Security professionals often warn against Telegram
wired.com
wired.com
The user experience is great, and I like the service in general. The fact that it's not tied to an advertising company that is profiling users and making money of it is of course the biggest plus, but please stop with the whole "totally secure" BS. It's confusing and is probably even hurting their image: I have had to explain multiple times to friends and family I finally moved off of WhatsApp that we did not do it for the security, but rather to be free of being mined for personal data... Same thing goes for these non-tech 'news' sources that make a big deal out of it as well, while it's totally obvious if you investigate a bit more.
(Apologies for the rant, I guess had to get this off my chest.)
I actually wish Signal had a "trade some security for convenience" option like that.
https://support.signal.org/hc/en-us/articles/360007059752-Ba...
I don't want my data mined and sold so Facebook can profit from pushing ads at me, I'm not worried about someone hacking into my messages.
So yes, even the article TITLE is wrong. No, it may not be more 'secure', but you'd have to be a fool to argue it isn't more 'private'.
This article is absolutely paid for by Facebook, no doubt it my mind.
> Telegram's MTProto protocol isn't obviously broken in a practical way, concedes Matt Green, a cryptographer at Johns Hopkins University who has consulted for Facebook on encrypted messaging systems. But it's uniquely "weird," he says, in a way that suggests its inventors don't understand tried-and-true cryptography practices and raises his suspicions that it may yet have undiscovered vulnerabilities. "It's like if everyone else in the world has agreed that we're going to use drywall to do the walls in a house, and then you've got somebody who's using toothpaste," says Green. "Even if the toothpaste works and makes a nice wall, that's weird. How do you know they're not doing other weird, nonstandard things when they put the electrical wiring into the house? And that's what scares me."
I prefer to give the benefit of the doubt (maybe this guy is just terrible at analogies?) so I’m not sure I’d say facebook definitely seeded the article but this is just such a wacky, nonsensical thing for someone to say I don’t really know what on earth to make of it.
...Thats not how maths works... cryptography is just math.
"You're not doing it the way we did it, so we're assuming you must be doing other nefarious things as well."
That's some pretty serious hubris and not something I've seen before in the crypto space. I've just always assumed most of the people in crypto worked together to build a better product which seems to be constantly under attack from governments. This is the first time I've seen one group call out another group simply because they didn't do it "the FB way"?
Is this just some healthy competition between two competing products or is FB actively trying to undermine Telegram's product??
I mean, bonus point for the disclosure, but why should I believe is any word of that quote?
It has secure options at least. But importantly doesn't require my phone number to create an account and contact people. But also has a lot of features that are missing in something like Signal.
Signal is my preferred option, but I'm not keen on sharing my phone number with everyone.
Documentation is still lacking, but if you want you can reach me directly to help you set things up.
I wouldn't even mention Matrix to get someone started. But this page will lead them to the Web App and mobile apps. By default they will sign you up to the matrix.org homeserver with E2E encryption. It is a great way to get people started. You can then send them a link to your profile or they can find you be email or phone number if you have verified those.
What if I want to host my own instance? Can I communicate with people who are signed up at element.io?
I will give it another try based on your info.
The fact is that many Americans would prefer to have their data mined by the KGB than by the FBI.
Which do you think is safer:
- The FBI can easily read all your messages, but they're not allowed to.
- The FBI is allowed to read all of your messages, but they can't.
Anyway, the sibling comment at https://news.ycombinator.com/item?id=25946537 is right.
Very large groups, if that’s your thing.
You'll ultimately have a make a descision based on who you trust more.
Not a telegram fan at all but their clients are also open source
But Telegram has one big advantage - they publish a public tdlib library with which you can easily build your own Telegram client.
Everytime this story comes up it just complains about the default setting.
Terribly reasearched articled. It offeres no insight to HNers compared to previous discussion. A bad workman blames his tools. Defaults are powerful -- I will concede. Not understanding defaults counts as not understanding your tool.
I don't even believe WhatsApp is E2E but I've no evidence to proove that -- I'm just that skeptical of FB. I believe FB are reading WA messages but again -- nothing to base that on other than FB being heavily incentived to do so.
It’s not an article, it’s a hit piece. Established publication protecting established vendor. Classic Wired.
If something has changed feel free to correct me, but as far as I know MTProto is still all in-house closed source code and hasn't ever been audited.
https://news.ycombinator.com/item?id=25722076#25724978
One note: Telegram doesn't need to "allow" experts to audit their code - E2E is all in the clients which have source available. I don't think it's had enough scrutiny to be trustworthy though.
But only mobile clients, no E2E on the desktop or for groups sadly.
https://core.telegram.org/mtproto
https://github.com/tdlib/td/tree/80c35676a2eb1e9b71db355ee21...