Telegram has launched a pretty intense campaign to malign Signal as insecure
twitter.com
twitter.com
This would be the same case for Telegram as well, if someone has your phone. I believe that Signal can have a lock on the client, and the database is encrypted.
The other part that Du Rove conveniently left out: Signal went against the US courts and won [0]. When subpoenaed to give all user information they gave them all that had: the unix timestamp of when the account was created, and the last date you connected to the signal service. That was in late 2021. I'm really curious as to what Telegram has told the FSB.
[0]: https://signal.org/bigbrother/cd-california-grand-jury/
The bigger problem with Telegram is that it by default has insecure encryption settings (as opposed to Signal, where encrypted is the default, you need to manually activate it with Telegram + I think it's not possible to enable for all chats and clients) and to my knowledge, Telegram will outright co-operate with law enforcement agencies to just hand over unencrypted communications. I'd personally argue that's a security dark pattern - make privacy a big selling point, but then don't activate the security by default
pretty similar to whatsapp. they boast end to end encryption, but business account (all of them now) uses the facebook server's key, so that the business can give access to several other clients to answer customers. they still call it end to end encryption, and this was actually the last crap the original founder accepted before leaving with lots of money on the table.
I use WhatsApp dozens of times a day, and interact with business accounts every couple months at most.
In most of the global south, 100% of business have a whatsapp. In those places it pretty much replaced telephone and the green whatsapp icon is now what the current young generation recognize as the we did the black telephone outline on a business front next to a number.
and if you own a business, or is self employed, it is even worse: you live by that app.
As an expat, this feature has enabled me to transact with locals from the convenience of my phone, even though i don't have any local line and i will not bother to get a local SIM card, nor do i want to have a US SIM and a local one interchangeably.
It also enables me to be very effective when requesting services on demand, and cutting thru the on-hold time, disconnected calls, or the needless chitchat.
I have many bad things to say about WA, but making living more difficult in a foreign country is not one of them.
Telephony is an artificial monopoly. There's not a single reason why you cannot call everyone around the globe for mostly free, as whatsapp proves. Yet here we are.
Considering the state of Saudi Arabia, having it there is marginally better, but still problematic.
And if the developers are still Russian, there's nothing saying they aren't being squeezed unless their families came with them to Dubai.
I think it's a great approach instead: the secure, end to end encryption is there and it's ready to be used.
You can easily activated it but you aren't burdened by it for 99% of the time when e2e encryption is not needed.
So, in those 1% of the cases when you actually need it, you're instantly flagging yourself as doing something fishy? Because if it ever comes down to it, good luck proving otherwise in a court.
That's like the whole point of why it should be on by default. Not because me making dinner plans is something super-secret that needs to be e2e-encrypted, but because those two scenarios need to be indistinguishable from each other for e2e to be effective.
For exactly the same reason if you have a paper shredder, you don't only shred confidential material, you shred a bunch of junk as well to make it harder to find which pieces to reconstruct.
But they gave the FSB info they asked for -- the vk.com website (facebook clone, at that time it had way more massive amounts of user data than telegram). They could have deleted the data, but no, they handed it over to FSB.
This is a deeply funny sentence.
"Other than that, Mrs. Lincoln, how was the play?"
Since he is Russian in origin, it's okay to throw baseless accusations at him and spout nonsense like "maybe they're FSB agents" or "maybe they hired an FSB agent without knowing it". You see it here everywhere, and HN is one of the better sites in that regard. Well, maybe Signal has hired an NSA agent and doesn't know about it either? How does that sound?
It wouldn't be the first time a cover story was ever used.
> Well, maybe Signal has hired an NSA agent and doesn't know about it either? How does that sound?
You should presume they're trying. I, frankly, presume they've succeeded, either in placing an agent or by compromising something, in virtually every prominent messaging platform.
I'd argue it's not giving us any certainty. They could've moved away to escape. They could've moved away to a nice FSB-sponsored location while making good publicity. Ideally the tech should be good enough for this issue to not matter.
Singling out Telegram, or Signal, or any other service's devs is not advancing any argument forward.
Partly because it’s insecure by default, which makes a large percentage of conversations vulnerable.
And also because the team behind it is very susceptible to pressure from the Russian government, which is especially bad when it comes to these things. Even if some of them are based out of Dubai now, it doesn’t mean that they aren’t still at risk of coercion, either directly or through for example threats against family members who remain in the country.
If you don’t trust Russia, which you shouldn’t, then don’t trust Telegram with anything sensitive.
I for one trust that there are more Americans who would say no to the NSA when they have a legal basis for doing so than there are Russians saying no to the FSB.
The state of the rule of law is certainly not great anywhere in the world right now. But it's far worse in some places than in others. The difference still matters to some degree.
No, we cannot, so yours and other comments come across as picking favorites. As an Eastern European I'll state that I distrust USA as much as I distrust Russia, China and North Korea. All nations with ambitions use every dirty trick known to man.
Not to mention there's not much reason to trust UAE any more than there is to trust Russia.
As for E2E encryption, eh, this topic has been beaten to death many times. Its UX is difficult so many apps like WhatsApp and Telegram do UX tradeoffs, quite successfully so I'd say.
If Dubai had to pick between letting some nobody foreign national living on their soil get squeezed by a foreign secret police, or pissing off the Russians, what do you think they would do?
(This isn't a knock on Dubai specifically, substitute them for almost any non-NATO country in the world).
Where Telegram's devs and business resides hardly matters IMO. If somebody truly wants to put them under their boot they'll find a way, and that goes for probably half the countries on this planet.
Also: this whole topic is about a Russian company/app and Russian citizens living in Dubai. What other country would we be talking about here, exactly?
If so, OK.
https://www.nytimes.com/2024/02/20/world/europe/russian-pilo...
If russia wants to find and kill you they will.
If whatever State/Government wants to find and kill you they will.
Guess you never heard of polonium either.
https://www.theguardian.com/world/2016/mar/06/alexander-litv...
Still no idea what your argument is. Or that of the grand-parent comment. "Oh look, Russia is poisoning people!" Yeah, we knew that ever since the Cold War. Show me a nation that doesn't persecute people it doesn't like.
This is incorrect. Check your facts. They're made up.
As nice as it would be to not have to provide that information, Signal proved that the only information they have to give is largely useless to law enforcement.
Signal prepared ahead for that eventuality and designed it so that their services received stored only the absolute bare minimum of information, and that most importantly didn't preserve the metadata of chats and calls. This is unlike Meta, for instance, which does keep that data for WhatsApp even though the chats themselves are encrypted.
