Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> But until someone actually published any hard evidence demonstrating weaknesses (ideally with a PoC), do we have anything else to go by?

Here you go:

https://news.ycombinator.com/item?id=41350809



How does that prove that Telegram as a whole is not secure? The only thing that would demonstrate is that your normal, not-E2E encrypted, messages aren't E2E encrypted, which yeah, of course they aren't.

I think you might confuse what the mud puddle test aims to demonstrate. It's to be able to confirm E2E encryption, which if you do that test with Telegram + Secret Chats (which is the E2E encryption feature in Telegram), you'll see you cannot recover those messages.


> How does that prove that Telegram as a whole is not secure?

It depends on what you mean by "as a whole". I mean that Telegram by default can read all your private chats, unless you manually enabled e2ee and suffer from related bad UX. On Linux desktop (and phones) it doesn't even allow to enable e2ee at all.


> It depends on what you mean by "as a whole". I mean that Telegram by default can read all your private chats

Yes, this is the expectation. You use someone else's platform that doesn't have E2E, you assume they can read your messages and will help law enforcement to do the same. No surprise there.

Doesn't mean their E2E feature isn't secure, or that the platform as a whole isn't secure. Facebook surely shares their Facebook + Whatsapp data with US law enforcement, we wouldn't call Facebook/Whatsapp insecure just because of that.


Whatsapp does, as far as anyone can tell, have e2e encryption. Now in principle it may be vulnerable to a government forcing Facebook to compromise it, but it's there.


> we wouldn't call Facebook/Whatsapp insecure just because of that.

I and many others certainly would.


>On Linux desktop (and phones) it doesn't even allow to enable e2ee at all.

There's "New secret chat" option on my Android client. Or what do you mean by "phones" here?


I mean on GNU/Linux desktop and GNU/Linux phones.


> The only thing that would demonstrate is that your normal, not-E2E encrypted, messages aren't E2E encrypted, which yeah, of course they aren't.

I mean, if nothing else, that's a bad default. This makes it worse than, say, WhatsApp or the apple messaging thing, nevermind the likes of Matrix or Signal.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: