Comment by maqp
2 hours ago
>is the only thing that matters, no matter what other features you have to throw out to get it.
That's just it, it's not a false dichotomy. Proper privacy engineering can achieve tons of private actually good features. And it's also fine for Telegram to not provide it, but then you can't really market yourself as more private than WhatsApp, "heavily encrypted" etc. There's loads of people who do not know how poor Telegram's security is. Informed consent is what matters much more than dialing every security feature to 11.
>What I am calling out is that this is a fundamentally ideological point of view.
Privacy is a human right: https://en.wikipedia.org/wiki/Right_to_privacy Just because some people sell it for pennies and convenience doesn't erode that fact.
> but general readers should be aware of what they are losing in order to enact this ideology with benefits that seem to be a bit dubious in the real world.
Sounds like you're trying real hard to get people to give up their human right. Why? Do you gain something personally from people using Telegram? Why would you defend such a shit product marketed with lies?
>It is well known that Meta is happy to hand over to any legitimate law enforcement agency any content they have.
Oh so privacy does matter to you when it's Mark Zuckerberg having access to your data but not when its Mark Zuckerberg of Russia having access to your data. The fact is, Telegram looks like an FSB op, or the very least, it doesn't give hard time for nation states to access messages of billion users. Hack the server and you're done.
>To the best of my knowledge, Telegram never has, and neither has Signal.
It shows a bit poor taste to equate these two. Signal doesn't have your data because it end-to-end encrypts all messages. Telegram does the opposite.
>The fact that Telegram potentially could someday seems more theoretical to me.
Their product is now 13 years old. If they cared about user privacy they'd have already hired competent cryptographers to design a protocol that provides the security and the features.
>Again, to the best of my knowledge, all actual leaks of messaging group content have been by various authorities compromising individual devices and/or their owners, which works equally well against Telegram and Signal.
Yeah except Telegram that clearly lacks proper security team wouldn't tell if their servers were compromised. There's nothing they could do to retain user trust at that point. They don't have to care about NSA or FSB or whatever hacking their servers because those agencies aren't boasting. And yeah user endpoint exploitation is obviously out of scope for secure messaging apps as networked TCBs can't be made hardened by some app vendor. I might know something about this topic as I'm the only person who has created messaging system that gets around that issue.
>Meanwhile, Telegram gives you a lot more practical security regarding what information to share with other users, and how to manage what other users can do in large chat groups, which seems like a much more real-world concern regarding actual dangers to users than what the company that owns it might potentially do at some future date.
Telegram IS the threat, not my friends in my closed group where I never need group management. Open groups that require granular permission controls do not require end-to-end encryption. The difference is, Telegram doesn't give you choice for small private groups with friends.
>I think for real security, it's better to pay attention to the business model of the company that runs it
It's SO CUTE that you're trying to control the narrative :D No Telegram has nothing to do with real security.
If Telegram is an FSB op, there is no business model. And if not, nothing prevents selling Telegram and its users and decades worth of data once it becomes unusable. Telegram is surveillance capitalistic, but the sale hasn't happened yet. You don't slaughter the piglet until it's grown. How many times do people need to repeat the same mistake of getting f'd by companies that betray them when it's time. You'd probably actually want to look into Signal's direction as it's a 501c3 non-profit, meaning it can't be sold.
>But on Signal, you're screwed if it's your mobile, and fine if it's any other device.
No you can just install Signal on new phone if old is stolen https://support.signal.org/hc/en-us/articles/360007062452-Wh... Then you just re-link your other devices to the new phone. It's the phone access controls' job to protect from accessing the messages.
>Though since you mentioned backups, I think Telegram's way is arguably more secure. Individual user backups, even encrypted, means all your communication security is at the mercy of whoever in your group has the weakest encryption keys and backup storage location. With a centralized system like Telegram, it's never anywhere but their servers.
Signal's backup storage location is at Signal's servers. The app generates a 256-bit encryption key for you. If you choose to use manual backups and upload them to some random ass company, then that's poor judgement on behalf of that person. The only thing worse, would be if Telegram would make that decision for EVERY group member, every time, with no chance to opt out :)
Your mental gymnastics are so insane if you aren't getting paid to shill Telegram, you definitely need to apply https://telegram.org/jobs
No comments yet
Contribute on Hacker News ↗