That means that what they provided in that particular subpoena is all they can provide from their server records for any user of Signal, not that it's all that was available in that particular case.
It would've been even more anonymous if not for the phone number requirement, but I can understand why they made that trade off and given the lack of metadata it's not that useful to law enforcement/surveillance agencies in any case.
I'm confused. Signal also has your phone number because they require it, that's the primary privacy criticism against Signal.
The usernames thing does not address any interesting concern. I don't care to show my friends who I chat with my name and phone. They already know these after all.
What I care about is not having to give Signal (the company) my phone number. That's not something they should have.
Signal rejects F-Droid for a different reason, though: They only want to distribute through channels where they get download statistics and control update rollouts.
I'm not sure what sort of "control" they have over the Play Store compared to f-droid, but I'd rather have a trusted 3rd party do the building transparently and verifyable.
It's of particularly high need on mobile since popular apps, even those who were originally FOSS, are sold to scummy publishers who fill it with ads and subscription schemes (oft called anti-features, since removing them could be seen as a feature in and of itself), ruining the original. You can't really trust mobile app devs because the track record is downright awful. Recently that happened with the "Simple" collection of apps, where the Play Store version got filled with junk but the F-Droid maintainer froze the version and marked the apps as outdated since nobody could conceivably want the new versions.
Of course, that strokes poorly with developers who a. don't want to deal with potential third parties in their distribution chain rejecting their updates or b. are planning to add anti-features to their apps later down the line. With signal, I'm gonna guess it's mainly a; the Play Stores checks and balances are much less invasive than the sort of thing an F-Droid maintainer might check for. (As I understand it, Google Plays checks mostly are anti-exploit and keyword scans.)
That sounds like a feature you want when using FOSS.
Imagine distros wouldn't have been able to intervene quickly and malicious xz would be still deployed through their channels just because the authors want to.
FOSS isn't really the important part for me there; it's nice, but the real value is that F-Droid is pretty much the only app store that has some reckoning on how the relationship between mobile devs and mobile customers should be far more adversarial than on any other platform due to the poor track record of mobile devs and empowers users to be able to deal with that in a way that restores some degrees of trust.
It's a fucking shame there's not an equivalent on iOS where you can just say "yeah, what you find here can be trusted" and then not have that gets polluted a year down the line. Apple used to somewhat police the App Store back in the early 2010s for similar peace of mind, but that's not the case anymore.
It might have been b as well – Signal did keep their server code proprietary for many months to add their custom cryptocurrency to it, and added this cryptocurrency for microtransactions into the app as well. There may be many more features like this planned, some of which F-Droid might oppose.
https://community.signalusers.org/t/signal-android-app-on-f-...
F-Droid with reproducible builds signed by both parties seems the best of both worlds to me, now I don't understand why Signal is so stubborn about this.
Google requires app developers on play store to give goole the keys that enable google to insert backdoors in any release. I can't trust anything on the play store for this reason. There is no way to tell which apps have been backdoored by google for whatever reason (the usual reason is a NSL).
Telegrams Encryption is off most of the time. They have serverside access to messages. The optional E2E is annoying to use and isnt even available on every platform. For example Tdesktop afaik still has no E2E support. (And has a very brittle software architecture.) You can't register Telegram accounts with the open source client anymore. This should be a non-Discussion.
MG implying that just because other messengers like Whatsapp use Signals encryption scheme does not make them more more trustworthy.
Yes you can verify in a binary if the stuff is implemented well. But if a vendor has control over the update channel or beta rollout features its kinda easy to hide targeted features. Wasn't Whatsapp caught exfiltrating chats in ways that don't involve the normal channel bypassing E2E?
Btw there is no Signal in Fdroid but nowadays there is an accepted by upstream third party implementation. You could separate software and infra vendor. Look at Molly.im
Better to bring non tech folk to Signal than to other messengers that do the same but less protected.
Matrix? Lol!
When signal becomes at least remotely as popular as telegram it will implement same protection to fight against spammers because you can't have free unrestricted registrations and don't drown in spam
Telegram currently makes it as accessible as possible: either use it freely but register using phone number and official app or pay and use anonymously as you want
The level of encryption isn't as important anymore at that point. It is less probable you get into problems by using a service that doesn't know your identity.
That hasn't been the case for Signal for some months: https://signal.org/blog/phone-number-privacy-usernames/
You still require a phone number for sign up for Signal, but your phone number isn't visible to anyone you chat with.
That's irrelevant - the phone number is known to Signal and can be request by law enforcement. And, since it's been made pretty much impossible to buy a SIM in the EU without showing identification [0], this will allow law enforcement to link the account to you.
[0] IIRC the Netherlands is the only country left where you can buy SIMs without ID.
Maybe I'm missing something here, but if usernames are treated as ephemeral, what's the threat model here?
So how does this work? Law enforcement asks signal if they have an account for a phone number, signal saying "yes, here's when they created it".
Then what?
You won't get the actual plaintext messages, but the contact graph + metadata (timestamps) are pretty sensitive.
Law enforcement says that the suspect chatted with some username/told people to contact him by his Signal username, then they go to Signal and request the linked phone number, which is then linked to the ID shown when the card was bought.
The UX on usernames in Signal might be non-ideal. It might be helpful to have a toggle that regularly cycles your username if that's important for your threat model.
As far as I know, in Romania you can still buy and activate a prepaid SIM card without having to show your ID. There was an attempt a few years ago to make it mandatory to tie the phone number to an ID, but it was overruled by the Constitutional Court.
Wrong. Because:
> You still require a phone number for sign up for Signal
So, they have your phone number. What is displayed is irrelevant.
If they have your phone number (which they do), they will have to disclose it for any subpoena/NSL, so they do.
> you need a jailbroken (old) iPhone. And at the end you still can’t verify the whole app. Some files stay encrypted
So basically, it works you just have to bend over backwards to verify that it's truly reproducible.
https://security.stackexchange.com/questions/18197/why-shoul...
I’d do a disservice to try copy and paste here so rather look at the top answer
It's not inherently broken, but it's sufficiently risky that it may be fair to assume it is broken. History has proven that software that's not known to be secure is typically insecure when it gets to the really hard crypto implementation. I think it's fair therefore to approximate it as "inherently insecure".
Most people in the cryptographic community agree that the Signal protocol is well-designed, is widely believed to be secure, and the authors react openly and swiftly to potential issues. Meanwhile, a lot of the MTProto crypto is just weird (that is, it does not follow standard practices of the field, without strong reasons to do so), and many cryptographers treat it with suspicion.
Additionally, home rolled crypto does not usually get the kind of security review from the cryptography community which makes it very likely that bugs of all kinds exist.
