Telegram probably isn't as secure as ISIS thinks
motherboard.vice.com
motherboard.vice.com
http://thoughtcrime.org/blog/telegram-crypto-challenge/
I don't think you should use Telegram.
Compared to the alternatives of Skype, WhatsApp, SMS, Hangouts, iMessage, etc it's a good chat service, with a relatively lightweight native client on multiple platforms, actual working sync, and good recovery when used on poor Internet connection.
It is unethical to market snake oil.
The hate stems from two main sources:
1. They're claiming to be secure in a very flamboyant (even arrogant) manner by challenging the world's cryptographers to break their protocol, but the contest is structured to be unwinnable regardless of how shitty their crypto actually is.
2. Telegram spends less time improving their crypto (which is full of WTFs) and instead markets themselves to people who aren't technical enough to figure out how shitty it really is.
Seriously, avoid Telegram. If you want Signal to work on more platforms, send a check to Open Whisper Systems and help them build up their team to cover more area.
The 4 or 5 people in the nsa that actually do any work don't stand a chance against several hundred million baby breeders with ak47s.
Are they super-duper safe? No. Will driving our cars grant you immortality? also, No.
But no car can promise this, and driving any car inherently runs the risk of dying - No car is provably 100% safe! If you're really worried about this, just don't drive!
Most car drivers won't care anyway, very few people crash their cars on a day-to-day basis, so it's not really relevant.
</good-natured-sarcasm> exaggerated/straw-man comparisons, or appeal-to-low-standards doesn't really satisfy these kind of concerns... <good-natured-sarcasm>
If it's not actually secure then they shouldn't advertise it as secure.
An app that advertises itself as secure but isn't is naturally going to attract more hate than an app which doesn't advertise security in the first place.
Nobody forced them to advertise security. If they just wanted to be a a good chat service with the advantages you listed, they could just do that. But if you advertise security, you had better deliver!
Claiming to be secure, and then taking what's mine away from my control is unacceptable to me.
Yes, Signal The App reads your contacts to construct the blinded signature query. Does it then do something nefarious with them? No: https://github.com/WhisperSystems
What alternative solution to the PKI key introduction problem would you rather see? You could go the iMessage central key broker route, but that means trusting that Apple won't introduce the wrong key to you (or be compelled to do so). [2] Or, you could let users exchange keys in person a la key signing parties. That's a reasonable feature request at this point, but advanced usage and not something that gets you traction with normal people. TextSecure/Signal wouldn't have gotten to where it is today with that much friction around key introduction.
For RedPhone, our user base is still manageable enough (for now) to use the bloom filter technique. For TextSecure, however, we’ve grown beyond the size where that remains practical, so the only thing we can do is write the server such that it doesn’t store the transmitted contact information, inform the user, and give them the choice of opting out.
I would expect that Signal does share contact information with the server.
But now you've got me curious. I'll dig back into the code and find out for sure.
[1] http://support.whispersystems.org/hc/en-us/articles/21274348...
[2] http://support.whispersystems.org/hc/en-us/articles/21247614...
It'd be nice to figure it out, but I guess it isn't that important, Signal still leaks lots of metadata, so anyone that would be burned by sharing their contacts isn't gaining much by using it (or any other mobile comm...).
I'm going to write up the protocol and publish a reference server I wrote in Go in a few days. I'll post it here and send it to Open Whisper Systems as well, they may want to integrate it.
Obviously, if you're extremely liberal with the upvote button, this may not be useful as a bookmark....
Useful?
I would call it Show.hn :-)
There's even an fdroid repository[1] you can add to track libreSignal apks.
----
[0] https://github.com/JavaJens/TextSecure [1] https://fdroid.eutopia.cz/
WhatsApp (most popular?) doesn't. ChatSecure (most secure?) doesn't.
I'd say 'Use Telegram' with the caveat that you shouldn't trust it blindly? Use it as a better and cross-platform SMS/text experience, which might or might not be more secure.
Edited to add: The same could well be true for someone using plaintext.
I think I agree that using encryption on Telegram singles you out though!
This tendency to talk about the name/brand of the client instead of the protocol is a current problem with IM. The ISIS people should really be writing articles about OTR and TOR to address their particular application.
I have a friend that thinks I use the Pidgin chat system because that is what she uses when she chats with me on XMPP. Since Pidgin does not run on her phone she thinks she can only chat with me when she is at her computer. So far all attempts to explain the idea of an interoperable protocol have failed.
I remember years back when I attempted the same problem with a thing called Wire, for activists, that I posted on here and combined Facebook/Twitter type stuff with "secure" messaging, which was a web based UI that implemented AES256 based browser encryption based on the Stanford JS library. I got thoroughly roasted by people that knew what they were doing, so I shut the project down realising that what I was doing was dangerous due to lack of qualification. It's interesting seeing all the projects that have sprouted up since, and clearly I was on the money with the initial idea.
FB Messenger works fine but of course is not private w.r.t. FB
Seems a good enough reason to use something different
https://threema.ch/en/faq/why_secure https://threema.ch/validation/
I've never gotten the impression from any other reporting (Wired, CNN) on this issue that they so much as skimmed Moxie Marlinspike, Michael Green, or anyone else's criticisms of Telegram.
My bet is that the real bad guys always use face2face when possible, and voice/video with codewords and visual cues when there's no other choice... and maybe an encripted sdcard carried by hand/mail when they really need to cary large volumes. They can't be stupid enough to use anything else for such high risk stuff!
I'd guess that the only people actually depending on good consumer-lever crypto are whistleblowers, anti-goverment protesters and individuals and companies that truly value their privacy for one reason or another! Are these the people we want to hurt here?!
The one exception is Ottela's Tinfoil Chat. It needs a robust, low-level implementation instead of Python. Yet, he cleverly dodged much of the TCB problem by creatively applying what he learned from others plus input we gave him on Schneier's blog for high assurance security & general improvements. So, you can build on and use that* but the rest depend on what top-tier and organized crime can buy attacks for. Ridiculous....
* Again, without Python and with TCB enhancements. OpenBSD at the least for its lower 0-days.
Also the fact that it doesn't even have end-to-end encryption by default means it shouldn't even be in the same class as "secure messengers". It's better suited in the Skype/Hangouts class of apps.
Once you are more or less identified as a terrorist, from the point of view of an intelligence organization, they might be sad to not get the content of the messages, but is they can have the graph of your contact, they'll be more than happy (and find the weakest link in there).
Incidentally I have also checked that the Telegram and Signal app are requesting a Location permission on Android. I don't know if it is sent to some sort of central server, but this does seem not safe if youe life depends on it.
Everything else—including the company's cocky and downright insulting attitude—doesn't matter nearly as much. I actually think a lot of what they say gets lost in translation.
We recently integrated with Telegram (without their knowledge, support, or blessing, of course—because Telegram), which sent me on a little research journey. Results are here: https://sameroom.io/blog/announcing-support-for-telegram/
edit: atm. 111 points and I love that. Wish pg could fix my karma, I really like even numbers and I feel that the karma crave is addictive..
btw. I agree with you. It's clever and the tools intelligence services have created for these purposes are fascinating
But I think Pavel Durov should make a system that gives up terrorists' communications if it detects indicators eg words that will lead to planning a violent attack. And without informing everyone about it.
BTW, if Telegram crypto was that much insecure why members of the so-called "security community" haven't yet compromised the Telegram chat for real (regardless of any contests and petty rules) and proven they had been right?
I don't rule out this as impossible - I just think that without such proof it's all just a kind of stupid whining.