Telegram: No-SIM Signup, Auto-Delete All Chats, Topics 2.0 and more
telegram.org
telegram.org
I think sites like Discord just assume you'll install the app and that browser users are just boomers or the 0.1% who are more security+privacy oriented.
Is there any decent lean client for Discord? Chat only, no voice or whatnot.
I don't think so. When you own a lot of crypto, and have lots of real dollars (Pavel has lots of real dollars!), you can manipulate price a little bit.
In 2019/2020 Telegram had to give investors all their money back, and the new TON project started without venture capital with a value of 0$. It's now 1.84$.
If their market makers are sophisticated enough, they will create enough liquidity grabs to sell telegram's TON bags over time for a nice sum.
I think they are aiming for creating a market + "eco system" similar to ETH.
Sigh.
Charge users directly or GTFO.
Seriously. If the product is "very secure messaging," then come right out and say "very secure messaging costs money, pay up."
Doing anything -- ANYTHING else lets me know they're not serious about the mission.
It's a typical freemium model. I'd subscribe if I were certain that my money won't be going to Russia.
Not a great way to monetize in one of the larger markets.
The networking libraries may be fine. The UI could be completely rebuilt.
(Sadly, I don't have a ton of cash, or even a ton of time, to dedicate to such things.)
Telegram launched a silly username auction that I won't link here. It essentially turns usernames into NFTs.
They need to make money somehow? Not really an issue for users who don't care about unique usernames.
I really hate being forced to invent a nickname and be hard-glued to it forever.
Similar to how ICQ low digits used to be sold.
Private keys as a form of identity can't possibly work in the real world.
Because you just said people lose their passwords all the time. So then what?
Unlike private keys they can also enter them in other sites, reuse them, and get phished and much more.
But yes, private keys bad! because they are cryptography and cryptography is crypto and crypto is scams and grift and there is a whole new cargo cult we have to be in now…
But if it's a private key, you lose it an it's game over. You have to create a new identity and start over with everything that was tied to your old one. Worse yet, if you leak your private key, you can't stop other people impersonating you.
Also, everything you said about resetting passwords can be done for resetting private keys too. The difference is that you don’t go around reusing it and typing it into phishing sites.
And if you think getting access to an account where you are totally butt naked and forgot the password is normal, I have a million gmail users who would love your wisdom.
With a government-issued identity document.
The trouble is, of course, that this organization can have corrupt employees issue the credentials to anyone if the amount of (social or moneyary) capital to be stolen is large.
And furthermore, the credentials like an identity document can be trivially copied and presented online, by anyone you ever presented it to. So can credit cards.
Identity Theft is quite common around the world since many organizations allow people to make accounts over the internet, without even notifying your phone about it.
And finally, by trusting the government with your very identity, you give them the power to encroach further on your privacy:
https://www.techdirt.com/2022/06/29/california-legislators-s...
https://www.theregister.com/2022/02/28/online_safety_bill_do...
Since you are against relying on cryptography for authentication and instead prefer to rely on the government to supply your very identity, I suspect you wouldn’t have a problem with requiring a passport to use Facebook. But perhaps you’d have a problem with what they will do NEXT once everyone is required to collect this information from you. After all, “crypto bros” are just about ponzi schemes right?
Send a QR code or a link that can be used only once.
Why have an identifier that any number of people can use to contact you?
I most often have to spell my contact details in a voice phone call because my primary job is to communicate to live people all over the world, not to code. Believe it or not but people actually call my office desk phone regularly (although I always prefer email if possible). Even in the IT sector (let alone administrative tasks, healthcare, utilities, etc), whenever you need a rack in a datacenter, new servers or whatever you often are meant to submit your phone number on their website and then they call you. Some very big Internet and datacenter operators don't advertise any ways to contact them other than by phone, some would publish an email or a contact form but ignore you until you call them.
> Why have an identifier that any number of people can use to contact you?
The same as the above.
It still covers a lot of mundane communication cases.
No worries, I'll do it for you: https://fragment.com
Source: https://www.telegram.org/blog/topics-in-groups-collectible-u...
To answer your question - the point of a blockchain would be a universal and uncensorable key store the Telegram client can point back towards. The fact that Telegram is centralized is less important when messages are encrypted. It would still in theory offer a way to bootstrap connections with people that is less vulnerable to censorship than relying on a central server, but I don't know and won't speculate more on the details of the specific blockchain they are using.
Telegram, now with integrated scamweb™!
Many reasons why Telegram is (most probably) safe. There are a lot of black/gray area stuff here like drugs etc. That people (i don't support them) trust Telegram showing us it's secure.
And the Telegram's owner (Pavel Durov) relocated from Russia for ever due to issues with his previous project (VK) when goverment asked to show private/personal data.
No, if some people trust some service, it doesn't mean that this service is secure.