[1] https://words.filippo.io/dispatches/telegram-ecdh/ [2] http://unhandledexpression.com/2013/12/17/telegram-stand-bac...
All crypto algorithms, even weak ones output what looks like random numbers that can be deciphered back into the original plaintext. Just by looking at it, there is no way to differentiate between secure and insecure crypto. Contrast to a physics engine, it is hard to get right, but at least, if you did it wrong, it tends to be obvious.
Also, like everything security-related, it is adverserial. You may have some of the smartest and most resourceful guys on the planet working to break your thing. It is worse than even critical systems. Aircraft engine control is critical, people may die if it goes wrong, so robustness and correctness are crucial, but at least, pilots won't go out of their way to break it.
Crypto schemes which get broken usually follow a pattern of "something smells wrong", "we have weakened it a little bit", "we have weakened it a little bit more", "this is now completely broken", "my god why are you still using MD5, it's 2017".
We're in the "something smells wrong" or "we have weakened it a little bit" phase for MTProto2, depending on how you view it.
Are you sure about that? TextSecure was created more 10 years ago than 20. 20 years ago, we did not have smartphones.
As I remember, TextSecure started with SMS (but that was not the Signal protocol) and added "internet" messages right after WhatsApp got bought (which was about when Telegram was started).
I love the Signal protocol, but I would say it's more 10 years old (like Telegram). Or am I missing something?
It's close enough that if, say, a novel attack against OTR were discovered today, the first thing I'd want to know is if there are any implications against Signal.
Wait if it's the same why don't we just use Facebook, WhatsApp and Skype instead of Signal?
- Facebook and Skype E2EE messages are optional, and people rarely use that option, and - Those apps collect a huge amount of data outside the contents of the messages.
The fact that Facebook, WhatsApp, etc. use the Signal Protocol kind of shows that it is an accepted standard. But of course there are many reasons to use Signal (the App) instead of those apps, for instance:
- The Signal App is open source. You can check the protocol implementation before you use it. For Facebook, WhatsApp and Skype, you have to trust them (or some audits).
- E2EE is only one part: it ensures that nobody except the recipient can read the content of your messages. But there is a whole story around the metadata. The metadata say who writes to whom, and when. It essentially helps build a social graph. Facebook is very interested in this social graph. It would appear that the Signal Foundation is not. And even if it is not perfect, Signal does a lot to try to minimize the amount of metadata it has access to (and quite obviously Facebook has a huge incentive not to do that).
This said, IMHO it is still a lot better to use WhatsApp than to use Telegram, because at least you benefit from a good E2EE.
I really dislike the "hand rolled is bad" meme. Someone rolled all crypto. The questions are "who is doing the rolling," "do they know what they are doing," and "was it peer reviewed or directly and faithfully built from a peer reviewed design?"
Crypto is notoriously easy to get wrong, even if you know a lot about it - and most people do not. Secondly, proving something secure is pretty hard as well. If the crypto isn't a bog-standard algorithm in a well-known and reviewed implementation, assuming it to be insecure is a pretty good rule of thumb.
The people who take this advice are people who have respect for the difficulty of things like crypto and should be the ones implementing it, or at least on-ramped into learning how to do so.
The sorts of people who ship bad crypto because they don't bother to learn anything about the field are going to ignore this advice.
So I think as a strategy for fighting bad crypto it's neutral or maybe even net-negative by discouraging the right people from learning crypto and having no effect on overconfident fools.
Someone (Bruce Schneier?) said that the best way to get into actually inventing/implementing crypto is to first get handy inventing attacks / hacking into other algorithms and tools.
But here, primary: https://christopherrufo.com/p/the-zen-koans-of-npr
> This week, I have been engaged in a campaign to expose NPR’s new CEO, Katherine Maher, and her anti-speech, anti-truth philosophy.
Any sources for this except the private testimony of a Signal competitor talking about his important friends? (ETA: Or is it when the court/media obtains your unlocked phone, in which case Telegram won't protect you either...)
I know several large IT orgs that have done this when Legal got involved. Literally using a 2nd phone to take pictures of Signal chats on the phone in question.
"Ah, but if you need encryption then you'll..." - well, two things now. Suddenly you're the person who has encryption switched on. And also more likely, someone they talk to will forget to switch it on and just blab everything into cleartext anyway.
The entire importance of Signal's model is that it is always encrypted. It's why LetsEncrypt is also important: to have effective security you need to be able to hide in the crowd. If encryption usage is rare, then who's using it itself (or suddenly starts using it) becomes an extremely valuable datapoint.
(so I'd add: Telegram absolutely sell timeline details of which user accounts change their frequency of encrypted chat usage).
> And also more likely, someone they talk to will forget to switch it on and just blab everything into cleartext anyway.
I expect that if you enable a Telegram Secret Chat with Bob, Bob cannot unilaterally un-secret it. I would be very surprised if that was the case.
Of course Bob can then share the contents with Carol via an un-encrypted channel. But every encrypted channel has that weakness.
I'd guess this is possible because Telegram e2ee chats aren't multi-device capable, so it's necessary to be able to use unencrypted chats while using Telegram on something else than the phone with e2e.
Possible, as many ridiculous things happened around the whole war. (Recently german generals on a video chat were targeted by the russians, wasn't too hard, they did not use any encyption at all)
Sources would be nice though.
But it really would not be a reason for me to trust telegrams security.
Rather a confirmation again, that also secret services can show great incompetence.
They used Webex. Doesn't Webex use any encryption at all?
https://www.nytimes.com/2023/01/04/world/europe/ukraine-russ...
> Ukrainian artillery targets Russian soldiers by pinpointing their phone signals. Despite the deadly results, Russian troops keep defying a ban on cellphone use near the front.
It's especially critical to drip-feed feel good news when you losing.
> “It is already clear that the main reason of what took place included the massive use, contrary to the ban, of personal mobile phones in the range of enemy weapons,” the Russian Defense Ministry said in a statement. The cellphone data allowed Ukraine, it said, to “determine the coordinates of the location of military service members to inflict a rocket strike.”
If you claim that neither Russian, nor Ukrainian special services are competent, I'd disagree with you.
IDK, the whole anti-Signal post really makes me suspicious of Telegram whereas I wasn't really before. Are trying to be the universal honeypot for agencies?
