Telegram Login for Websites
telegram.org
telegram.org
I think the fundamental component to their success is just how snappy and 'live' their chat conversations feel. Everything including their backend perf, chat bubble animations, etc seems to be finely tuned to make conversations feel alive and active.
And it absolutely is, from a 2 minutes look at their code :
- their chat activity is 12000 lines of code : https://github.com/DrKLO/Telegram/blob/master/TMessagesProj/...
- it looks like they have copy pasted tons of Android library like exoplayer directly in their repo
It does work very well though !
I guess that they have an extremely small team (or just one persone) and it is their first Android project.
It looks like they have acqui-hired a competing chat client (Telegram X), so it looks like they have a solution to clean this mess.
I've seen some huge Android java functions where everything gets stuffed into the Fragment creation/update/etc API functions... but this is one just stuffed everything in them.
It's just asking for bugs and security issues.
Edit: the commit history all comes the same developer, each titled with a generic "Bug fixes" commit and no description of the changes. Seems like a single guy is just cowboying the whole App, it's not a team project at Telegram. Which explains the above... https://github.com/DrKLO/Telegram/commits/master/TMessagesPr...
Maybe the developer was pressured to focus on releasing quickly over code quality...yada yada. The typical startup developer story. But not a story that I like to find in my security-focused software.
I am not sure at which point it becomes too big and new features and bugs are just impossible to handle.
It might have been the right choice for Telegram though. Their app feels snappy, so the 'only' big downside is that now it looks like they are going to have to thrown away this entire code base and replace it with the one from Telegram X (a third party client they bought)
Be it matrix simply writing a HashMap into a file as "database" replacement https://github.com/matrix-org/matrix-android-sdk/blob/master...
Or Signal simply taking apart Android system structs with JNI, to get a file descriptor’s owner https://github.com/signalapp/Signal-Android/blob/master/jni/...
There’s lots of suboptimal code in messaging apps. All of them.
The existing database implementations in the system do much less writes.
Doing such large, constant writes not only is slower, it also degrades the NAND.
1. https://itunes.apple.com/us/app/telegram-x/id898228810?mt=8 2. https://play.google.com/store/apps/details?id=org.thunderdog...
if (view instanceof ChatMessageCell) {
.......
ChatMessageCell cell = (ChatMessageCell) view;
....
}The `view` variable is still a reference of the parent type (Say `MessageCell` for now, can't be bothered to find that part in the code), and `MessageCell` references can only do certain things.
It's possible to check what the type of the underlying object is with `instanceof`, but that doesn't change the type of the reference.
If you want to do things that only a `ChatMessageCell` can do, you need to make a new reference of that type.
Kotlin would do what they call a 'smartcast' : ie if you did an instanceof if the if, in the corresponding {}closure you know the type of this object.
The whole code is probably unmaintanable for anybody other than it's original writer (and even for him, there must be a limit to how much code you can fit in your head).
I would love to work for Telegram, it is one of the products I use daily .. but if I had to handle this codebase, it would be a rare case of 'total rewrite or I am out'.
Incidentally, it looks like they are going to do this full rewrite. Telegram seems to have acqui-hired the creators of Telegram X and are prepping it up as a replacement.
On topic, I don't like these third party login systems much. Yes, they could provide better security compared to what smaller websites with less competent teams could, but associating a login with a provider also means I'm putting more eggs in one basket, so to speak. I also don't like the privacy implications, regardless of what Telegram states. It's sad that Mozilla Persona didn't take off and was shelved. It seemed like the best solution for this requirement.
When you say features, which ones do you mean? Do you mean the user interface?
But comparing to e.g. Line or WeChat maybe the entire social & stickers & attending services thing. Signal is a pretty bare-bones chat client, and WhatsApp only slightly less so.
Although not "features", having an open API for writing clients for whatever platform I choose and the fact that their official clients are open source are also a big plus.
Why don't you just use Snapchat?
Wire went two steps further and allows a) signing up with email addresses (without revealing phone number to Wire) and more recently b) multiple accounts for a person. Telegram has just started catching up on multiple accounts, but is still tied to a phone number.
A minor feature in Telegram that I use a lot is to edit my messages after sending them. No more re-typing messages with corrected typos prefixed with an asterisk. This either doesn't exist or came much later in other platforms I've listed in my comment (including WhatsApp).
This is anecdotal, sharing photos in Telegram means it gets through with the same resolution instead of being re-compressed and losing detail. I've heard from some others that re-compression happens on other platforms, but I don't recall on which ones right now.
Speed of message delivery, which is the most basic thing for any messaging platform. While Telegram has slowed down over time (it used to be almost instantaneous a few years ago), it still seems faster than the other platforms. This may just be my experience, since there are multiple factors that affect this.
Multi-platform and multi-device support with synced conversations across all of them. Telegram did it this way from the beginning. Wire is also similar, and better, since it has end-to-end encryption as well (but it doesn't store all conversations forever, and so newer devices will start with the most recent messages). Signal is way too behind in this department, and doesn't even allow carrying over received messages from one phone to a newer phone (this is true in iOS, and on Android it involves some work by the user). Signal actively prevents data from being backed up from the device!
Telegram's search, both within conversations and across conversations, is very fast and reliable.
Telegram allows chatting with oneself, which was renamed to Saved Messages a little while ago. I use it as a bookmarking feature to store interesting information. Combined with great search, it becomes a reference repository.
I'm sure I'm forgetting some other stuff, but the overall user experience is much better, right from application startup.
Security with fewer features is still useful; features without security are unusable.
I'm still waiting for Signal to come closer to being relevant, as per my expectations, before moving to it and pushing some others to move to it. But every time I look at a new release and compare, Telegram still seems about a year or more ahead.
It's 2018. Why are we still trusting the phone network for anything related to authentication? Surely companies like Telegram can't use the excuse that they didn't know how horribly insecure SMS and the phone network in general is, no?
I don't know how Telegram does it, but it keeps picking the wrong security options. It's like a gift they have.
It's 2018 but this problem is far from solved.
(there is a lengthy rant about that somewhere in my post history)
It then calculates a second number that you send back to the bank. No SMS at all!
Why would you think I'd have to use Allo and G+?
To me the spooky part is that he only thought of two use cases in which one is guaranteed that a random person is not using Google's services (at least, not exclusively).
This isn't like a Facebook share widget, which is usually so ubiquitous, they really can know all the sites you visit.
Or in other words: We are ready to sell your private data now. Because that's what actually happens when you login to another website via Telegram login.
First, it's you who decide to use telegram to login to a website (as you would login with Facebook / google).
Secondly, you see what informations will be shares with the website.
Lastly, there is no money involved. It's totally free to use.
Yes, this is implicit in what the parent is saying. The point is, your data can be shared if you volunteer it by using this feature.
> Secondly, you see what informations will be shares with the website.
At a minimum, you are sharing the fact that your identity logged into the application. A profile of logins associated with your identity can be built, and a profile of how many Telegram users logged into a particular website can also be built. Both (and particularly the latter) are valuable.
> Lastly, there is no money involved. It's totally free to use.
This has nothing to do with whether or not your data is actually shared or sold with third parties.
I'm not necessarily agreeing with the parent that Telegram is going to start selling user data, but your arguments here do nothing to diminish the fact that they could do so en masse. A graph of your logins should probably be considered "private data."
But it has absolutely nothing to do with this feature as the parent comment was implying. This feature involves no selling whatsoever.
The commenter you replied to was expressing a (snarky) hypothesis that Telegram will sell login data. You initially said this was nonsense, but are now saying that they could do so. That’s basically the point.
Ofc telegram can sell user data like any other company, and may be doing it for months for all we know.
