Informer: A bot library that allows masquerading as real users on Telegram
github.com
github.com
[1] https://telegram.org/blog/privacy-discussions-web-bots#view-... [2] https://github.com/pyrogram/pyrogram
Had I parsed Usenet feeds into a relational database, and called it 'mass surveillance', I'd have rightly been ridiculed.
Regardless, it can be useful to have message data in this format.
And yes, I admit the headline is a bit charged and its implementation does not reflect it as much as I would like.
It does not change the fact that I researched an implementation of Telethon for a use case I needed, and I didn't find it so I made it and shared it.
My involvement in ads and marketing had nothing to do with that. It's less nefarious, it just sounded cooler and was an innocent mistake in retrospect.
As mentioned above, I appreciate the mod(s) for taking the time and energy to edit the title so it reflected the implementation. This is my first shared project on HN and I am excited to finally participate and see the feedback/energy.
Thank you guys/gals!
That said, I haven’t checked deeper, if this bot is not actually using the bot API but MTProto, this is pretty significant as the bot appears like a normal user (and not as a bot, which are required to have a “-bot” suffix on Telegram).
That appears to be an MTProto library.
https://docs.telethon.dev/en/latest/concepts/botapi-vs-mtpro...
like what? I really have no idea.
If you want to validate identity as a service, then the only options you really have available are a central authority, or a web of trust. Both of which have serious downsides, and neither of which are offered by Signal.
If you can reduce the trust problem by requiring every person to verify out-of-band the identity of every one of their contacts, it becomes a lot simpler. For some Signal users, such as the person you replied to, this appear to be the case.
It represents more than just a crawler if you have an imagination. That said, I was looking for a solution for one of the listed use-cases and none existed so I did something about it and shared it and now one exists. It takes no creativity to deride a work, and enough to make one and put it out there.
Getting both sides of the feedback has been a fun learning experience and looking forward to putting more out given the amount of feedback! Thank you both :)
Sure, there are edge cases, like being on a plane and only having bought internet access for your phone, phone battery dead and no charging cable, phone lost/stolen, but those things seem rare enough that most people just live with it.
I would prefer that I didn't need my phone to use WhatsApp Web, but in practice it hasn't kept me from using WhatsApp (mobile or web).
That doesn't sound right to me. It may well be the case for a particular implementation, but I don't see why it would hold for the general case.
When you do this, your other devices are informed of the account change by the server, as are people you communicate with (if they've previously marked your account as trusted, changing any devices on your account changes that). This isn't much different to Signal: ultimately the server acts as a key directory in both cases.
The problem with this approach is that it doesn't scale well at all. This is why Facebook, Wire etc are working on MLS (Messaging Layer Security) which is basically "add trees" so group chat scales better.
It seems to me that double ratchet is really to blame here. Without it, you could simply share a single key across all devices. With it, your choice is to either deal with this sort of complexity or to set up a trusted proxy in the middle.
It's a bit strange actually. There's this constant mantra of having to pick either security or usability. We now have readily available means for usable _and_ reasonably secure E2E, but the crypto nuts go and add additional "must haves" that once again make it difficult for the average person to use.
An aside: Instead of authenticating with a central server to add a key (as you've described Wire doing), why not handle this client side via X.509 certificate chains? This is very mature crypto and seems far more flexible. It would enable use of standard PKI token hardware for managing your root identity, allow fully offline enrollment of new devices, and provide cross signing for various purposes (changing your root identity, setting up a web of trust with a group, integrating with a corporate environment, etc).
> Multi-device E2E requires ONE device be the source of truth for the private key.
To this:
> That's why for WhatsApp Desktop to work, you need your phone to be connected.
Is just an implementation detail. Signal gets around this by letting server know about person's devices so that each device can sync independently of others. Phone holds ultimate key, but messages do not need to be routed through phone.
Also from all my group chats and I have hundreds 99% are public or semi public (not searchable in telegram but can be found on the internet) it make no sense to encrypt this.
The problem is that they're allowed to get away with it and the "4% of global turnover" fines are yet to be seen.
I'm not sure what kind of open source apps leverage it, but I would guess there is something.
Similar discussion from previous HN thread:
It's all relative.
Former head of the National Security Agency Gen. Michael Hayden
I don't see any negative ethical aspect to be honest.
>Potential Business Applications:
>Sock puppeteering to overthrow a despotic regime
>Brand monitoring and sentiment analysis
>Shilling cryptocurrency at a moments notice for financial gain
>Influencing sentiment on topical issues
>Getting in on price action early
>Running analysis of a telegram channel
While some of them are arguably unethical, some of them are almost certainly not.
Do a search for "site:telegram.me" including a keyword from any illegal activity, such as carding, and you'll find hundreds of channels with interesting behavior.
* Send and Receive Messages with the Telegram API https://medium.com/@wk0/send-and-receive-messages-with-the-t...
* Running a Serverless Telegram Bot from AWS Lambda https://medium.com/@wk0/running-a-serverless-telegram-bot-fr...
* Integrating Your Serverless Telegram Bot with AWS API Gateway (published today) https://medium.com/@wk0/integrating-your-serverless-telegram...
I can finally build by telegram-to-rss project!
Inspiring actions