1) On-screen keyboard - by default most phones do send what is being typed - a lot of phones also have 3rd party keyboards of doubtful origin preinstalled
2) "Enable backup" scam - on starting an app (like Google Photos or WhatsApp) chances you or your wife accidentally press "ok" on a pop up message
3) Hardware drivers - non open source binary blobs with back doors
4) Operating system - you basically don't know what information is logged and sent back to phone's vendor
That's extraordinary if true. Do you have anything to back it up, though? Even Google (!) wasn't brazen enough to log everything typed on Gboard, they implemented federated learning.
https://www.technologyreview.com/2024/04/24/1091740/chinese-...
- "I don't like where their funding comes from" (US govt regularly funds secure software because they depend on it for their own operations, see: Tor)
- "An alarming number of people think their chats were leaked". It's easy to state things without sources. Also an alarming number of people think Facebook listens to them through their phones' mic. People are bad at opsec. Not news.
- "No reproducible builds. They closed a GitHub request from the community." Well, except Android is reproducible, and they explicitly state on that closed issue that they don't do feature requests via GitHub and asked the reporter to raise in the proper channel.
- "Telegram is the only service with reproducible builds". Telegram barely has encrypted chats, reproduce all you like, that doesn't make the chats secure. Signal has E2E encryption and verifiable builds for Android, that's a strictly better security position.
Easily explained by direct access to the phone or Pegasus (or Pegasus-like) spyware. Both of which Telegram is also vulnerable to.
iMessage, Telegram, and Signal all get usage from me, with the vast majority of that usage weighted heavily on the former two because that’s where most people in my circles are. When comparing user experience between the three, it’s easy to see why.
Signal does this today by verifying phone numbers themselves, so they’d have to continue doing so centrally; “never trust the client” applies to their own client just as much as anyone else’s, and “allow unverified users to initiate contact with strangers” is the spam vector infecting all modern telephony (thus STIR/SHAKEN).
So with that need resolved, the biggest risk of third party clients would be intentionally compromised code within an attractive wrapper — but the only way to defend against that is to not allow third party clients at all.
So.. I guess I no longer support third-party clients, having worked through the timelines of what will occur. Ah well.
However Du Rove is right about a bunch of things:
- Signal clients suck, specially the Desktop one where they ship (or used to) pre-built binaries like their own lib: https://github.com/signalapp/ringrtc - Also you can't have Signal without Google Play Store - Signal client suck in usability. I wish I had Telegram client (android) and desktop (qt) instead of this electron garbage. Telegram clients are super-duper-awesome - I would say that removing phone number requirement is their #1 request. yet they take so much time to address it, specially when they cry about phone number validation SMS costs - BTW, telegram is implementing a very nice idea of a crowd sourced sms validation, where they use their users phone numbers to send the validation sms - They have a very questionable crypto integration with MobileCoin, which have a obscure value: they depend on IntelSGX and is 95% pre-mined
You can use Signal without the Play Store. Download the apk from Signal's website and it will use a background connection to receive calls and notifications. The downside is that it's heavier on the battery.
In any case, if we don't trust the official client/app/build, then I'm not sure if a F-Droid release would help that much. If we think there's something funny with the official apk, then we can't trust any part of Signal.
Things like WhatsApp and iMessage get scam messages too, and the less visibility the operators have for contents of messages the harder it is to proactively filter out spam.
Do any platforms require that both parties add one another? (And/or allow for restricting an account to such a mode)
e.g. if user123 and user789 wish to communicate, then user123 must add/contact user789 AND user789 must add/contact user123. Until both do so, then nothing happens.
It's more work to legitimately establish contact with someone, but that seems like it pales in comparison to the effort produced by spam/scams.
Same thing with verifying identities. In order to actually establish proper contact with someone, you need to communicate with them via some outside means (ideally in person) in order to establish the connection. Requiring both parties to enter/scan some ID/code/whatever seems like it would only facilitate proper verification (though not guarantee it, of course).
I'm sure that I'm missing something, though. I assume I'm just not familiar enough with these platforms and that some/all of them provide such a feature. It's just odd to me that spam sounds like such a problem when it feels like the above solution would be highly effective and simple to include.
Like I understand that Telegram is probably not very secure, but seeing what proponents of Signal are saying doesn't really make me trust Signal either.
If it is indeed political don't try to bring some kind of technological merit into this, it makes you look really dishonest.
It's insecure by default so I guess it could be an everyone-honeypot. I'll keep using Signal for my secure messaging thank you very much. Honestly I trust Apple iMessage encryption more than Telegram.
If you follow the discourse, the crypto quality is no longer brought up in factual Telegram-to-Signal comparisons, except as low-effort swipes at Telegram's general credibility.
That's one hell of a leap. How far has our requirement for evidence fallen?
Once again, this is not my opinion. This is the result of independent auditors who have no affiliation with either the USA or Russia.
There are positives to the UI of Telegram, there are negatives to the UI of Signal. None of these has much to do with the underlying protocol of either.
Personally I'd rather we all put our collective efforts into something like the protocol suggested by Matrix, but if only given the choice of Telegram or Signal, I'd avoid Telegram like the plague. They are either malicious or amateur. Either one isn't a good choice for security.
Please provide evidence of such issues. Because at most, the issues with MTProto were at the level of "we are not familiar with this, but seems ok". Which seem to be inflated by Signal activists into maliciousness.
You do make bear service here.
> Recently, in [MV21 ] MTProto 2.0 (the current version) was proven secure in a symbolic model, but assuming ideal building blocks and abstracting away all implementation/primitive details.
Translation: it is secure, except for bugs, if any.
It's like a clunkier version of the backdoor in Dual EC DRBG. When problems like this are found, you can either assume deliberate malice (as in the case of NIST) or accidental incompetence. Either should be immediate grounds for not using the software. This isn't Flappy Bird. This is meant to be secure comms. The "This Is Fine" mentality doesn't cut it.
I'm not sure what this means.
Basically, by being proactive you do more damage as if you didn't do anything.
There's another: proactive idiot is worse than the class enemy[1].
[1] "Class enemy" or "třídní nepřítel" (cz) might be an unknown term in itself - https://en.wikipedia.org/wiki/Enemy_of_the_people#Soviet_Uni...
I don't care if the people who can decrypt Telegram chats are allied with any one side or another. I believe the idea of "Class enemy" to be abhorrent, and the moral / social threats of "the overall impact" to be negligible when compared to the fact that using compromised communications platforms will inevitably lead to greater problems than the act of calling them out.
This is the equivalent of "You'll keep quiet if you know what's good for you".
If Telegram is broken, certain people need to stop using it. The socio-political climate of the areas most likely to be using Telegram just makes this more urgent. This applies independent of if / how / why it's broken, and who, if anyone, may benefit from this.
What if the gnat isn't a gnat? What if the gnat is another man who now knows the communications of the first man? I'm not saying the Bear should kill both, but I'm pointing out that the analogy falls apart when the gnat isn't just a mildly annoying third party.
