[HN Gopher] Moxie on Telegram Encryption
       ___________________________________________________________________
        
       Moxie on Telegram Encryption
        
       Author : decrypt
       Score  : 25 points
       Date   : 2021-12-23 19:27 UTC (3 hours ago)
        
 (HTM) web link (twitter.com)
 (TXT) w3m dump (twitter.com)
        
       | sschueller wrote:
       | Moxie obsession with Telegram is odd especially when he blocks
       | anyone just a tat critical about signal. He seems to be unable to
       | deal with any criticism even if constructive.
       | 
       | I don't trust him, sorry.
        
         | no_time wrote:
         | He is certainly weird in many regards. Does anyone know for
         | example why is his personal site, moxie.org excluded from the
         | Wayback Machine?
        
       | eloeffler wrote:
       | It really is strange that Telegram is commonly considered an
       | "encrypted" messenger while the app makes it very difficult for
       | users to actually use e2ee.
       | 
       | The feature is hidden, and old "secret chats" stop working after
       | a while without any indication that messages cannot be delivered
       | anymore. To start a "secret chat" one must access it from a menu
       | entry stashed away in users' profiles. And you can only start
       | writing a secret message when the other side "comes online" for
       | the first time after starting a "secret chat".
       | 
       | All discussions about the technical implementation of e2ee in
       | Telegram aside, this makes e2ee a pain, which is why it is rarely
       | used (by most) if not desparately needed.
        
       | zarzavat wrote:
       | I subscribe to the conspiracy theory that Telegram is actually a
       | plant by a security service (FSB?). The app seems to be
       | constructed in bad faith. Presumably Telegram has the resources
       | to increase their encryption/privacy level, yet they have not
       | done so, so the question "why would anyone knowingly market an
       | app as a private messenger without providing privacy" can only be
       | answered by "because they want the data". And who would want the
       | data of people who think they are communicating privately but are
       | actually not?
        
         | coolspot wrote:
         | I didn't see any evidence that Telegram's "secret chats" are
         | vulnerable to snooping.
         | 
         | They are separate from regular chats and not available in the
         | official desktop app, but they are secure.
         | 
         | Signal with their "we trust Intel SGX to be single point of
         | failure" kinda smells like a government honey pot.
        
           | [deleted]
        
           | matthewdgreen wrote:
           | I also don't see a lot of evidence that they're bad, but it
           | should be said that this is the wrong standard. I also
           | haven't seen a lot of convincing evidence that Telegram's
           | crypto is good (and plenty of past evidence of weird
           | mistakes.) Overall what I've learned from examining
           | Telegram's crypto in the past is that the company does not
           | really value outside expertise and analysis, nor do they make
           | it easy to review their (very strange and non-standard)
           | protocols.
           | 
           | Reviewing crypto is hard _when you're working with an
           | organization that has good engineering practices and
           | minimizes the possible risks._ My early examination of
           | Telegram crypto led me to the conclusion that Telegram was
           | not an organization whose approach to crypto engineering is
           | compatible with that standard, so it's not worth the effort
           | to try to vet their crypto when the company leaves so many
           | weird question marks in their engineering approach. Meanwhile
           | there are products with more professional crypto teams
           | working hard to behave in ways that engender trust: I'd
           | rather devote my limited effort to poking around over there.
           | 
           | I do recall Telegram building a very weird variant of Diffie-
           | Hellman that effectively let the server modify the secret key
           | (and thus conduct MITM attacks.) In fact they did this
           | multiple times in different ways, either by accident or
           | through malice. This happened a long time ago so it's
           | entirely possible that they've cleaned up their act, but it
           | left a bad enough taste in my mouth that I'm afraid to poke
           | around in their crypto and render any opinion. If I look at
           | it and say "looks better now" I'm afraid I'd just be hurting
           | people. Unless the company makes a real effort to bring their
           | crypto engineering up to a higher standard, I won't feel
           | confident in any of it: there are too many non-standard bits
           | of engineering where dragons might lurk.
        
         | egberts1 wrote:
         | There is a certain truth to that "conspiracy" theory.
        
       | egberts1 wrote:
       | " There is no other significance to these [uploaded] files."
       | 
       | So sayth my canary.
        
       | bijant wrote:
       | Sry Moxie, you lost my trust when you temporarily took the signal
       | codebase closed source to integrate some cryptocurrency scams
       | into it. Now your criticism just sounds like whining about a more
       | successful competitor. Why is Telegram winning against Signal ?
       | Mainly because the app is more stable and doesn't dictate its
       | philosophy to the user. Proper e2e encryption has tradeoffs. Why
       | shouldn't the user decide for which conversations he is willing
       | to place convenience over security ? Why does Signal force users
       | to use a pin even if they don't want to ? Why do you lose your
       | history when you switch between android and ios ? why would I
       | choose a messenger that requires a phone number over another that
       | does not ? I was an enthusiastic evangelist for signal. But over
       | the years you just lost me. I still use it but I don't recommend
       | it anymore. I know, I'm not the only one. Apparently you seem to
       | think, you can make up for it with paid advertising that you
       | plastered my city with (repeatedly). I would have preferred to
       | see that budget allotted to developing a more stable client and
       | new features, but I'm not calling the shots.
        
       ___________________________________________________________________
       (page generated 2021-12-23 23:02 UTC)