https://github.com/DrKLO/Telegram/blob/74def22213846b1f90a26...
On line 666:
if (sendingText.contains("WhatsApp")) { //who needs this sent from ...?
sendingText = null;
}https://github.com/DrKLO/Telegram/blob/74def22213846b1f90a26...
On line 666:
if (sendingText.contains("WhatsApp")) { //who needs this sent from ...?
sendingText = null;
}This is wrong. If you follow the logic (which is admittedly difficult) you'll see they are stripping out the "sent from WhatsApp" tagline WhatsApp adds when you share a photo, etc from WhatsApp to Telegram.
You'll still get the photo, it just won't have the tagline indicating where it came from. Still a bit shady but I also dislike the "Sent from ..." taglines.
EDIT: Parent is a WhatsApp employee... now this seems like sort of a lame attempt to justify their own unethical behavior. This makes me pretty bummed.
So you will run in to issues (not sure how it would manifest itself) if you share photo or video that does have text, but just doesn't contain "WhatsApp" ("Sent from FooBar").
It looks like it'll send a text and then send the photo[0] but who knows what kind of state will be modified when you send the text first.
[0] https://github.com/DrKLO/Telegram/blob/74def22213846b1f90a26...
The logic is too mixed up and this method does too many things. Off the top of my head you might refactor it so that inspection, classification, validation, preparation, etc all happen separately, right now this method does them all and then some.
I think you're right. There is a lot of room for refactoring here. A few more (business/model) classes would not hurt here.
https://github.com/DrKLO/Telegram/commit/a93d2994842ef694442...
> Showing 208 changed files with 5,479 additions and 1,841 deletions.
It looks like they squash all their commits and just push one big diff for each update. This isn't really what I've expect from a product that advertises itself as open source security software.
They handle this pretty weirdly, with each commit on master being a release. There's dev branch that was meant to have actual changes (without commit comments - developer said most of his commits have useless descriptions like "bugfixes", but that's a personal preference), but seems to be dead.
This was all discussed here: https://github.com/DrKLO/Telegram/pull/76
Dirty games. I don't want to use either.
2. Given that you're a WhatsApp employee, commenting about Telegram on a thread about how WhatsApp (unfairly?) competes with Telegram, you should probably disclose your affiliation. That would be true even if your comment was accurate, but since it's an outright false claim...
The interesting question here, I think, is whether you're just careless and didn't take the time to double check your claims, or if your comment was actually made in bad faith.
Also the fact that you're a WhatsApp employee makes your comment a poor attempt at justifying your own censoring behaviour
Intent.ACTION_SEND.equals(intent.getAction()))
And no, it isn't just removing "Sent from Whatsapp", it is setting the sendingText variable to null, which will result in:1. The message not being delivered.
2. The exception block being fired where this toast message will be displayed to the user: "Unsupported content"
2. error=true is set in the else if case, which can not be stepped into anymore after having checked if the text contains "WhatsApp"
I can't trigger this behaviour in telegram though on mac or windows phone. Maybe just for Android?
I don't have time right now to dig through the source myself, but the desktop source code is here if you want to see if this logic is in it: https://github.com/telegramdesktop/tdesktop
Base: https://news.ycombinator.com/item?id=10657981
Edit: tone.
In other words: As my (green/new) sibling ones_and_zeros states, afaik that ONLY strips the text if it contains "WhatsApp" and you send non-text content. Which .. is an improvement, I guess. Or a band-aid to grudgingly fix a 'bug' in WhatsApp.
This code is written with a bulldozer ! How hard is it to refactor each of those branches into separate functions or objects ?
If there's no time for that, I wonder, is there enough time to figure out the security and privacy implications of this entire codebase ? Should I trust this code with my life ? Because some people will ...
Also, open source does not automatically imply high quality or immunity from criticism.
In this particular case, when people can be arrested or even executed for what they say (in some countries), this kind of code can be plain dangerous.
Even if their intentions are absolutely pristine and they really want to do good in the world (which I hope they are) - a bit more diligence about the quality of the stuff you're sharing never hurts.
It seems to me about as constructive as walking into any software company and saying, "Ugh, these engineers are wearing t-shirts and their shoes are completely unshined! People, if these programmers care so little for their appearance, can you trust them to care about their code?"
How do you even share a message from whatsapp to telegram?