Show HN: Telegram bot with filters to read Hacker News
storebot.me
storebot.me
Telegram is one of my bets on a good, sane messaging platform for the future (vector/matrix is another, tent and even twitter used to be)
Why? It was made by VK (russian Facebook) devs and there are many concerns about its security.
Yeah, it's possible to have security like Signal, but then synchronization between devices is PITA and the rate of new features is slow.
It was not done by VK. It was done by Pavel Durov after he escaped from Russia.
> Yeah, it's possible to have security like Signal [...]
Actually, WhatsApp has implemented Signal's encryption and they worked together with Moxie Marlinspike (the developer of Signal) who verified those claims (or something along these lines. I'm not 100% sure this is how it happened, please take it with a grain of salt). So at least one popular messenger implements security that is better than Telegram.
[0] https://security.stackexchange.com/questions/49782/is-telegr...
> Someone actually cracking WhatsApp would be a serious issue for OpenWhisperSystems.
Why can't you imagine that e.g. Moxie has been blackmailed/etc. by some government authority? Again, I have no problem with Moxie's person in particular, I'm sure he would also agree that a single persons claims should not be trusted automatically.
Please read the link I provided before[0], it features links to a bunch of people saying Telegram is not secure[1][2][3][4]. It's not just Moxie. I actually have not seen any expert saying that Telegram is secure, but I'm interested in such thing. As the Telegram protocol is open, everybody is able to see how flawed it is. We know that. With a closed client that allegedly implements a secure encryption method (we also know it's good because it's open as well) there's a chance it doesn't work the way it's supposed to work, but there's also the chance it's working as intended. I'd rather take one percent chance over zero.
[0] https://security.stackexchange.com/questions/49782/is-telegr...
[1] https://eprint.iacr.org/2015/1177.pdf
[2] https://unhandledexpression.com/2013/12/17/telegram-stand-ba...
[3] http://www.alexrad.me/discourse/a-264-attack-on-telegram-and...
> With a closed client that allegedly implements a secure encryption method (we also know it's good because it's open as well) there's a chance it doesn't work the way it's supposed to work, but there's also the chance it's working as intended.
However, from the other side: Telegram is not _trivially_ breakable (there's a 2^64 attack, which is not 'trivial'), but Whatsapp might very well be simply MITM-ed by Facebook. So you could also look at this from a different perspective and say "A powerful adversary could probably break Telegram messages, but maybe all Whatsapp messages are immediately decodeable by Facebook".
Also note: you have provided 5 links, but [0] simply refers to [1] and [2], [1] says that "We stress that this is a theoretical attack on the definition of security and we do not see any way of turning the attack into a full plaintext-recovery attack", [2] claims that there could be attacks (but does not provide one), [3] is a real attack, [4] is not about an attack.
So while I see that there are valid concerns re. Telegram's security, the links you have provided are a nice example of the Internet echo chamber.
> but Whatsapp might very well be simply MITM-ed by Facebook
As long as you're not inspecting the binaries you use for Telegram (or build the applications by yourself) however, you can't guarantee it's not MITM-ed by someone either. Maybe you do, but most users certainly do not. When downloading the Telegram app from Google Play, there is not much difference to the WhatsApp app. You're basically trusting small groups that they provide the "real" binary to you. Not much of a difference to trusting Moxie's words, is it?
Link 0 was to remind you of the link I posted before and the other links might not provide specific (or effective) attacks, but they point out flaws in Telegram's protocol (1,2,3) and the way they test / value the strength of their encryption (4). More flaws are very much plausible for a homebrew crypto solution.
I don't like Telegram claiming that it us unbreakable in the early days.
That said: I don't care for the things I use Telegram for. Most people seem to post their thoughts to Facebook or Twitter anyway, compared to that Telegram is a better option in my case.
For serious stuff we use seriohs crypto anyway, don't we?
Not a single working proof of concept attack on telegram has been released and no one even claimed to have decrypted a single message.
I'm not saying Telegram is impervious to ever being cracked, but it's certainly not cracked yet or at all proven to be insecure.
Telegram has a number of those weaknesses, and many of its implementation details don't paint a good picture in terms of security either[1].
[1]: https://twitter.com/matthew_d_green/status/72646884513381171...
https://news.ycombinator.com/item?id=11432047
In short, "sources do not guarantee anything, and it's better to inspect the binary directly".
About Telegram, there have already been a few papers and so many articles pointing out its obvious security flaws that it is not even worth discussing anymore. Any search engine will return enough results for you to decide whether you should trust Telegram or not.
I think this is a fallacy: if you live your life by "nothing but the safest option" rule you are missing out in a number of ways.
I do not use chat programs for anything that is likely to cause me serious trouble, only for sharing photos with my family, chat with my wife etc.
Telegram is more open source than Whatsapp, isn't owned by Facebook, delivers features faster, has a better desktop client, has a an api and encourages useful bots.
I do use serious crypto when I need it. Where I live I luckily don't need it for photos shared with my family.
It's Durov's bullshit. Telegram is developed one floor beneath the VK office in Saint-Petersburg, Russia. Moreover, Durov himself often visits the office. Sources: [1] [2]
So yeah, between this and "MTProto is secure" I'm not sure if one can trust any other claim about Telegram's security (like "your chat logs are secure on our servers").
[1] https://tjournal.ru/p/durov-back-in-ussr (in Russian, sorry)
[2] I was there
I wondered who is financing Telegram since it's really moving fast and it has no apparent source of revenue; it makes sense that it's even coming from Russian government, since they want alternatives to US-owned services.
2. "Many concerns" only accumulate to one bad default setting (namely end to end encryption opt-in).
People should stop spreading the same FUD over and over, it makes me wonder whether those people posting messages on social media to influence online conversions also post on HN.
It's pretty quick and dirty, but enough that you get the idea. It doesn't read HN, but it reads Beer Advocate, Bing, Calorie King, IMDB, Rotten Tomatoes, Weather Underground, and several others.