The only real reason ex-Soviet drug users keep using Telegram is they are careless and it's popular. Another suspicion of many is that most of the drug trade in Russia is under FSB "protection", and they have no reason to kill the goose that lays golden eggs. Drug dealers only run Telegram for their clientele though, with anonymous SIMs and Tor; for more serious purposes, they and other criminals use more secure communication channels, XMPP in particular.
>the Telegram's owner (Pavel Durov) relocated from Russia for ever due to issues with his previous project (VK)
...while keeping Telegram developers in Moscow and regularly showing up there himself. (no idea whether it's still true, probably not)
I can't say with 100% confidence that Telegram itself is compromised, though, there's no clear evidence for that. Some smoke probably, but no fire, sketchy indeed.
In China, too. With a more aggressive approach: just remove the app before going out.
Literally nobody in their sane mind does that.
I haven't seen anyone show that Telegram uses bad encryption. I've seen plenty of people repeat the "don't make your own crypto implementation" mantra, but just like the "don't optimize prematurely" truthism it's not always true. Where's the exploits?
And then there's another reason, most communication isn't particularly sensitive. Dinner suggestions, memes, thoughts on the latest season of The Crown... I chat about the same things that I talk about on the unencrypted phone "line", or at a cafe surrounded by strangers. If Telegram turns out to be unsafe, I wouldn't have any issue with continuing using it for everyday stuff, and using a different app for secrets. Compartmentalizing is probably a good idea anyway, I use my real name on Telegram with my family.
Literally a week ago in India: https://torrentfreak.com/telegram-discloses-user-details-of-...
> I haven't seen anyone show that Telegram uses bad encryption
The bigger point isn't that Telegram uses "bad encryption", it's that it isn't encrypted by default in all scenarios. This is a conscious choice they've made.
> If Telegram turns out to be unsafe, I wouldn't have any issue with continuing using it for everyday stuff, and using a different app for secrets.
Great, now every time you're talking on the "other" app the State knows you're talking about something sensitive. The point of encrypting everything is to ensure that encryption - by itself - is not a sign of illicit activity.
That wasn't by breaking the encryption, it was by court order.
> it isn't encrypted by default in all scenarios.
It is using encryption in all cases, but it's not using end to end encryption in all cases. I know plenty of people will argue that it's the same thing as no encryption, but by using encryption you then force anyone who want's to eavesdrop to go through court to get the data from Telegram, and not just listening on the same Wifi network. Saying it's unencrypted is disingenuous.
How successful have those protestors been? In each case it seems like the government was always one step ahead of them and all there. So I don’t think it’s a giant leap to think they’re communications are compromised.
The FBI says they can't get message content, and only IP and phone number for convicted terrorists.
https://www.malwarebytes.com/blog/news/2021/12/heres-what-da...
End-to-end encrypted (by default and for all chats) messengers exist, but Telegram simply isn‘t one of them.
Other than Signal, Telegram is one of the very few messengers that happens to be both E2E capable in some way, open source, and sufficiently heard of that people won't give you weird looks when you suggest downloading the app.
Telegram is not end-to-end encrypted in any practical scenario (you can‘t use it on multiple devices, for example), their end-to-end encryption uses some ridiculous/scary homebrew cryptography ("with the power of 5 math PhDs and a bug bounty worth millions!!!"), and being open source doesn‘t help a bit if the service provider just gets everything in plaintext anyway by default.
I haven't looked at Telegram's blockchain thing yet, but the non-blockchain version is not very private (and the same applies to Signal).
xx Messenger (https://elixxir.io/; source https://git.xx.network/elixxir/) has very solid encryption, metadata protection and decentralized gateways. But it's less polished, blockchain-based, and has few users.
People complain about the use of blockchain in messengers, but they offer no solutions on how to address app sustainability or eliminate metadata centralization, censorship, or risk of having your data handed to the government by the organization running the network. We'll see how sustainable your centralized donation-ware is.
Btw somebody mentioned "only" 1:1 encrypted chats: who does it better?
xx Messenger can do group chats but you can't add people to a chat after the group has been created.
What are you missing on Signal? The ability to sign up without a phone number would indeed be great, but other than that, they seem to be collecting effectively nothing.
> People complain about the use of blockchain in messengers, but they offer no solutions on how to address app sustainability
If this is about funding, just make it paid/freemium! Effectively that's the same thing as launching an own token or even blockchain, just without all the complexity of launching and sustainably managing what might easily become a pyramid or Ponzi scheme and/or a security in scope of regulations.
> Btw somebody mentioned "only" 1:1 encrypted chats: who does it better?
Signal, and everything based on it (e.g. WhatsApp), Matrix, and Threema immediately come to mind, and they all don't have this weakness:
> but you can't add people to a chat after the group has been created.