{ PasswordExpirationDate: null, EmailVerified: false, IsActive: true, IsDeleted: false, Uid: null, CustomFields: null, IsEmailSubscribed: false, UserName: null, NoOfLogins: 3, ID: '', Provider: 'facebook', Prefix: null, FirstName: '', MiddleName: '', LastName: '', Suffix: null, FullName: '', NickName: null, ProfileName: '', BirthDate: '3/1/1985', Gender: 'M', Website: '', Email: null, Country: null, ThumbnailImageUrl: '', ImageUrl: '', Favicon: null, ProfileUrl: '', HomeTown: null, State: null, City: 'unknown', Industry: null, About: '', TimeZone: '3', LocalLanguage: 'en-US', CoverPhoto: null, TagLine: null, Language: 'en-US', Verified: 'true', UpdatedTime: '', Positions: null, Educations: null, PhoneNumbers: null, IMAccounts: null, Addresses: null, MainAddress: null, Created: null, LocalCity: null, ProfileCity: 'unknown', LocalCountry: 'France', ProfileCountry: null, FirstLogin: false, IsProtected: false, RelationshipStatus: '', Quota: '', Quote: '', InterestedIn: null, Interests: null, Religion: '', Political: '', Sports: null, InspirationalPeople: null, HttpsImageUrl: '', FollowersCount: 0, FriendsCount: 0, IsGeoEnabled: null, TotalStatusesCount: 0, Associations: null, NumRecommenders: 0, Honors: null, Awards: null, Skills: null, CurrentStatus: null, Certifications: null, Courses: null, Volunteer: null, RecommendationsReceived: null, Languages: null, Projects: null, Games: null, Family: null, TeleVisionShow: null, MutualFriends: null, Movies: null, Books: null, AgeRange: { Min: 21, Max: 0 }, PublicRepository: null, Hireable: false, RepositoryUrl: null, Age: '31', Patents: null, FavoriteThings: [], ProfessionalHeadline: null, ProviderAccessCredential: { AccessToken: '', TokenSecret: null }, RelatedProfileViews: null, KloutScore: null, LRUserID: null, PlacesLived: null, Publications: null, JobBookmarks: null, Suggestions: null, Badges: null, MemberUrlResources: null, TotalPrivateRepository: 0, Currency: 'EUR', StarredUrl: null, GistsUrl: null, PublicGists: 0, PrivateGists: 0, Subscription: null, Company: null, GravatarImageUrl: null, ProfileImageUrls: { Small: '', Square: '', Large: '', Profile: '' }, WebProfiles: null }
EDIT: Yes, Telegram uses passwords if you enable them. This is what the questionable query looks like: https://i.imgur.com/BAnddlg.png
https://i.imgur.com/BAnddlg.png
I counted the asterisks, they do in fact reveal the length of the password.
That... is a problem.
It is a car with seatbelts that don’t work; a car without any seatbelts is better.
All of the peer review by qualified professionals has been negative. Don’t take my word for it, go look it up.
As an aside this is a very bad SE answer as SE policy is to include conclusive information within the answer itself, and here the only relevant part is merely being linked to.
It had a vulnerability, but not a severe one, and certainly not one that could be exploited silently or lead to retroactive message decryption.
The vulnerability was: If you pwn the server, you can join a group without being invited, which means subsequent messages would be plaintext to you. However, everyone gets notified of a new arrival.
> Telegram has had no such vulnerabilities as far as I'm aware.
That's because Telegram doesn't encrypt groups or channels at all.
> This reinforced my impression that HN's mantra that "Telegram's encryption is bad" is more a personality cult to moxie than an informed opinion.
I don't particularly like Moxie, personally, but his work stands on its own merits.
EDIT: Because the wording was ambiguous, I want to clarify: I don't particularly dislike Moxie, either. I'm neutral to his personality, largely due to a lack of personal interaction with the man.
If to you owning server => accessing group is not severe, then you should be happy with Telegram's default encryption: it's run of the mill SSL by default, just not E2E. If you own their servers you can read people's conversations too.
1. Announcing your intrusion
2. Only being able to read what people say after you joined
That's a far better security proposition than server operators being able to silently spy on everything you ever send.
I hear you. What I meant is that although I know the guy has an excellent reputation, I know that because I heard other people say. I don't really have the technical knowledge to evaluate it myself, and I suspect 99% of the people in HN are in the same position. Therefore, if I were to say "Signal's security is excellent" I would be falling for the cult of Moxie myself, not an informed opinion.
Please acknowledge that this happened before continuing to offer more opinions about this subject.
> you're offering security advice
I'm not offering security advice.
Transport-layer encryption that leaves messages totally readable to the service operator should not be classified as "they do encrypt". It muddies the water and will confuse users.
For the sake of communicating risk effectively, only E2E should count when we talk about encryption. Lack of transport-layer security (TLS, Noise, etc.) simply demonstrates severe negligence and/or incompetence.
> I'm not offering security advice.
Above you said:
> WhatsApp had a severe vulnerability for groups disclosed not so long ago. Telegram has had no such vulnerabilities as far as I'm aware.
A casual observer might read this and think, "Wow, WhatsApp is vulnerable and Telegram isn't. I should use Telegram" despite being even more at risk by choosing Telegram.
Whether it was your intention or not, it will have the same effect on HN readers as formal security advice from any other commenter.
In that case, you should consider WhatsApp's group security issue as severe.
Maybe the question to your "true or false?" comment to 'tptacek will elucidate adequately why the worst case of the WhatsApp vulnerability is still miles above what Telegram offers in terms of privacy, and even aside from Telegram, would be most generously a sev:medium (but by most measurements a sev:low).
It's fine not to keep up with this stuff and not to have solid answers for basic questions about it. I just think you should use a lot more question marks when you write about it.
True or not?
No, WhatsApp did not.
Messages are not exposed to the operator. If you exploited this vulnerability, you could not read messages that had already been sent.
Instead, what happens is, everyone is notified of a new arrival, and then can decide whether or not to keep communicating through that channel.
That is NOT the same thing as "leave messages exposed to the operator" in any stretch of the imagination.
Sure, but that's not what's happening when people whose day-to-day involve applied cryptography and/or application security are commenting on MTProto and Telegram.
Here's a good read on why Telegram's "contest", which is a challenge meant to create the illusion of resilience, is totally bogus in the context of real-world cryptography: http://www.cryptofails.com/post/70546720222/telegrams-crypta...
The things that the Signal Protocol does well:
1. It maximizes forward secrecy,
2. while working for mobile devices that may be offline or unreachable,
3. and uses authenticated encryption.
https://tonyarcieri.com/all-the-crypto-code-youve-ever-writt...
https://paragonie.com/blog/2015/05/using-encryption-and-auth...
Disclaimer: The last link (the paragonie.com one) was my writing on the subject.
The problem I have with WhatsApp is not a question of vulnerabilities, it's a problem of trust in ownership of the app's code. There's no way I would ever trust Facebook with anything sensitive enough to require the Signal protocol because the endpoints might be compromised at some point straight from the app itself.
I don't necessarily think that's likely, but it's also not entirely implausible that they would do something, intentionally or not, that subverts the threat model/privacy assumptions of its users.
Facebook's interests are not aligned with users when it comes to privacy.
If it was malicious, they already control the client code and therefore have access to the plaintext anyway.
As a practical matter, it's even starker. WhatsApp messages are end-to-end encrypted by default, forward secure so that losing your phone doesn't let adversaries retroactively decrypt sniffed messages, and, most importantly, encrypted for groups.
Telegram's messages are plaintext by default --- you have to opt conversations in to encryption! --- and don't encrypt group messages at all. Telegram plays a sneaky game where they tell users that all messages are encrypted because they use TLS. But, of course, so was AOL Instant Messenger.
If you need top security - maybe. If you need features - not. I'd consider using something else if other apps have same features or similar features done better.
People are using for many things. Channels and groups are two main features that other IM's either do not have or have nothing but poor substitutes.
>it’s safe to use
It is safe to use. As safe as any other method as long as you are not stupid enough to share sensible information. Using any IM for this task is a stupid move to begin with.
>Its use should be discouraged in all cases as a result.
