Hacker News new | ask | show | jobs
by stinkytaco 2130 days ago
First of all, most of this goes back five years and things have likely changed, but basically MTProto used several non-standard and out of date security mechanisms (no AE and using SHA1 were fairly notable at the time) whereas Signal was purposing fairly standard and widely used mechanisms (OTR). It's possible that many of those failures have been addressed over the years, but I haven't followed it closely. It's worth noting that Signal has been widely vetted over time and is the underpinning of WhatsApp, whereas MTProto continues to have a poor reputation, it seems.
1 comments

The very fact out-of-date security mechanisms passed into first version should tell the developers don't follow their field, or that they're complete amateurs. Both are flags so red Stalin would have a problem with it.