[HN Gopher] Moxie on Telegram Encryption
___________________________________________________________________
Moxie on Telegram Encryption
Author : decrypt
Score : 25 points
Date : 2021-12-23 19:27 UTC (3 hours ago)
(HTM) web link (twitter.com)
(TXT) w3m dump (twitter.com)
| sschueller wrote:
| Moxie obsession with Telegram is odd especially when he blocks
| anyone just a tat critical about signal. He seems to be unable to
| deal with any criticism even if constructive.
|
| I don't trust him, sorry.
| no_time wrote:
| He is certainly weird in many regards. Does anyone know for
| example why is his personal site, moxie.org excluded from the
| Wayback Machine?
| eloeffler wrote:
| It really is strange that Telegram is commonly considered an
| "encrypted" messenger while the app makes it very difficult for
| users to actually use e2ee.
|
| The feature is hidden, and old "secret chats" stop working after
| a while without any indication that messages cannot be delivered
| anymore. To start a "secret chat" one must access it from a menu
| entry stashed away in users' profiles. And you can only start
| writing a secret message when the other side "comes online" for
| the first time after starting a "secret chat".
|
| All discussions about the technical implementation of e2ee in
| Telegram aside, this makes e2ee a pain, which is why it is rarely
| used (by most) if not desparately needed.
| zarzavat wrote:
| I subscribe to the conspiracy theory that Telegram is actually a
| plant by a security service (FSB?). The app seems to be
| constructed in bad faith. Presumably Telegram has the resources
| to increase their encryption/privacy level, yet they have not
| done so, so the question "why would anyone knowingly market an
| app as a private messenger without providing privacy" can only be
| answered by "because they want the data". And who would want the
| data of people who think they are communicating privately but are
| actually not?
| coolspot wrote:
| I didn't see any evidence that Telegram's "secret chats" are
| vulnerable to snooping.
|
| They are separate from regular chats and not available in the
| official desktop app, but they are secure.
|
| Signal with their "we trust Intel SGX to be single point of
| failure" kinda smells like a government honey pot.
| [deleted]
| matthewdgreen wrote:
| I also don't see a lot of evidence that they're bad, but it
| should be said that this is the wrong standard. I also
| haven't seen a lot of convincing evidence that Telegram's
| crypto is good (and plenty of past evidence of weird
| mistakes.) Overall what I've learned from examining
| Telegram's crypto in the past is that the company does not
| really value outside expertise and analysis, nor do they make
| it easy to review their (very strange and non-standard)
| protocols.
|
| Reviewing crypto is hard _when you're working with an
| organization that has good engineering practices and
| minimizes the possible risks._ My early examination of
| Telegram crypto led me to the conclusion that Telegram was
| not an organization whose approach to crypto engineering is
| compatible with that standard, so it's not worth the effort
| to try to vet their crypto when the company leaves so many
| weird question marks in their engineering approach. Meanwhile
| there are products with more professional crypto teams
| working hard to behave in ways that engender trust: I'd
| rather devote my limited effort to poking around over there.
|
| I do recall Telegram building a very weird variant of Diffie-
| Hellman that effectively let the server modify the secret key
| (and thus conduct MITM attacks.) In fact they did this
| multiple times in different ways, either by accident or
| through malice. This happened a long time ago so it's
| entirely possible that they've cleaned up their act, but it
| left a bad enough taste in my mouth that I'm afraid to poke
| around in their crypto and render any opinion. If I look at
| it and say "looks better now" I'm afraid I'd just be hurting
| people. Unless the company makes a real effort to bring their
| crypto engineering up to a higher standard, I won't feel
| confident in any of it: there are too many non-standard bits
| of engineering where dragons might lurk.
| egberts1 wrote:
| There is a certain truth to that "conspiracy" theory.
| egberts1 wrote:
| " There is no other significance to these [uploaded] files."
|
| So sayth my canary.
| bijant wrote:
| Sry Moxie, you lost my trust when you temporarily took the signal
| codebase closed source to integrate some cryptocurrency scams
| into it. Now your criticism just sounds like whining about a more
| successful competitor. Why is Telegram winning against Signal ?
| Mainly because the app is more stable and doesn't dictate its
| philosophy to the user. Proper e2e encryption has tradeoffs. Why
| shouldn't the user decide for which conversations he is willing
| to place convenience over security ? Why does Signal force users
| to use a pin even if they don't want to ? Why do you lose your
| history when you switch between android and ios ? why would I
| choose a messenger that requires a phone number over another that
| does not ? I was an enthusiastic evangelist for signal. But over
| the years you just lost me. I still use it but I don't recommend
| it anymore. I know, I'm not the only one. Apparently you seem to
| think, you can make up for it with paid advertising that you
| plastered my city with (repeatedly). I would have preferred to
| see that budget allotted to developing a more stable client and
| new features, but I'm not calling the shots.
___________________________________________________________________
(page generated 2021-12-23 23:02 UTC)