zlacker

[parent] [thread] 10 comments
1. themod+(OP)[view] [source] 2020-06-05 04:07:25
I was about to ask about this. Signal was comparatively annoying. Can I keep using Telegram or am I postponing the inevitable? Curious.
replies(3): >>technt+31 >>goneho+96 >>ViViDb+Z6
2. technt+31[view] [source] 2020-06-05 04:21:16
>>themod+(OP)
As far as I am aware E2E only works on mobile and I think Mac for Telegram, although there may be third-party apps that support it. As long as you use E2E then I believe it has a lot more active users and probably has received an equal amount of security validation, so you should be fine.
3. goneho+96[view] [source] 2020-06-05 05:31:56
>>themod+(OP)
Is Telegram at all trustworthy?

I feel like I’ve repeatedly seen on HN that they’re not a good choice for secure messaging (though I don’t remember the specifics around it).

Signal and Matrix are the two options I’ve settled on.

[Edit]: Looks like the main issues with Telegram are that it doesn't use end to end encryption by default and that they rolled their own encryption protocol that's likely not secure. They also used to leak a ton of metadata, but from searching around it looks like they may have made improvements. Either way seems like something to avoid when there are obviously better alternatives.

replies(3): >>est31+A6 >>input_+c7 >>AnonC+Z9
◧◩
4. est31+A6[view] [source] [discussion] 2020-06-05 05:36:56
>>goneho+96
Telegram is not E2E per default. They claim to not turn over data to authorities but I doubt that claim. Signal on the other hand is fully end to end encrypted.
5. ViViDb+Z6[view] [source] 2020-06-05 05:42:58
>>themod+(OP)
I switched my friends from Telegram to Signal a few months ago and it’s been great. Probably depends on the features you use most frequently, but we switched as soon as message replies were added.
◧◩
6. input_+c7[view] [source] [discussion] 2020-06-05 05:44:47
>>goneho+96
Telegram only end-to-end encrypts "secret messages", which I assume are rarely used.
replies(1): >>antice+jO
◧◩
7. AnonC+Z9[view] [source] [discussion] 2020-06-05 06:21:44
>>goneho+96
Telegram's homegrown crypto has been dismissed by many people (including experts). But it offers privacy features that some other messengers do not. Is Signal trustworthy considering that it exposes your phone number to everyone else in groups? With Telegram it's possible to communicate with anyone without revealing your phone number or profile picture or anything else.
replies(2): >>goneho+Ca >>sorenj+Mo
◧◩◪
8. goneho+Ca[view] [source] [discussion] 2020-06-05 06:30:13
>>AnonC+Z9
The phone number issue is pretty overblown since it's a clear and intentional tradeoff that allows signal to retain very little metadata (leveraging local phone contacts instead of sending your social graph to their servers like everyone else). Moxie Marlinspike is the founder/co-author of the protocol and Brian Acton put in massive funding after the FB/Whatsapp fallout - not sure you can get better than that?

They're also making moves to make the phone number requirement unnecessary. What privacy features does Telegram have? It sounds like they don't even have encryption on by default and people have also dismissed their security? Why would anyone use them?

◧◩◪
9. sorenj+Mo[view] [source] [discussion] 2020-06-05 09:16:26
>>AnonC+Z9
> Telegram's homegrown crypto has been dismissed by many people (including experts).

Only the expert's opinions are of any value IMO, and I've never seen anyone showing an attack on Telegram's encryption. Telegram themselves seem to claim that it's never broken. I often see vague criticism over the fact that they use their own protocol, but never anything more detailed than that.

https://core.telegram.org/techfaq#q-i-39m-a-security-expert-...

replies(1): >>AnonC+hD
◧◩◪◨
10. AnonC+hD[view] [source] [discussion] 2020-06-05 11:48:01
>>sorenj+Mo
GP here. I agree. I believe there’s a stigma against Telegram. There was one security issue with the MProto version 1 several years ago, which was reported (given a bounty too, IIRC) and fixed. I don’t recall any other issue being reported after that.
◧◩◪
11. antice+jO[view] [source] [discussion] 2020-06-05 13:14:25
>>input_+c7
Telegram secret chats allow self-destruct timers and remote retraction of messages.
[go to top]