Hacker News new | ask | show | jobs
by lambdadmitry 3647 days ago
>That's all people can ever come up with.

This isn't true. [1] highlights handful of crypto problems in Telegram (besides it's being being opaque af).

>non-compliance with any government requests

How can you now?

>not being a legal entity in privacy-invasive countries

I've actually LOLed at this point. Telegram is developed in Saint-Petersburg, Russia; are you really sure that it's not a "privacy-invasive country"?

>which can make no claims on Telegram's chats or even metadata

The problem with Telegram is that passive snooping is enough to get that metadata. Given that Telegram servers are mostly outside of the US, it's a fair game for NSA to listen for Telegram metadata.

>the reason is efficient device synchronization

Already done in Signal.

>you are blowing it way out of proportion

"The market leader" didn't claim that it's all "secure" and "encrypted".

>none have actually broken the algorithm

See [1]. It was broken many times.

>Telegram added a bounty of $200 000

…under totally ridiculous and unrealistic restrictions. See comments here [2] for some context.

>neither has the Signal protocol been proven to be secure

It was to the large extent [3].

>they used existing building blocks (SHA1, AES, DH) to form a new protocol

If anything, recent security breaks shown us that it is very, very easy to combine secure building blocks in unsecure manner. Which is exactly what was done in Telegram case.

>that has stood the test of time so far

It hasn't [1].

>If anyone is opaque it's Whatsapp with their closed-source clients

A: Telegram is opaque and you can't trust it

B: Whatsapp is even more opaque!!!

Can you see how B can't be a counterargument to A?

>at the time Telegram came out with MTProto, there was no such thing as the Signal Protocol

There was, it was called "Axolotl ratchet protocol" [4]

It seems that your most basic assumption for this comment are wrong. Please reconsider your worldview re: Telegram.

[1]: http://cs.au.dk/~jakjak/master-thesis.pdf

[2]: https://news.ycombinator.com/item?id=6931457

[3]: https://eprint.iacr.org/2014/904.pdf

[4]: https://www.whispersystems.org/blog/advanced-ratcheting/