Hacker News new | past | comments | ask | show | jobs | submit login

Good! Time to move to telegram! And delete your facebook account! And uninstall whatsapp!

I expect nothing less from HN.




There is a lot of hype over encrypted chat programs.

Telegram's encryption is not end-to-end unless you opt into "Secret Chats"[1] and many claim their crypto is not secure[2,3] as they rolled their own[4].

The latest Google chat app Allo also backed away from defaulting to end-to-end encryption for all messages as it lessens the quality of their auto-assistant[5].

The Axolotl protocol (developed by Moxie and Trevor[6]) is available in Signal and was later adopted by WhatsApp. Signal has far fewer features than other chat applications, and people aren't clamoring much about it; I would guess because many people place features > crypto.

Wire (wire.com) uses this protocol as well[7].

WhatsApp being part of Facebook has already called into question their handling of privacy[8], the feature they were originally advertising as their main strength.

[1] https://telegram.org/faq#secret-chats

[2] http://security.stackexchange.com/questions/49782/is-telegra...

[3] http://www.cryptofails.com/post/70546720222/telegrams-crypta...

[4] https://news.ycombinator.com/item?id=6916860

[5] https://news.ycombinator.com/item?id=12547130

[6] https://en.wikipedia.org/wiki/Double_Ratchet_Algorithm

[7] https://wire.com/resource/Wire%20Security%20Whitepaper/downl...

[8] http://www.nytimes.com/2016/08/26/technology/relaxing-privac...


Still hoping that iMessage will switch to Axolotl rather than their broken E2E design.


And in case @m0xie complains that we should call it the "Signal Protocol":

No one will call it that as long as you claim that Signal is trademarked, and threaten legal action against projects using that name.

The LibreSignal issue, where you behaved worse than a kindergarten child (and I know, I volunteered to work some weeks in a kindergarten a few years ago) is still in memory for most people.


Given that it's not multiplatform it's kind of irrelevant. It's not a replacement for any of the others. I mean, yay for better encryption, but it's not going to help anyone on Whatsapp today.


So what's recommended then? Signal, Wire and Tox?


If you want desktop clients (electron, but at least not Chrome app) try Wire.


What's recommended is not posting anything you absolutely need to be secure through some instant messaging app...


It isn't about securely sharing highly sensitive material, but enabling verifiable privacy of typical communications. For example (hypothetically) me discussing cancer with a family member, or financial information, or (in countries where there is government oversight) organizing protests.

If not using a secure end-to-end encryption method such as chat, what do you recommend?

Email providers such as ProtonMail provide the same but in the form of email. Telephone calls are not secure, and neither are text messages.


If you are like me you can even use Telegram.

For the things I post on Telegram I don't care about crypto but rather about a good desktop client, features months ahead of Whatsapp, nice niche communities, bots (including the hn bot which is really nice to see all things that have been voted above a configurable threshold during the day.)

Now that I think of it a lot of what I use it for is as a RSS and twitter replacement: subscribing to channels and groups, occasionally posting harmless stuff.


A message should only be readable by the intended recipient, regardless of how sensitive the contents are.


Please do not use Telegram. It' closed source and uses some half-baked crypto. Signal is open source and is actually end-to-end encrypted.


Wire[1] is also an excellent option. Unlike Open Whisper Systems they wont hang you from a tree for building a third party app. Signal wont work without Gapps or Google Play Services on your Android phone and Google Chrome for desktop.

[1] https://wire.com/


Signal does work with MicroG (https://microg.org/), an open source reimplementation of Google Play Services.


But that still requires using the Google Play Services library in the Signal APK, still doing analytics.


I tried Wire after this WhatsApp news came out initially and brought about 10 people (friends/family) to it. They're satisfied how it works.


Signal is pseudo-open-source but will not allow you to use it except via the closed-source google play services, so I still wouldn't have confidence in it.


Yes. Also, on what payroll is Moxie now? He was working with Facebook on WhatsApp and then worked with Google on their new messaging app.


This is incorrect. There is an open source reimplementation of Google Play Services (https://microg.org/) and Signal works beautifully with it.


And wherefrom can you get Signal except for the Google Play store? I was looking for it a while ago to install on my phone but only found two other projects which were threatened by moxie and then shut down.


I compile my own binaries. Not too bad actually.


So the Signal APK does NOT depend on the Google Cloud Messaging library anymore, which pulls in 40k LOC of analytics?


Telegrams clients (and the e2e encryption) are open source. For instance: https://github.com/DrKLO/Telegram

Curious if you know why the crypto is half-baked. Has it been broken?

edit: found Signal server, I think: https://github.com/WhisperSystems/TextSecure-Server

Nice it's out there. This will help Signal live a long time.


Exactly. Not to mention if it becomes popular it will get sold to megacorp in a heartbeat.


I'll give signal another try, last time I couldn't register.


A lot of people here use twitter.

Why must things be provably sure to have any value?


No windows phone client :-(


If you've used Telegram for a while you will notice that in practice no one uses secret chats because these chats don't sync between devices. Your "non-secret" chats are readable by Pavel and anyone he wishes to share them with. I guess it's fine if you trust Pavel's good intentions. I don't[1].

[1] https://www.instagram.com/p/-MrPWGr7aL/


Holy shit, Pavel sounds very much like JM Le Pen.


I don't know what I would feel worst about: being compared to Merkel or Le Pen


But unfortunately he's right


I would not entrust my data to telegram either. Enrolling your own crypto protocol [MTProto] is, in my opinion, something which you should not do.

They also have a nice privacy policy, which is worth looking at: https://telegram.org/privacy


> Enrolling your own crypto protocol [MTProto] is, in my opinion, something which you should not do

Signal did the same thing.

The question is who's more capable and builds a more secure system


Why do you feel for insulting all of us at once?

HN is the most open, thoughtful (and honest-but-careful) public forum I know of and I intend to do my part to keep it that way.


I don't care too much for Facebook but WhatsApp has become essential to communicate with almost everyone I know.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: