> If you want to use secure and private apps, I recommend: Signal Private Messenger: https://signal.org...
I feel it's wrong to criticise Telegram for using phone numbers, and then in the same breath recommend Signal.
> If you want to use secure and private apps, I recommend: Signal Private Messenger: https://signal.org...
I feel it's wrong to criticise Telegram for using phone numbers, and then in the same breath recommend Signal.
Matrix/Riot.im and Wire doesn't. I think they're both good alternatives.
Bridging Matrix/Riot to IRC/Telegram/Whatever seems to require some black magick beyond my capabilities.
On the other hand, even my grandmother can (and has) set up Telegram and WhatsApp.
https://media.ccc.de/v/35c3-9400-matrix_the_current_status_a...
OT but I suppose you mean century?
1. WhatsApp was the first widely-used such app and it was phone number-based, so all the clones use the same system.
2. Non-technical people have a hard time (read: bordering on impossible) remembering their usernames, let alone passwords, and by using the phone number as both identification and authorization, the problem is sidestepped.
3. People have an existing address book of contacts (in the form of phone numbers) in their mobile phones, that can be used to pre-populate the app's buddy list.
The problem was when you change your device you can't migrate your PIN so I think it contributed to decline to usage as people moved to other BB devices or iOS/Android
This only strengths the argument why majority of chat apps use phone number as your username.
https://www.theguardian.com/media/2011/aug/08/london-riots-f...
from 2010 / 2011
> Using BlackBerry handsets – the smartphone of choice for the majority (37%) of British teens, according to last week's Ofcom study – BBM allows users to send one-to-many messages to their network of contacts, who are connected by "BBM PINs". For many teens armed with a BlackBerry, BBM has replaced text messaging because it is free, instant and more part of a much larger community than regular SMS.
In Signal it's a requirement and not a convenience: I would like to avoid using the number, and I'm able to configure it, but I can't, because the apps don't allow that. Just the same like I have to use it for a new Google account etc.
The real reason is: both the spy agencies and the ad companies really like to be able to easily identify everybody.
Some topics to consider, that those interestdd in such topics have to clear with themselves (source: all Wikipedia):
“The Open Technology Fund (OTF) is a U.S. Government funded program created in 2012 at Radio Free Asia.”
“Radio Free X” (for different X” have a very long history of effecively being made and maintained by CIA.
“Clinton's policy was "heavily influenced by the Internet activism that helped organize the green revolution in Iran in 2009 and other revolutions in the Arab world in 2010 and 2011".[3]”
“Notable projects that the OTF has supported include The Tor Project, Open Whisper Systems,..”
Such associations can at least (directly or indirectly) influence some design decisions.
The best proof against the points like mine would simply be to allow those who want and know how to do that to really use the service completely anonymously, that is, especially without providing some phone number.
Yes for “complete” security by all means use your own optical fiber network and your own crypto, with a touch of quantum cryptography custom made by Bruce Schneier et al just in case.
We’re talking about someehing else here though.
It is just their insisting on the phone numbers is their action that for me makes use of their product problematic.
And the "Open Technology Fund" is surely an interesting beast, worthy knowing about, as well as the stories about the "Radio Free X" for some X.
Some fascinating insights on that topic:
https://www.theglobeandmail.com/arts/books-and-media/review-...
Signal has repeated the reason they use phone number identifiers ad nauseam. The goal of Signal is to make text messaging secure. Those are the roots of the project. You're confusing the application with the underlying technology, which Signal has published and many other projects have exploited.
For whom is that messaging more “secure“ if the phone numbers are the (technically completely unneeded) requirement on which is insisted by the producers of Signal?
If you don't and never would send an SMS text message, you are not Signal's model target user and never were.
Use something else; you have lots of choices. If not Signal, I recommend Wire, though I think you'll come out behind on the privacy tradeoffs.
So I still claim that the fact they don’t has some very strong reasons that are completely opposite to the security of their users.
And I still haven’t read here any argument that disproves that.
What you cannot get away with doing is making the argument that your disagreement with them is an indicator that they're compromised by the US Government. That's comically false. Snipe at them for things you can make actual arguments about (there are lots of those).
"Apparently" because it's without any proof.
> What you cannot get away with doing is making the argument that your disagreement with them is an indicator that they're compromised by the US Government.
I'm not claiming that and I've never claimed that. I'm claiming only this:
1) there are no technical reasons for them insisting in their users giving them user's phone numbers and user's contact data: the underlying technology would not be any more complex without that.
2) There was(is?) actual monetary support of Signal development by the actual US spy organization (with the decades of historical support for these direct "spy" connections, some of which really amazing, see before). Which gives some additional context for the whole operation.
Specifically "tainted" and "compromised by" were always only your formulations. I'd just say "given the circumstances, there can be observed some non-technical reasons behind some design decisions."
Which would, I hope, be completely non-controversial if we would, for example, talk about Skype. Because for Skype we have the direct proofs from Snowden. And not having such for Signal we surely can say "we don't have proofs" but we also can't claim that "this time it's completely different." Even if Snowden himself talks nice (or something) about Signal.
And downvoting my comments stating both is not changing these facts.
until whatsapp appeared on the scene. The key innovation whatsapp brought, because the app was laughably insecure and probably overly simple (but that simplicity can't have been the reason it won; there were other really simple apps out there)... was making your account ID equal to your phone number.
This gave whatsapp the ability to skip the phase of setting up your 'network'; there'd be no need to ask your friends what their ICQ id is or whatever. Whatsapp would even simply tell you which of your friends had whatsapp installed, immediately, without any consent or setting up your network required.
THAT sold. That simplicity. Yeah, you can (rightfully!) put quite a few question marks on the consent and authentication mechanism I laid out above, but it does lead to an app that is useful and understandable for a great many people (even if it is also not particularly secure or careful about your consent).
I'm sure all these messenger apps (signal, imessage, whatsapp, and telegram) know it and wouldn't dare walk away from phone numbers at this point.
Syria was a very big market for it.
I'd prefer to see people go for a federated system (eg XMPP with OMEMO for E2E crypto) or work on truly decentralized ones (that one is hard, and blockchain is not a trivial solution ;-) ) rather than propose yet another system where somebody else can control who you can talk to (even if they can't see what you're talking about) as a replacement for the previous system with the very same properties, just ran by a different party.
So in a way this is Signal Protocol (the one "regarded as secure") with that "next step" of adding decentralization already taken.
Metadata is surveillance.
It is VC backed, doesn't require a phone number, everything is end-to-end encrypted and has apps for all major platforms (iOS, Android, Windows/Mac).
In Signal the remote Signal server will not deliver the messages, since anyway I can't decrypt them (there are no unencrypted messages in Signal) and it never keeps any that it has successfully delivered.
Now, if I convince the network that I have your phone number, how should your friends determine that I'm not you?
In Signal (and WhatsApp) this is designed into the UI. If you aren't sure if this is who you think it is, you can meet in person and compare numbers or QR codes to check there are no shenanigans going on. Many casual users never do this, but if something seems "off" you can verify.
But in Telegram there's no option like that.
nitpick, but I think you mean 'opaque', as in, they can't see it.
In Signal you have an identity that's verifiable, and that's what their verify step does. The keys constantly ratchet, and you can even both reset them from scratch, identity verification isn't affected.
In Telegram you set up a separate encrypted chat and the secret keys for it can be visualised. But if you create a different chat any steps you took to verify the identity don't carry over.