Hacker Newsnew | past | comments | ask | show | jobs | submit | not_me_ever's commentslogin

We don't know if telegram is secure or not.

We do know that signal is lying: - About it's code being open source - About it's protocol being open - About it's funding - About it's massive white washing campaigns in forums - About smear campaigns against and harassment of journalists who dare to look into them

We do know that signal is probably insecure if(!) - It is actually based on the original white paper - It is actually using any of the code they released ages ago

There have been major security incidents with apps using the signal protocol, e.g. WhatsApp.

Who is the one doing the astroturfing?

You might not like the facts, but that doesn't change them.


> We don't know if telegram is secure or not.

I don't have anything against Telegram personally, but that sentence is by all intents and purposes equivalent to "Telegram is not secure".

Meanwhile, every person I have met at my past affiliations who did research in security was using Signal as their main IM app. Blind trust is always bad, but I don't think that crowd was using it just for cargo-culting.


We definitely know Telegram is not secure, because it doesn't encrypt chats by default, and I have never seen anyone turn the encryption on.

Doesn't help the encryption is very badly designed, possibly on purpose: https://words.filippo.io/dispatches/telegram-ecdh/


Signal apps and server are all on GitHub and frequently updated, for what it's worth: https://github.com/signalapp/Signal-Server https://github.com/signalapp/Signal-iOS.


And none of that code can be converted to something that is even close to the published app. They might as well just release the source code for the firmware of a fridge.


Frequent updates are not a sign of security. They are more like: Move fast, break things.


I was responding to

> code they released ages ago


> We don't know if telegram is secure or not.

Last time I checked, everything but the secret chats was not E2EE. So for the most part, it's effectively not secure. For the secret chats you're right, we don't know.

> signal is lying: - About it's code being open source

I compile and run Signal from the sources...

> About it's protocol being open

Are you talking about the Signal protocol here?

> We do know that signal is probably insecure if(!) - It is actually based on the original white paper

Can you elaborate on that?


"We don't know if telegram is secure or not."

The point was: This is a discussion about Signal, not Telegram.

But by now we have gotten pretty used to deflecting every discussion about "is Signal secure" to "look behind you, a three headed monkey" or rather to "but telegram is not secure, because all Russians are stupid".

"I compile and run Signal from the sources..." Yes, so you get a messaging app that might be secure, while 99.999% of users use the one from the store which very likely comes from a completely different source.

"The original whitepaper" Just use you favourite search engine, we have been over this dozens of times by now. If you understand security I would start here: https://cs.nyu.edu/~afb383/publication/uc_signal/uc_signal.p... If not -- it probably takes 15-25 years to teach you.

Very rough, and simplified: "Double Ratchet has some very strong preconditions which have never been addressed by signal, and probably never been implemented by anybody." (Please, don't quote me on that, it's very dumbed down.)


> "We don't know if telegram is secure or not."

I did not write that, were you answering to me?

> Yes, so you get a messaging app that might be secure

I was answering to... well to what I quoted: "signal is lying: - About it's code being open source". So it is obviously open source enough that I can compile it from sources.

> "The original whitepaper"

I did not write this either, were you answering to me? I am a little confused.


What major security incidents?


The random number generator in signal is fully predictable. There is no need for a back door -- when the front door has no lock.

:sigh:


That is a pretty damming accusation. Can you provide more details? This should be the sort of thing you should be hearing from a disclosure or ideally a vendor advisory - not an HN comment thread on a vaguely related article. Failures of randomness are almost always fatal to a cryptosystem.


Do you have a source for that?


Of course he doesn't have a source for that


Source: made it up


Source: Read and understood the original whitepaper. Plus verified it in the (probably fake) source code.

You can do it too. Might take a decade or two depending on your mathematical background.


Why would I need to spend two decades? You already did it. Congratulations on probably one of the biggest exposés of this decade. Ignore the haters with their "delusions of grandeur" insults. You will soon have global fame. So, when are you publishing your bombastic exposé? Or do you plan to sell it for it's minimum $1 billion value? Either way, great job!


Google has been ruining the internet since 1998. So no news here.


Hi @not_me_ever

I know this is totally unrelated and probably won't see it, but I read your comment about German solar farms sometime ago and I was wondering if you could throw light on that. I can't find any email to contact you by except the one you shared like a year ago (hnr@webhome.de) which I figured belongs to your friend. Please, what's a good email where I can reach you? Mine's in my profile. Thanks and hoping to hear back.


Funny how "journalists" who spend their day in a text editor, or at least should, keep saying that 8GB is not enough, while award winning AAA game developers are fully ok with 8GB.

Yes, 16GB (or currently 18GB) is nice, but it only means I can leave chrome & slack open forever; And has no impact on my actual work whatsoever.


What AAA devs are okay with 8GB? It's really common to hear devs complain about RAM limitations on the Xbox Series S which has 10GB of RAM.


Hi @not_me_ever

I know this is totally unrelated and probably won't see it, but I read your comment about German solar farms sometime ago and I was wondering if you could throw light on that. I can't find any email to contact you by except the one you shared like a year ago (hnr@webhome.de) which I figured belongs to your friend. Please, what's a good email where I can reach you? Mine's in my profile. Thanks and hoping to hear back.


ML is quite ok at answering questions, but it is very bad at asking the right questions.

Engineering is about asking questions.

Looks like we are at least 50 years out from "AI" replacing entry level engineers. I'll let me grand children worry about that, and use this glorified auto completion until then.


Hence my question was about programming rather than engineering. Composition could, for a long time, be a task humans do whereas the components are generated by AI.


It's genius.

And finally my $1/month 50.000 free worldwide texts burner phone is earning some $$$. Well $$$$$ to be exact.


In other words you're violating the provider's terms and conditions. I fully expect either you to get kicked out by them or the product to change.


And that's why it won't be $1 in a few months. But you earned your buck, good job. Tragedy of the commons courtesy of telegram + not_me_ever


which provider are you using, out of curiosity?


Broken software might crash -- no news move on


Wait, they write to protected memory, and get killed.

:tripplefacepalm:

Somebody hire some engineers at Oracle.


Sarcasm only works when you are actually smart and know what you are talking about.


To finish validating a request and then start executing it creates a race condition. That's why execution always needed to fail in a recoverable way.


JavaScript A Nightmare


My GF earns more money selling her hand made weaves than the average senior SWE at google.

When did they come for the weavers?


Assuming a senior SWE there probably makes around $500T I guess your GF would need to sell one woven item for $2,000 every week day for the whole year to come close to that? That seems like an amazing amount of work, is she a spider perhaps? ;)


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: