3 ms·
Eh. Agreed re: table stakes. But I think it's quite valid to suggest users should carefully think about the tradeoffs between being subject to legal disclosure
by md_ 3y ago
Eh. Agreed re: table stakes.
But I think it's quite valid to suggest users should carefully think about the tradeoffs between being subject to legal disclosure and being subject to compromise. Basically, do you trust the FISA courts, or do you trust the code?
The answer isn't really obvious! When it's a random anonymous startup based in, like, Panama that claims to have reinvented JavaScript-based encryption or whatever, yeah, I sorta trust the FISA courts more!
- sam_lowry_ 3y ago[flagged]
- md_ 3y agoNo, I wasn't talking about Telegram. I was making a general statement about crappy e2ee startups with bad designs and accountability. There was a recent one using Sealed.io whose name I forget. Re Telegram, sure, use what you like. https://www.pwnallthethings.com/p/russia-is-spying-on-telegram-chats https://www.pwnallthethings.com/p/russia-is-spying-on-telegr...
- sam_lowry_ 3y agoRead the story, but did not understood what's wrong with Telegram. Sounds like a FUD campaign.
- tptacek 3y agoTelegram's cryptography is objectively inferior to every other messaging app. It is anything but "tried and battle-tested". The idea of selecting Telegram over Signal to protect metadata is risible.
- lmm 3y agoMeh. All secure systems are alike, each insecure system is insecure in its own way. Like, yes, there are absolutely systems whose code is weak enough that I trust them less than the US authorities (I wouldn't say the FISA courts - isn't that the court that's declined like 3 warrants ever?). But that doesn't make having a presence in the US any less dangerous!