This is like saying that kitchen knife usage should be discouraged in all cases. You can hurt or kill yourself or an other person.
https://fas.org/sgp/crs/intel/RL33332.pdf
NSLs don't break well-designed and well-implemented E2E encryption. They can obtain metadata, which can still be harmful, but that's it.
If you want metadata on Telegram users, just hack Telegram's ISP. If the NSA hasn't already done so, I'd be surprised.
This is a wrong comparison.
Furthermore:
As an early enthusiastic Whatsapp user I'd love to use Whatsapp if it had continued developing into what Telegram is now instead of selling out and start feeding data Facebook.
Right now
-one side has sketchy crypto (according to world leading cryptographers AFAIK) and correct incentives
while the other side has
-- good crypto,
-- incentives stacked towards tracking me (contrary to their previous promises)
-- and a track record of doing exactly that
I don't think it is an obvious choice without trade-offs either way.
But it's not like "just use Whatsapp" is an obvious alternative.
(Signal seems to be a completely different story but most of my contacts don't use it.)
Telegram gets a lot of hate on HN, but I have to say that of all large messaging apps Telegram has by far the best UX. That said, I can see it slowly turning into a walled garden. For example, in public channels (distinct from groups, they're broadcast only) it should be possible to link to their content from the outside. Instead if you try that they force you to download the app to see the content. EDIT2: As someone noted you can link each individual post on a channel, but you can't see and scroll through a list of posts as you can from inside the app.
I wish we had a messaging app with a market as large as WhatsApp's, UX as good as Telegram, security as good as Signal, run by an organization like Mozilla.
Edit:// Evil might is the wrong word. But if you have the choice between a self enforced world police with a history of using information against people in foreign countries and a country that is mostly involved in their own shit and area the choice is IMO easy
https://en.wikipedia.org/wiki/Russian_military_intervention_...
https://en.wikipedia.org/wiki/Russo-Georgian_War
By using telegram you are directly supporting the Kremlin.
Not that i think any of both is right. But only one directly changes _my_ life.
See, for me it makes sense to link Telegram to Kremlin, as it's very obviously ran by Putins buddies.
If Signal devs are in a similar situation, it's certainly not nearly as obvious as with Telegram.
Essentially:
> By using Facebook/Whatsapp you are directly supporting the U.S.
is just as valid isnt it? Because you know Zuck has been to the White House and has followed requests by U.S. gov agencies.
Thats my whole point. If you have to choose between 2 evils, you choose that that is less threatening to yourself.
PS: I dont compare with Signal as they have neither spread nor common features.
Do you have any reason to believe this, other than the guy's nationality?
Durov was the founder of VK (Russia's version of Facebook). He was approached by the Krelim and "forced" to sell his stake (nice social network you have there, it would be a shame if something happened to it)
https://www.theverge.com/2014/1/31/5363990/how-putins-cronie...
I would imagine if there's someone who hates the Kremlin, it's Durov.
So I'll ask again, do you have any evidence to support your claim? Because if it all hinges on his nationality you're sounding a bit biggoted.
lol.
>Do you have any reason to believe this, other than the guy's nationality?
It seems bigoted to assume that his nationality would have anything to do with this.
Durovs have spent years cultivating this lie of them having been forced to "exile" from Russia, despite being a regular sight in Saint Petersburg.
Pavel even went as far as assaulting someone and taking their phone after he was spotted in a local mall. https://lenta.ru/news/2017/03/20/durov/
>https://www.theverge.com/2014/1/31/5363990/how-putins-cronie...
>I would imagine if there's someone who hates the Kremlin, it's Durov.
Well then you probably wouldn't imagine that Telegram is being developed in the VKontakte HQ building, but nonetheless that is the case.
https://tjournal.ru/52954-durov-back-in-ussr
Maybe Durovs genuinely do hate the Kremlin, maybe not. It doesn't make a difference. They've spent years cultivating their false image as dissidents while remaining extremely close to Putin, whether or not they do so by choice makes little difference.
Pavel literally fled the country and bought himself a different citizenship only to be best Putin buddy, yeah.
