The moment a product is "secure by exception" rather than "secure by default," a huge benefit of E2E encryption is immediately thrown out the window. Sometimes the simple knowledge of which conversations are secure, and which aren't, is more valuable than the content of those conversations.
Furthermore, when everything is E2E encrypted, mass surveillance of message content is essentially quashed.
Don't get me wrong, the Telegram crypto can (and should) definitely be criticized. But please criticize that they use "bad crypto" or "strange crypto" or "unreviewed crypto", not that it's their own. (And of course, substantiate such claims with references that can be discussed.)
(the criticisms are well enough known that people either aren't going to listen or can just go read them)
It’s almost as if your cognitive time series is not the same as everyone’s.
(why the parens)?
1. Folks spear-heading the Noise Protocol Framework (upon which Signal's protocol is based) are cryptographers [0].
2. They built upon existing standards for one specific purpose: Creating two-way secure channels [1].
At some point in time, all now well-established cryptographers will have developed their first own cryptosystem, without already having established a good reputation. Whether or not someone develops a cryptosystem without being famous for cryptography work is simply not a good argument for discussing a cryptosystem. The properties of a cryptosystem are a good argument for discussing it.
All protocols are invented at some point. Telegram did a terrible job marketing this one but it has been a long time now and the only issue I ever heard of was fixed some years ago. It's still not exactly pretty, but then look at TLS and I'm actually quite okay with mtproto.
The real issue is that mtproto is never used. It isn't implemented in most clients for no apparent reason ("can't keep state for encryption keys!" is the usual excuse - dude you keep my login token what's the big deal here) and if you try to use it, it doesn't sync between devices. One of the core selling points is a solid desktop experience.
And I can't tell if Moxie really means to improve the status quo or works for some three letter agency and builds just enough metadata opportunities into popular messengers and opportunistic encryption into WhatsApp to be helpful without being suspicious. To avoid redundancy, I posted these only yesterday and it includes some of the reasons: https://news.ycombinator.com/item?id=25669531 https://news.ycombinator.com/item?id=25669267
They don't cover everything unfortunately but I'm also getting annoyed with the ephemerality of HN. What's posted last week is forgotten and never looked at again. I can try to find old posts that cover it or type it all out again (and it's a big claim so very few people will even take the time to read a big comment with reasons in the middle of another thread). I'm also not denying he does good stuff, just that there are enough weird opinions (decentralization = evil, anybody but us = evil, bug bounties = evil...) that I carefully look at what he makes and would rather there were better alternatives than their central servers.
Signal is still the only realistic messenger to use for good security and usability, unfortunately. Wire is a good second but Signal is definitely more smooth and I'd still recommend that to the general public, with the asterisk that it's an American company and that they should try Matrix if they're feeling adventurous (Wire falling somewhere in the middle, at that point you might as well try Matrix).
Not a fan of Moxie either but you got a source for that?
As if Moxie having opinions that you don’t agree with is evidence for some covert NSA operation or some such. What nonesense.
Moxie is an anarchist (or near to it) and has been so for a long time. Secretly working for the NSA would be a stupendously long con.
> it's more of a hyperbole than something I truly suspect. It's just that their opinions are in line with the hacker community 50% of the time, and in line with surveillance organisations the other 50% of the time. Of course, he always has some reason for having the opinion, it's all covered up just fine, so it could also be perfectly legit. It's just weird to argue both sides at the same time.
His being an alleged anarchist, how does that hold with the prohibition for forks to use Signal's servers? Or the insistence that Google is the only place you should get the apk from? Shouldn't we all build from source, not trust a central distribution point? They argue both sides and I find it hard to tell what they really believe in.
That said, I definitely see your point and, as said, he does plenty things to improve the status quo. It's just his rejection of other things that would be even better.
No, you can but are not forced to. There is compiled apk (that autoupdates) which you can get directly from their website.
At this point, Matrix, Threema, and Signal are some of the more popular cross-platform solutions left to ponder about. Telegram nor WhatsApp are answers to any privacy question anyone may have.