It's funny to see the basic cultural stuff float to the surface in comments like that. Like when there was a large number of "American" accounts some time ago on Twitter responding to financial news, but putting USD after the numbers... (To be clear, I'm not suggesting anything specific about the author here, just that sometimes you see enough opinions about something with the origin "leaking" through the side channel and wonder how organic it is)
You can check this thread where his claims are debunked https://discuss.privacyguides.net/t/according-to-elon-musk-s...
Let's enumerate the purported problems:
- "Elon Musk said so", which does not matter. - Signal attachments can be viewed by an attacker with local access to the client. This is not Signal's job to protect against. - Signal offers an optional `--no-sandbox` flag which only has security options if enabled on Linux. - Weaknesses in sealed sender. This is the only one that might be an actual problem (two theoretical and one empirical attack, but the latter comes from an 18 page paper that I have not read). But this does not compromise the integrity of the chats, and is not something Telegram improves on.
Given how the posted described the optional `--no-sandbox` flag as "no sandbox on Linux", it's clear that they don't understand anything they're sharing, and they just want to spread FUD.
---
edit: Per discussion below, I was wrong about the `--no-sandbox` flag. It's enabled by default. The risk is that an attacker could figure out how to use Signal to run arbitrary JavaScript. I take back my insult- it was I who did not understand the linked issue.
I still stand by Signal > Telegram. The risk here is that an attacker could figure out how to abuse Signal to run arbitrary Javascript, e.g. through a specially crafted message.
Could you elaborate as you seem to be more "knowledgeable". This flag is clear at what it does and shouldn't be shipped into production. https://no-sandbox.io/
You can have a look where they specifically chose to force it https://github.com/signalapp/Signal-Desktop/commit/1ca0d8210...
Can confirm with `cat /usr/share/applications/signal-desktop.desktop`.
This still would require a pretty sophisticated attack to take advantage of, but I wouldn't rule it out as an attack surface. (We regularly see iPhone exploits that attack font and image rendering, after all.)
I'll amend my post given this.
There's an issue open to provide a flatpak for the app.
I am really glad that telegram is nowhere nearly as big in western countries compared to eastern Europe. It pains me to say this but, but even till this day, us eastern Europeans are way more susceptible to propaganda than the western world, although, for a million and one reasons that seems to have a huge effect on the western world as well. In that sense, telegram is an active contributor.
10/10 times I'll sit firmly behind Signal, despite the many shortcomings: there is no developer integration, if you want to create a signal account for your own personal bots or whatever, you can but only through a hacky repo that's on github.
Yes, the people behind telegram know all this very well and they don't like the fact that people who are aware of it as well are favoring signal infinitely more than telegram.
Applying an emotional argument to shut up discussions against censorship is propaganda 101.
(I use Telegram and Signal each for about 45% of my messaging, even though I'm in Europe where WhatsApp is so prevalent.)
You can use the above link. Otherwise, you will have to log in, unfortunately. Earlier, we could have used a nitter instance, but all of them have been blocked.
You cannot critique missing guaranteed end to end encryption when effectively matrix cannot guarantee it either.
E2EE can not prevent the receivers from sharing the message (they are one of the "end"s in "end to end-encryption" after all"). The same thing could happen because one person in the group chat ends up getting some ransomware on his phone; E2EE can not prevent that.
[0]: Yeah, might be changing or has already. Now, after ages.
A phone number is still required for registration. As of a few weeks, it's not necessarily communicated to your contacts anymore, which solves a few concerns (but not all).
> crypto push a while ago
I was worried about this, but I use Signal daily and I haven't even noticed anything in the UI about this, it seems like a non event in the end.
I got a bit confused here! Didn't Musk support and encourage people to "Use Signal" three years ago?! https://twitter.com/elonmusk/status/1347165127036977153
I'm sad to see so many people swallow this up.
https://www.vice.com/en/article/d7yyqv/another-day-another-h...
* A phone number
* Access to your contacts
WHY do messaging apps need ALL our contacts? Why can't we add only the people we want to stay in touch with on a particular app?
WHY doesn't Apple let us choose WHICH contents to let an app steal, just like we can with limited photos access?
Boast that end-to-end encryption is absolutely safe is obscurantism. If you want most security in transmission, share your GPG public keys face-to-face.
Du Rove made this post after the founder of Twitter forwarded an article about Signal. Instead of Elon Musk who has turned Twitter into a easy to surveillance platform. It was also Elon Musk who used to be very direct and later learned to be smart these days.
I strongly recommend reading the original post yourself first.
> Pavel Durov, the CEO of Telegram, has recently been making a big conspiracy push to promote Telegram as more secure than Signal..
Jack Dorsey's Tweet: https://twitter.com/jack/status/1787895769183268948
- The Polish spy chief is warning that Russia intends to invade a NATO state in the near future [0]
- Poland is strengthening its border with Belarus [1]
- Germany is considering conscripting all 18 year olds in the face of what it perceives as Russian aggression [2]
- Russia warns of "enormous danger" if NATO troops are sent to Ukraine [3]
- Russia threatens to use "special ammunition" against NATO [4]
Headlines were starting to read like this immediately before the Russian invasion of Ukraine. We saw troop buildups and threats for a while before any action was taken.
Amidst all this, there's a sudden push to move people off of Signal and onto the Russian-developed Telegram, which is widely regarded as less secure and is even not encrypted by default.
Telegram now operates out of the UAE, which has long been a partner with Russia. Wikipedia has this to say about the strengthening of UAE-Russia relations since the invasion of Ukraine:
> trade between the two nations strengthened with many Russians relocating to the UAE to invest in real estate, business, or "escape financial restrictions in Europe". Trade between the two countries has doubled to $5 billion since 2020 and there are approximately 4,000 companies with Russian roots that are operating within the country.
So, my take here is that this push toward telegram smells pretty bad given the timing. Telegram has always had kind of a smell about it, given that it rolled its own crypto and given Durov's involvement with the VK social network which was, in Durov's POV (again according to Wikipedia), taken over by Putin's faction.
Personally, I like Signal. I have some of the same concerns folks here have brought up. But it's been well vetted by experts and is highly regarded by people I trust. That doesn't mean you have to like Signal. Its crypto improvements have been spread to other apps, and many people are probably just fine using something like iMessage.
And while I don't know anything about Durov or his motives, I have yet to see any successful cryptography app anywhere in the world that didn't eventually have to compromise with a government. And Russia seems especially good at applying pressure, with a history of institutional tips and tricks that go back at least to the Soviet secret police, and possibly even further back to the Tsars.