I'm not willing to have all of my personal communication sitting in plaintext controlled by an unprofitable company founded by Russians and located in the UAE. Even if they're not compromised, that's an incredible target for a state actor.
If you want really safe comms I don't know if any popular chat app would do the job, maybe signal? don't know much about it however.
For the few that don't I have IRC, email, sms, phone calls...
Never used WhatsApp, Telegram etc
What I am saying: it depends on your individual bubble and where you come from. ;-)
- Accumulate data and try to use it for mass manipulation
These are from the top of my head.
What makes you stating that so undoubtedly?
Why ? Are you russian ? Do you travel to Russia ? A lot of people also trust WhatsApp and Signal for their communications and i'm sure that no western government will ever spy on them. I'm joking.
Just be aware that encryption is not useful when your OS provider has access to your keys.
That the cia has got far more leverage on it than any other foreign powers
It is used fantastically by them on the current iran unrest and as a medium to pierce against Russian information spheres
Where zunzuneo failed telegram has succeeded and blossomed
also, Telegram has no ties to Russia
who had his billion dollar business (vk.com) stolen by the russian government, left the country and acquired cirizenship elsewhere
it's a pretty good indicator that he is not a putin's stooge
>most of the engineering team is Russian. The founder visits Russia regularly. I assume their non-resident Russian engineers visit Russia too.Most of their user base is Russian.
is Microsoft an Indian company? the CEO is Indian, half the engineers are Indian, yada yada yada
>And they have an agreement with the Russian government not to be blocked if they cooperate on combatting terrorism.
I got the impression that it was just a way out for the russian government to give up on trying to block it, after they have repeatedly failed to do so
This seems like a pretty big leap from true username sign-in, and I really like Telegram.
'Anonymous login' seems extremely misleading in this case.
There's a reason that a 2017 study called Telegram the [security blanket of the chat world](https://www.researchgate.net/publication/319622415_The_Secur...).
If signal wants to be seen as better; third party clients are a huge step.. Failing that: provably P2P messaging.
As it stands it's only really "better" on paper, you still have to trust the network provider.
That’s a really weird way to say: aggressively discouraged.
https://news.ycombinator.com/item?id=26469007
https://techjaja.com/whatsapp-shuts-down-users-of-3rd-party-...
Signal had a bug where it sent private photos to random contacts, so it seems like that can't possibly be called safe either, if they're making junior level UI state mistakes like that (it's also not E2E encryption if the app switches one of the ends without your consent).
Are you saying it's impossible to do anonymously, or just that it's not anonymous by default?
1 TON currently sells for 1.83$, by the way.
Does Coinbase have TON?
Buy TON Token with Coinbase Wallet
TON Token is only available through Coinbase Wallet. Assets on Coinbase Wallet are not held by Coinbase.
For reference, the list of exchanges is here: https://ton.app/exchanges.My gripe is that how awkward the whole process is, especially the fact that you're locked into using Metamask to be able to transfer TON into their network via bridge.
I wonder if relatively small number of people who are able (and willing to) jump through all these hoops will stand out like a sore thumb and this in turn would actually reduce anonymity.
Do you think it's accurate to call it 'anonymous' when it's not in 99.99% of cases?
What nation states even have the capacity to collect (a lot of) metadata on all connections that happen anywhere on earth? They'd need to see you connecting to the VPN (easy), and they'd need to see the VPN server connecting to the mining pool server (hard unless you have access to a lot of backbones), and then correlate that data. Add additional VPN servers to make it harder as you wish.
I'm pretty sure we could narrow it down to a handful of states having the ability to get data from a lot of the web, so unless your beef is with one of them, you're pretty secure.
What I don't understand though is, why they don't just ask for money directly instead of using the fake number as a roundabout way.
However why the fake number? Why not ask for money directly?
The codebase is a good point, hopefully this will be fixed in the future.
Backwards compatibility probably? I think having a phone number present is built so deep in the architecture that it’s easier to add a fake number than change it overnight and wait for universal adoption of new client versions.
WhatsApp Business allows landline numbers too, by the way.
And for the purposes of anonymity I am definitely more fine with a landline than any method that requires me to make a payment
I don't think it's something they make very obvious. It also used to be broken for non-US numbers for more than one year at some point...
xx Messenger also doesn't require any identification. And unlike Threema:
- it's open source (https://git.xx.network/elixxir/); Android users can build it on their own and load from F-Droid
- it uses blockchain
- no big attachments for time being, but once they come (in 2 months, I hope) they'll be affordable and stored encrypted on IPFS
- no data collection of any kind
- (my guess) better privacy and security
- less polished
- optionally searchable by in-app nick or phone number, or not, in which case you get a cryptographic ID. Identity can be backed up to SFTP and restored from it
Unlike Telegram, xx Messenger app has a publisher, but the app can be installed independently (F-Droid) and there's no centralized entity that runs messaging gateways that can deliver any data about your identity or communications.