This would be ideal. Until then I still feel Signal gives me the best balance and I haven't had too much issue with friend/family adoption.
The only way I could see this happening is some open/decentralized chat protocol takes hold and private companies build nice UX on top of that.
Sadly, strong UX is not the strength of opensource/foundation driven development. (For the love of god someone please prove me wrong on this)
Even worse, one can only participate in their network with a mobile phone number. In my country, land line numbers do not even work.
But you can link the content, no? (example: https://t.me/dailyeng/1402). You see the full post, you don't have to donwload Telegram for this.
But you're right. I'll edit above.
Edit: To perhaps stem the downvote tide: The impulse for my comment is that OP probably hasn't tried it, even though Telegram and KakaoTalk have similarly sized userbases and the emotion-inspiring stuff in the Telegram client app is mostly a timid knock-off of better Asian messengers (the Telegram team faces the challenging task of slowly acclimatizing Western audiences to features it knows will eventually be popular, by example). The West-centricness of such statements is grating to me.
The reason my comment doesn't substantiate the UX difference further is that I can't think of a single feature or screen that isn't better realized in Kakao's Android app than in Telegram's. General performance, group management, galleries / archive retrieval stuff, cross sharing, search, stickers, etc. It's available with a full English UI, go have a look. (From a privacy/security/freedom POV Kakao is terrible, though.)
To my mind Mozilla should have had, and kept, a set: Firefox, Thunderbird, instant messaging, Persona. Not forgetting Lightning etc.
An open protocol is a prerequisite. There's a 2018 IETF proposal for interoperable E2E messaging, initiated by Cisco, Google, Facebook and Wire:
Architecture: https://datatracker.ietf.org/doc/draft-omara-mls-architectur...
Protocol: https://datatracker.ietf.org/doc/draft-barnes-mls-protocol/?...
"Messaging Layer Security (MLS) ... is not intended as a full instant messaging protocol but rather is intended to be embedded in a concrete protocol such as XMPP [RFC3920]. In addition, it does not specify a complete wire encoding, but rather a set of abstract data structures which can then be mapped onto a variety of concrete encodings, such as TLS [I-D.ietf-tls-tls13], CBOR [RFC7049], and JSON [RFC7159]. Implementations which adopt compatible encodings should be able to have some degree of interoperability at the message level, though they may have incompatible identity/authentication infrastructures."
Already, in the starting point draft, it's been crudded up: it has "ciphersuites", and comes with support for the NIST P-256 curve --- despite the fact that the underlying design wants to take byte strings to curve points, which is tricky to do on the P-curve. It will only get worse from here. They'll figure out some reason to bolt a PAKE onto it soon enough.
Signal Protocol is exceedingly well-documented (and even before those documents were written, it was open enough for Wire to lift the protocol wholesale).
The IETF is bad at cryptography. Your default position should be distrust of IETF crypto standards.
(I like my source on this, but can't share it; I expect to be able to this year, though. In the meantime:
0e49002152a374d9c11251cf856a7ccf25ef9bd0db54c3e97bef2a4109dad4f0)
2. Facebook's interests in the standard are not necessarily what drives the standard; Facebook can just be along for the ride.
I think what's going to happen with this is what happens to all de novo IETF designs other than TLS, the one that the market requires actually work: it's going to fail. That's also the outcome that I'm hoping for.
In the meantime, if Millican wants to get together with Katriel Cohn-Gordon and do a Facebook-only ART protocol design for Facebook Messenger, with an eye towards replacing Signal Protocol in WhatsApp, that would be a great development. So would a Cisco-only ART messenger, or maybe even a Mozilla ART messenger (though Mozilla's motives are the ones I trust least here).
What does not make sense is for a protocol whose service model we barely understand even in theory to be designed from scratch in an open standards group. The IETF motto used to be "loose consensus and working code". Now it's "take an RWC paper, add the P-curves to it, and use it to fuck over the most successful secure messaging protocol".
We shouldn't be cheerleading this. It's capture, not progress.
I would donate some money for such an initiative if it also had strong privacy protections from the start.
I'm good.