As much as I think we can't objectively trust the US government in all matters, I think we can generally trust the cryptography experts. They tend to be skeptical of all governments when it comes to cryptography, even in democracies.
So that's my two cents. I wouldn't switch from Signal to Telegram. If you're on Telegram and you have especially interesting activity (like you fight in a war), then you should probably assume that Russia can see everything you're doing. That may change if Telegram gets the sort of robust cryptographic scrutiny Signal has. If you're not warring, you're not doing exotic fancy crimes, and you live in a democracy, you're probably fine with either app but possibly a little better off with Signal or iMessage.
[0] https://www.newsweek.com/russia-ready-launch-offensive-nato-...
[1] https://abcnews.go.com/International/wireStory/poland-streng...
[2] https://www.telegraph.co.uk/world-news/2024/05/11/germany-co...
[3] https://www.telegraph.co.uk/world-news/2024/05/11/germany-co...
[4] https://timesofindia.indiatimes.com/world/rest-of-world/form...
"With assistance from Elon Musk" is a pretty big accusation. I held off replying until I read your whole thread, and then you didn't mention that at all. What the hell?"
Seriously, what the heck has Elon Musk to do with this? Unless we also want to debate what we all think of Elon Musk when we talk about chat protocols?
https://twitter.com/elonmusk/status/1787589564917490059
Keep in mind that X/Twitter's "For You" algo boosts posts to which Elon replies in his followers' feeds.
Any distro can have Telegram clients, both official and third-party, in their repository.
Compared to this
1. You cannot download Signal from F-Droid. You need to download it from the Google Play Store. The released source code has lagged behind the version on the Google Play store by long periods of time many times. One example was when they implemented cryptocurrency payments, pushed the update to everyone but no one could inspect the source code.
2. Signal has sent legal threats to repositories that package Signal. The repos either need to confuse users by offering the client under other package names or remove it.
3. They also send baseless threats to forks that use their server. Combined with their lack of federation, this results in people having to use multiple apps from different sources with a much larger attack surface.
4. They beg for donations in the app even though they made an app with payments and cryptocurrency integration with an obscure coin (which they were involved with and had ample opportunity to hoard before ever announcing it as a feature in Signal).
5. They claim to have privacy features that other messengers lack, but these features are based on known-to-be-broken technologies like Intel SGX.
If you assume they are malicious, (a) I wouldn't use their product in the first point, and (b) of course they can do whatever they want independently from the published code.
- You can download an apk from signal that self-updates
- Telegram isn't encrypted by default and uses a home-brew protocol
Not that I really want to defend Signal (XMPP FTW!), but the legal threats were about using the Signal name, not making an unofficial client per se. I know a bit about it because I develop an alternative signal client (a signal-XMPP gateway to be more accurate). That said, they don't help 3rd party client devs at all.
The name is what their reputation is staked on, and if a third party compiled it they have no idea if malware is secretly packaged in there too.
Having said that, the smart move is to dedicate a few engineer hours to packaging it for every linux distribution and every app store, even the smallish ones, to prevent others trying to 'be helpful' and requiring you to send a takedown.
>we really don't want forked versions of the app maintained by other parties connecting to our servers.
that's just misleading misdirection.
Firefox have issues with the legal name, that's why the source is called by other names and the branding is added later on.
signal ties the branding with the code, so it is impossible to build from the canonical source without triggering the branding issue.
So, in practice, it is a convoluted way to annoy anyone releasing from source. And as we know, actually using open source software without a "distro" is insanity. You cannot trust 1000s devs. you trust the distro, the distro trust 10s of package maintainers, the package maintainers trust 10s of devs. and everyone is happy. I trust f-droid just fine. But i don't trust the person who is publishing every apk on random sites like signal.
The Telegram Org itself gives no support to volunteers at all.
You can't register with Foss builds. Only official binaries. Nowadays a lot of features are premium only. You can only get premium with official binaries. That part is closed.
Pretty much all the packages on Linux repos come from package maintainers taking upstream source code, removing parts they don't like and then building that. This is a normal part of packaging and building open-source apps.
Also which distro packages Telegram?
Fedora doesn't. Debian does but at times it was so old the client crashed from receiving server comms because it wasn't fully compatible. It actually crashed as in segfault.
Granted yes, the version commits are squashed like you said. [1] However I haven't seen source release to lag behind store releases, any sources on that?
0: https://core.telegram.org/reproducible-builds 1: https://github.com/DrKLO/Telegram
Release lag -> Telegram foss needs to wrangle the release every time. Fdroid CI takes its time.
A couple months ago I actually verified a build of Telegram on my friend's phone as he thought something might be off and didn't have any issues there (the build matched).
If so, up-to-date source code us pretty useless.
How many people check their app's source code?
With third party clients it's pretty easy to get malicious ones
Matrix or bust.
You can also download the APK directly from their website: https://signal.org/android/apk/
When doing so Signal uses its own update mechanism to stay up-to-date.
Even then
> You need to download it from the Google Play Store.
Factually incorrect, just go to https://signal.org/android/apk/ (and the apk will then update itself) or build it yourself.
> pushed the update to everyone but no one could inspect the source code.
That was for the server code, which you shouldn't care about from a security standpoint for an E2EE messenger such as Signal. AFAIK that was not the case for the clients.
Regarding your other points, they have reasons that have been discussed elsewhere[0] to avoid federation, notably a lot of the progress on the Signal protocol would be way harder in a federated setting. There's no other messenger that has the same usability ("my grandfather can use it and won't have problems using it afterwards") while being at this level security-wise.
That page tells me that the safest way is to have a Google account, with Google Play Services installed on my phone, and to download it from the Google Play Store.
It then gives me an APK link after saying "Danger zone" and "most users should not do this".
If the app developer tells me it's dangerous and I shouldn't do it, can you even expect users to do this?
If you care about reproducible builds and avoiding trusting Google, you're already in the class of not-most-users.
Signal seems to have usually taken a pragmatic stance of defaults mattering.
Afaicr, that was the argument for linking to phone numbers (it allowed for more lazy users to use it) and encryption by default (few turn on opt-in-encryption).
And it seems accurate to say 'for most users, who don't know what they're doing and don't want to play personal-IT-department, using the Google Play store is more safe and secure.'
F-Droid for as much as I love the open platform, does not provide any security guarantees about what you're downloading. It is a volunteer run project and does not have the extensive security policies and practices that Google has. From https://f-droid.org/en/about/
> Although every effort is made to ensure that everything in the repository is safe to install, you use it AT YOUR OWN RISK.
