just as insecure because they can push any code they want to anyone they want to spy on. What now? That's not "just as insecure", since Telegram can also "push any code they want to anyone they want to spy on," but they don't need to because your data is already plaintext on their servers. Signal not being perfectly secure does not make it "just as insecure."
- DarylZero 5y agoI mean, if you were at all serious about security you'd just not use it. So it's just as insecure.
- Barrin92 5y agoThis is a bizarre take. What's considered "serious security" depends on the needs of the person and the kind of info they're transmitting. To tell people that there is no advantage to use Signal instead of much less secure alternatives because your Area 51 security requirements aren't met is actively harmful and bad advice.
- DarylZero 5y agoLOL, "Area 51." Whether Signal or Telegram, you rely completely on trust in the central third party for security. The choice of whether to use Signal or Telegram should depend on which of these organizations you trust the most (their leadership, their internal employees, and their security from external infiltration), NOT based on what technology they use in the client & server. But you simply shouldn't use either because real security is all about not having to trust anyone like that.
- 5y ago
- charlieyu1 5y agoTelegram is a big no. Leaking phone numbers just by joining a group. Hong Kong police had arrested so many protesters through Telegram channels in 2019.
- sorenjan 5y agoThat was fixed years ago.
- emptysongglass 5y ago
- 3np 5y agoOn 2), just because the FBI can’t just ask for the data doesn’t mean other threat actors don’t have and can’t get readily-available access. I’d also consider the possibility that the document is planted and not fully accurate.
- emptysongglass 5y ago> I’d also consider the possibility that the document is planted and not fully accurate. It's this kind of extreme paranoia that taints the entire world of populist secure messaging products, which actively drives me straight in the other direction. I'm not a state target. But I do use Telegram's Secret Chats for things like discussing how great a trip into the woods on psychedelics can be. That's a great compromise, for me, and most others who use the platform. If you're a state target or you entertain such ideas as state actors trying to get your cat photos, please use another platform. But there's zero need for this kind of mud-slinging that goes on, all the time, within the world of secure messaging products and platforms. The guy behind GrapheneOS does it, Moxie does it, the entire Signal fanbase does it, even going so far as to apologize for when a piece of their beloved product goes closed source for a year so Moxie can insert some terrible crypto coin he's a major investor of.
- ViViDboarder 5y ago> Messages sent through Telegram are stored on Telegram's servers in their original form, or plain text, without going any sort of encryption to protect private user data, shared Marlinspike. It is not disingenuous to call data stored in plain text as stored in plain text. Transport security is very different from security at rest. > Here is the FBI's own datasheet on what message content they're able to obtain with court order from Telegram [2] Keep in mind that there are other governments with jurisdiction over Telegram that may have access. Additionally, data could be “leaked” by someone. Or, rules or owners of the data could change. Just because they don’t respond to a warrant doesn’t mean that data is safe when stored in plain text.
- sorenjan 5y agoNot everything needs to be super secure. I can sit and talk with a group of friends at a cafe, and anyone can listen to us, and see that we're talking to each other. If we want to talk about something secret we can go somewhere private that's less convinient but more secure. Same thing with messaging online. Everyday nonsense can use whatever app you want, and if there's something you really don't want anyone else knowing you can use a different solution. I think the trade-off is worth it for most people.
- ViViDboarder 5y agoSure, the objection Moxie has is people referring to Telegram as an “encrypted messenger” when the default usage is not encrypted. It means that people may download it wanting security and thinking they are covered, when in reality they aren’t because they are using a group chat.
- cbxyp 5y agoFull remote code execution in signal desktop via an node context enabled and an XSS in a react application, rendering user messages with __dangerouslySetInnerHTML. A similar XSS in the webview on mobile signal allowed at the very least, compromising all of the contacts and messages of the user. I wouldn't take anything that Signal developers/founders say about their product or others' products security seriously.
- deleted 5y ago[deleted]