Not related to parent comment, but I see some people are bitching about the use of blockchains as if they've figured out a way for Signal or Telegram to provide for their messaging needs without selling ads or metadata.
If funding free messengers was easy and blockchain merely a distraction, Signal wouldn't have those pop-ups that reminder you to donate.
You can try with VoIP, usually works as well.
The point is, some people seem to assume that "no-SIM" means "anonymous", but to many others "no-SIM" means just "without a need for a mobile phone/number". So it's just a question of interpretation. There are many uses for "without a mobile number" that don't have the "anonymous" requirement.
Which I can see the point of for a good app, which it is. But in terms of "anonymity for the masses" it's a hard sell when you could use Element with roughly the same features if less stability.
Instant no thanks and no deal.
Is Telegram supposed to be private? I always thought they were more security than privacy focused. Now how do you allow private and secure messaging without being overrun by every bad actor on the planet? They'd flock to the platform if there were no hurdle to account creation or ensuring authenticity.
Handle payment like Mullvad?
Banks have a different threat model, and while I can be reimbursed for stolen funds, it‘s not exactly possible to "un-leak" personal messages.
This is beyond bizarre: They are selling numeric-only identifiers (for no technical reason), looking like and clasing with a namespace they don't own, for money that they made up.
I literally spat out my coffee. What nerve.
Telegram disguises itself as an encrypted chat app, when it is actually just a regular centralized plaintext messenger that has an encryption feature that nobody uses.
Don't walk. Run.
https://www.livelaw.in/news-updates/after-court-order-telegr...
Ummm, but are our raw messages being stored at their servers, in a form of encrypted data-at-rest (such that no one can get to the message on the hard drive, if stolen, powered down, or an errant process accessing them ... without a key),
... AND are the keys being kept only on the clients' side (such that keys are generated only by client-side and its keys are never sent to Telegram servers)?
I didn't think so.
Nope, and that's why I use it!
I like the fact that I can just open it on any device and have my chat history available. I like the fact that damaging my phone doesn't lose me access to my contacts or chat history.
I'm more worried about usability and UX than I am whether Ivan Kgbinov is reading my insipid chats.
Screw you, telegram. I'll stick with open-source Jitsi Meet hosted on my own Debian Virtualbox machine using DDNS and Let's Encrypt so I can give people a link to instantly be in text/E2EE voice chat with me. No software. No app. No login. No password. Just over the browser WebRTC.
Just type in any name you want, give the link to a friend and bam.
I don't have a Facebook messenger and believe me that's bad enough without also ditching Signal because eww phone number, Threema because eww nonanonymous payments, Telegram because eww no encryption, Element because it's unstable and I don't think my mom (let alone my grandma) would be able to use that UI effectively, Briar which can fundamentally not support voice calls, Jaimi which is about as stable as Windows 95 at launch when I tried it (and this wasn't an early beta, it was called Ring before iirc, it's gone through years of development), Wire which runs on USA infrastructure and isn't focusing on consumers anymore, et cetera and so on and so forth. I've actually got most of these apps and it's already hard to find common grounds when literally everyone else has Facebook's WhatsApp and they're wondering why I'm being difficult if they're not techies or privacy nuts themselves.
I'd rather have nothing to do with weirdos who require an "app" to communicate, and I say that having been using voice chat online since Iparty. (1997)
Iparty. Battlecom. Roger Wilco. Ventrilo. Teamspeak. Skype. Mumble. Discord etc
Until recently, you could host your own server on most of these. I want to go back to that. I'm sick of relying on other people for things to be up. Jitsi Meet is great.
Also I suspect you're trolling everyone.
Do you need to give a phone number or even email address to get on IRC? No. What about Ventrilo, Mumble, or Teamspeak? No. What about Skype? Yeah. Email.
Email is about as far as I go. If they want more than that (phone number etc) they can fuck off. How is that out of the ordinary? Because I'm not a cell phone newbie to the internet? I've been here for a long time and the personal information demands from all these piece of shit "services" are egregious when we have open source and self-hostable options that STILL WORK.
Telegram is not worth recommending to anyone until they require SIM (or some Blockchain nonsense) and all chats/calls/content is not E2EE by default, even Whatsapp is safer option, if you don't want some proper alternative like Matrix (Element, FlufflyChat), Briar, Session etc.
What does the hn crood think about it?
IPs are a bit tricky to handle though, because they're required to be stored for session management since Telegram is cross-platform and has independent multi-device login.
This low-tech "attack" would also work even better with WhatsApp and Signal (better because in Telegram secret chats don't get shared between multiple devices while in WhatsApp and Signal they obviously are - cause every chat is encrypted).
they've been doing blockchain stuff since 2017: https://en.m.wikipedia.org/wiki/Telegram_Open_Network