Likewise downloading and side-loading it from their website, requires you to disable some security guarantees by doing things like enabling developer mode.
I don't know how to verify the SHA fingerprint without Googling (I know how it works, just don't do it often to know the exact openssl or equivalent command).
If I'm downloading the APK directly on the phone, there's a lot that's not under Signal's control that could happen.
What if I'm directly under attack, and I'm trying to move to Signal? The attacker could MITM the connection and intercept the download.
I think that's a fair warning to show a user, because indeed most users will likely want to install apps through Play Store, that'll reduce/remove supply chain risks. Users who know enough about APKs would be able to verify the hash, or build it themselves.
Even if I download the APK, I still have to accept a similar warning when installing it on my phone.
Researchers of Telegram's protocol have said in some ways it's weaker than TLS.
E.g.
- https://www.wired.com/story/the-kremlin-has-entered-the-chat...
- https://therecord.media/telegram-blocks-chatbots-used-by-ukr...
- https://www.oporaua.org/en/polit_ad/and-telega-is-still-ther...
- https://www.pravda.com.ua/eng/news/2024/05/8/7454849/
- https://time.com/6280190/cia-recruit-russian-spies-telegram/
- https://www.cia.gov/stories/story/cia-launches-telegram-chan...
- https://nordvpn.com/blog/is-telegram-safe/
- https://portswigger.net/daily-swig/multiple-encryption-flaws...
For example of this sort of vetting, take a look at the standardization around AES or the post-quantum schemes.
In crypto you're almost always relying on hardness assumptions that aren't provable yet. So you need to guard against things like accidentally haven chosen the wrong constants that collapse a problem's hardness. Or, more mundanely, making a seemingly reasonable engineering choice that is known to weaken the protocol and which would be caught by a big org with a thorough review, but a startup may not catch.
Seems like FUD. This took me 30 seconds to check just now:
-Telegram's android source code git hasn't had a tagged release in more than two months and is several versions behind the android app (10.12.0 vs 10.9.1)[1]
-Signal's android source has a tagged release two days ago that is two releases ahead of the stable version on google's app store, and also lists the tagged release for the version that is on the app store.[2]
Metadata are more important than the content of the messages and yet Signal has always been about knowing your phone number, with handwaving when the subject is mentioned.
Sessions, a Signal fork, had its tagline right: "Share encrypted messages, not metadata".
Signal is a metadata exchanging app and it's about collecting your phone number and everybody else' phone number.
Now I don't think Telegram needs to "attack" Telegram: Telegram is immensely more successful and has reached take-off velocity.
To me Telegram is going after WhatsApp, not Signal.
I think Telegram is very wide-spread for running large group chats and communities, a use case that Signal is not interested in. Personally, I want my chats end to end encrypted and I'm grateful to Signal for pioneering this and inspiring Whatsapp, facebook messenger and others to adopt the same.
You will still need a phone number to sign up for Signal. Signal still knows your phone number, you just hide it from your contacts. To me this only makes it even more suspicious.
And you can correlate username to phone number not that hard in most standard setting cases.
Sorry, but that's not privacy. I don't care what they do to encrypt your messages, they are still tied to me, which makes the super duper encryption pointless.
Yes oranges umm phone numbers is a problem. They have that both. Only one can additionally read the contents.
Thats for now the price for a normie interface.
First goalposts first.
But in this thread, GP was just talking about metadata. The goalpost here is metadata. GP particularly mentioned that Signal "fixed" the phone number issue and I just want to note that currently Signal isn't any better than Telegram in this aspect.
And then you moved orange back.
This is incorrect. Telegram has E2EE.
So, not on by default (unlike Signal), no group chats (unlike Signal), no support at all in desktop apps (you've guessed it: unlike Signal).
The success of such tactics can more easily be understood by even looking through the many, many comments right in this thread telling us Signal protects metadata because usernames are now a feature - guys, Signal has the metadata as the *services* are what is the topic of discussion here, not other users.
It's not as simple as Signal inspiring Facebook and Whatsapp, the sequence of events happened in reverse order.
Whatsapp started encrypting messages after significant security issues in ~2012
It was purchased by Facebook under initially some administration separation terms in ~2014?
In 2016 it added e2e encryption. If I recall this was controversial because it limits fb ad potential on users.
I guess what I'm trying to say is that the timeline seems to me to still be pointing towards <<e2e came from Whatsapp not FB as an initiative, even if FB owned Whatsapp at the time.>>
Again you're not factually wrong, but I hope my restating of the timeline makes it more clear why i I think your reverse order point doesn't tell the same story.
Wow, really? ICQ had that in 1996 ...
yeah exactly so what is actually going on here?
You can block number discovery.
You can't resolve username to number.
Your main account ID internally is not your number anymore.
If 2 users add you using 2 different links or usernames. Its now harder to confirm its the same account.
"[...] You can have a Telegram account without a SIM card and log in using blockchain-powered anonymous numbers available on the Fragment platform."
> To me Telegram is going after WhatsApp, not Signal.
They mention Signal by name in the referenced post.
So all it can tell authorities is that a person with x phone number uses Signal and still uses it.
I have little trust in an entity that "leverages the social graph" though...
Your encryption may be great, but if you act like Farmville I'm going to trust you as much as I trust those facebook games that spam your friend list.
I'm sure reactionists will immediately drop Signal because Elon the great said they should without considering that it still might be their best solution to communicate privately with their friends and family. But X makes *all* of it's money from collecting a lot more than metadata from their users, Tesla collects driving data and metadata from all of its customers, Grok trains it's AI on all of the data collected from X, Tesla and other sources without asking if users want to opt out of those training datasets. So I'm not sure Elon has a leg to stand on in this conversation.
Signal got a massive boost in popularity because "Elon the great" literally told people to "Use Signal".
So, if you can call "metadata exchanging app" an app that simply has a list of numbers registered to the service, without any metadata assigned to them except their last access, the same label could be assigned to a much larger number of services.
It may not be anonymous, but it can hardly be disregarded as private.
[1] https://signal.org/blog/phone-number-privacy-usernames/
[2] https://signal.org/blog/sealed-sender/
[3] https://signal.org/bigbrother/central-california-grand-jury/
Assuming you trust them (notice all your links point to signal.org own publications). Most of the privacy people are cautious/paranoid and assume that everything that can be collected is collected. Even assuming a lack of malicious intent, what's stopping NSA from hacking into Signal's infrastructure and logging who's talking to who along with timestamps? That's not to say I don't trust signal (it's the best mainstream solution right now), but it could do better to hide metadata from the protocol.
