Hacker News new | ask | show | jobs
by donogh 2332 days ago
What's more is that Telegram's approach to crypto has been shown to be deeply flawed[1].

I take my chances with Signal instead. Unfortunately, enticing all of my contacts to do the same has proven difficult.

An aside: is anyone else disturbed by the fact that Whatsapp now shows the Facebook logo when you first open the app? The day the Facebook Messenger/Instagram/Whatsapp merge happens is the day I'm deleting Whatsapp.

[1] https://security.stackexchange.com/questions/49782/is-telegr...

8 comments

> is anyone else disturbed by the fact that Whatsapp now shows the Facebook logo

I'm disturbed because I dislike facebook, but reality hasn't changed – only become more visible. That's good. Especially for people who aren't savvy enough to already know FB owns whatsapp.

Sorry. You're wrong and you're spreading SEVEN years old information, which is not true in 2020.

Telegram crypto was redone, and is now using standard primitives. You can verify it at high level at https://core.telegram.org/mtproto or low level if you'd like to check sourcecode in their github. BTW, telegram has reproducible builds since last year.

I'm tired of people repeating 7 years old meme without verification.

Standard primitives, perhaps, but has the scheme itself been reviewed by competent cryptographers?

At best, the Telegram developers are well meaning but have demonstrated in previous versions of MTProto that they lack a background in cryptography or a desire to consult experts. And their public face—posts like this one—seem often to be hyperbolic attacks on competitors, which is not a great look.

I’m not a cryptographer, so I’m not going to review the current MTProto. I hope it’s awesome and bug-free. But some skepticism seems warranted.

Does Telegram use end to end encryption by default yet, or does it still send and store everything except for secret chats to the Telegram service in plaintext?

Also, when you use the secret chat feature does that now support multiple clients or does it still establish a secret chat with a random recipient client over which neither initiator nor receiver can control?

What does "deeply flawed" mean? Is there any proof Telegram has been severely compromized over the last years? It appers not, thus in my opinion it is impossible that Telegram's approach to crypto is "deeply flawed".
I think it means deeply flawed as in, reinvent security instead of using battle tested methods.
The articles you linked to are five years old. What I'd like to know is if there have been any actual recent attacks on Telegram.
It's a good thing if they display that logo. A lot of users aren't (or weren't) aware that WhatsApp, or even Instagram, are owned by Facebook.
In November, Facebook made a branding push in its major aquistions (e.g. Whatsapp and Instagram):

https://techcrunch.com/2019/11/04/facebook-branding/

My guess it was for the "I don't use Facebook, I just use Instagram" crowd.

“is anyone else disturbed by the fact that Whatsapp now shows the Facebook logo when you first open the app”

Same for Instagram. I’m wondering if FB is trying to gain positive PR by highlighting the association. Or if it’s an upcoming regulatory requirement.

Could you clarify what you mean by your ultimatum for me?

Whatsapp and Instagram are already owned by Facebook - that is, as far as I understand, they have already merged.