NSA can hack into Signal's infrastructure, and what they will be able to gather are the same information provided by Signal in reply to subpoenas (the whole list here https://signal.org/bigbrother/), because everything else is end-to-end encrypted.
Sealed Sender, the second link in the comment you've replied to. The indicator is off by default, but you can enable it under Settings → Privacy → Advanced. If I remember correctly, it doesn't work for the very first message you exchange with someone, but then it turns on and remains on.
In layman terms, it turns "from A; to B; content: <encrypted>" into "to B; content: <encrypted>". Their infrastructure doesn't need to know the "from" part to serve its purpose, so they strip it away.
If it was the other way around, they'd have to give that info to the (US) court. Same as any other US-based business, it's not optional, they can't ignore such requests, they can't lie, otherwise they'd be placing themselves in legal troubles for a random nobody that happens to be using their product. So, when I see this page, I fully believe them: https://signal.org/bigbrother/. If I didn't, my first step would be to look up those court cases from alternate sources.
This is not to group everyone, I realise there are communities that cross that divide, and this is no judgement of people using either. But I think this divide will continue as the political trends continue. Both sides believe they are right, both more than they perhaps should given the evidence. That said, I'll stick with the one the cryptography/security nerds are using, not the one they think is a honeypot.
2. Conduct an astroturfed campaign for Signal
3. ???
4. Crypto profits!
Oh and I also use it for messaging sometimes. But my main use case is participating in various groups, like in a forum way. And my peer group does the same and I have not met a single person that uses telegram mainly for messaging. Most also have signal or whatsapp for that.
Yeah, plenty have accounts, but nobody uses it to actually chat.
Also, it adds many useful features that other messengers didn't always have and many still don't have, for example Saved Messages, Scheduled Messages, Spoiler Messages, Reply to Message, message formatting (bold, monospace, etc), just to name a few off the top of my head.
Oh, and it's end-to-end encrypted by default.
Everyone in my friend group is using it.
In terms of functionality, speed, fluidity of the interface everyone is trying to catch up to Telegram. And doing a half-assed job of it
Telegram is often praised here for their features that helped them to grow and made people keep using it. Something that Signal should consider doing.
They have 900million monthly active users.
Telegram has a huge advantage versus WhatsApp: it's not Meta. Then the Telegram UI is really excellent.
When you tell people all your friends and family are using it and that's it's not from Facebook, they usually install it on the spot. Then they're hooked.
Except the government, as reported in the news.
Actually the only time I used it it's because I needed to chat with a Russian SaaS personnel.
I would never trust in with any confidential information though.
So, it's good that the personal involvement of the illustrious Elon turns even obvious political influence operations into a circus with talking horses and scary clowns.
It's good :)
If that's all there is to it, then the opinion is rather weak.
edit: maybe post a comment in addition to pressing the downbutton. I'm curious what's so problematic about what I've said.
In the end it doesn't matter if you are using a smart phone from Apple or Google as your soft-keyboard is such an easy target there is no need to decrypt anything.
I use both these apps fwiw. I'm under no illusions that anything is really private online.
However, technicalities are not the point: both Ukrainians and Russians trust Telegram—despite being at war. Telegram has managed to distribute its servers and legal presence across multiple countries, making it challenging for courts to track. This provides a level of security that American-based entities cannot offer.
There is a great discussion by Pinboard on why telegram is more safe, and it is preferred by activists in Hong Kong: https://twitter.com/Pinboard/status/1474096410383421452 "There's a disconnect between critiques of Telegram and its practical use that have made me uneasy about joining technical pile-ons around how it's not really encrypted messaging. Let me use the example of Telegram use in the Hong Kong protests..."
If anything, all this animosity toward telegram has always been a bit suspicious to me. But anyway, assume your cellphone to be extremely unsafe.
I'm not saying that you should jump on Signal (or anything else). I'm saying Telegram is almost certainly broken. Maybe maliciously, maybe accidentally, but almost certainly.
For reference, I don't use either Signal or Telegram anymore, but Telegram sets off so many alarms I'd steer clear of it.
https://twitter.com/matthew_d_green/status/17883860908411619... https://twitter.com/evacide/status/1788040276331884593 https://twitter.com/naomibrockwell/status/178863495226900939... https://twitter.com/paulmillr/status/1788563576455610552
(I'm pretty sure the list goes on)
https://news.ycombinator.com/item?id=40301508
https://news.ycombinator.com/item?id=40336005
https://news.ycombinator.com/item?id=40330694
https://news.ycombinator.com/item?id=40308241
https://news.ycombinator.com/item?id=40299313
https://news.ycombinator.com/item?id=40298608
https://news.ycombinator.com/item?id=40279661
https://twitter.com/jack/status/1787895769183268948
But the Meta companies are lying about E2EE, I don't know? Signal has seemed to me to be the company (org actually, nonprofit) that cares the most about privacy in terms of intentions and implementation.
The main leg that Signal has to stand on is it uses standard encryption, but it has all kinds of shady components like it used to require sharing phone number to contact someone, and the cofounder Moxie launched some MOB crypto scam which went to 0 and he has now quit the project too.
It's getting harder and harder to tell because bot activity has gotten so good, but Matthew Green has been around a while and is a genuine old school crypto dude. There is a group of people who just believes that crypto and privacy are good things and want to promote them.
The reason it gets harder is because you can spin up a handful of "expert" accounts shilling for this or that privacy VPN or bitcoin scam etc. So it's hard to just pull up a list of statements and know whether it has any weight. In this case, Matthew Green has a lot of weight because I've followed him for a while and I know what he's about.
Doesn't mean one can't become a sellout eventually.
Especially in Green's particular case - he had invested a lot of attention to Margaret Salter, e.g. https://twitter.com/matthew_d_green/status/13578907313697095...
The reasons why are already pretty well listed in the thread above. Telegram's E2EE is hand-rolled and not the default. Signal's E2EE is always on, and it's _the_ industry standard protocol. (Outside of iMessage, I believe the Signal protocol is used on every well-adopted messaging service which offers E2EE chats.)
People also aren't aware that phone numbers and usernames are tied on Telegram. When a former friend of mine joined Telegram, I searched up his username, and found his _very_ explicit Reddit account. This identity compromise issue isn't mentioned more often.
You can add me to the list. There is no good reason to pick Telegram over Signal, unless you don't care about security. It DOES have more sticker packs.
But you can, under Privacy & Security, switch Phone number visibility to "nobody". You can also change your username anytime you want to. A new feature called "anonymous numbers" allows you to purchase and use virtual numbers (they start with +888).
I think the bigger problem here is that Telegram has not e2e encryption enabled by default, which is definitely suspect.