• gedaliyah@lemmy.world
    link
    fedilink
    English
    arrow-up
    87
    arrow-down
    1
    ·
    11 hours ago

    Wait, the centralized service that security experts warned for years could be easily compromised because a centralized messaging service is inherently insecure has now been compromised? Surprised Pikachu face

    • Star@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      1
      ·
      6 hours ago

      Not to discredit your arguement but isn’t Signal also centralised?

      • lemmylommy@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        3 hours ago

        It is. But it is open source and the encryption is solid. All communication data is end-to-end encrypted. They have been subpoenaed before and all they could provide was when the account was first registered and when it was last used. The signal protocol is well documented and open source. The foundation and LLC behind it are registered in California and are run by reputable people.

        Telegram is run by shady people, supposedly out of Dubai, while it is registered in the British Virgin Islands. Its clients are also open source, however the encryption, if enabled, is of the home cooked variety, although it was improved over time. Unfortunately it is not enabled by default, you need to enter a „secure chat“ for that, which only works with single contacts, not with groups. Despite having access to everything else, and working like a social media-messenger-hybrid, telegram is very reluctant to get rid of clearly illegal content.

      • gedaliyah@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        6 hours ago

        The data is not centralized in the same way, making it slightly better, but yeah. A lot of the same pitfalls of centralization happen there. The whole system doesn’t operate without the corporate servers in the middle, even though they don’t see or store the data. They have total access to Metadata. The organization could be sold for profit, shut down, change terms, etc.

        If security is important, you’re better off with something decentralized like matrix. I’m not an expert, so hopefully, a lot of people here who are smarter than me will fact check these statements, but at least those are my impressions.

      • MiltownClowns@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        6 hours ago

        It is, which is why the comment didn’t advocate for it. Signal has more robust encryption than telegram, but its not zero-trust. They should really be using private hosted services instead of public or pgp, but when battle kicks off you use whatever works and then go back and revise as needed when you’re not dodging bombs.

    • MehBlah@lemmy.world
      link
      fedilink
      English
      arrow-up
      35
      arrow-down
      2
      ·
      edit-2
      10 hours ago

      Owned by a fake rebel russian who has somehow managed to keep from falling out of a window on a high floor. Cough, cough plant.

  • cheese_greater@lemmy.world
    link
    fedilink
    English
    arrow-up
    31
    arrow-down
    1
    ·
    11 hours ago

    Was kinda wondering when they were gonna cut the cord, Telegram is likely thoroughly compromised and compromising

  • triptrapper@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    2
    ·
    9 hours ago

    I know nothing about cyber security, but it’s funny to me that depending on the time of day these comment sections either mostly criticize Telegram or mostly support it. I have no idea what to believe or whether it’s safe for me to use Telegram.

    • helenslunch@feddit.nl
      link
      fedilink
      English
      arrow-up
      5
      ·
      8 hours ago

      I think people want to support encrypted communication apps in general, not Telegram specifically. It’s just that there are many far more secure apps.

    • iorale@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      1
      ·
      edit-2
      8 hours ago

      Tl;dr: big name services are to be avoided as much as possible, but even if I use alternatives like signal, telegram, simplex and such, I wouldn’t say I trust them since they are made by humans, no matter how much the fans defend them.

      As far as I’m concerned, no messenger is 100% safe, there will always be one reason or another to suspect a backdoor, man in the middle, your messages being spied inside the server or the host (a remainder that very few people can host their own things for one reason or another), whatever, you name it. It gets increasingly more suspicious the moment multiple people suddenly appear to attack one service and sing praises to another, specially if they ignore your needs or the chances to move that group of people you need inside that new app.

      At least we can count on big corpo apps to be compromised, anything meta, tiktok, microsoft, apple or google; nothing to be done about it since most normal people are afraid of improvement and just stick to what they already know.

      I use telegram because of how it works (like, it fills my needs); the pretty stuff and the design allowed me to bring my family and some people I know into it. Signal didn’t really had pretty things back then (nowadays I have no idea since all the fans yell at me is about it’s privacy and that I shouldn’t question any further) and was complicated to setup, no way I could bring anyone over.

      I’ve been looking into SimpleX but it’s still not where I could convice anyone to jump over… And I would still need use someone else’s host, so I wouldn’t say I trust it completely.

      It’s basically a pick your poison kind of thing.

      • mitram2@lemmy.pt
        link
        fedilink
        English
        arrow-up
        2
        ·
        6 hours ago

        Honestly curious, what was missing on Signal and what was complicated? I can’t even remember the sign up process and never felt I was missing out on features, at least not on features available elsewhere

  • Wilshire@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    9 hours ago

    I presume this will have zero effect, especially since it includes this huge exemption.

    Those who use Telegram “part of their job duties” will not be affected by the move.

    • Alex@lemmy.ml
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 hours ago

      I assume that is too cover the intelligence officers monitoring the Russian milbloggers.

    • andrew_bidlaw@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      7
      ·
      9 hours ago

      SMMs for officials, volunteers and military would keep posting, right. It’s inside communications that are a concern. And as some ukrainians wrote, in some places it was an obvious rule from the very start.

      • sunzu2@thebrainbin.org
        link
        fedilink
        arrow-up
        9
        arrow-down
        1
        ·
        11 hours ago

        Network effects… Once community picks the app, it ain’t changing.

        It pretty amazing that two years into the war this is still an issue in Ukraine especially at government/military level.

        I get plebs giving fuck all due to poor understanding, the state taking this long doesn’t make sense. These issues were brought from the start of the invasion.

        • helenslunch@feddit.nl
          link
          fedilink
          English
          arrow-up
          1
          ·
          8 hours ago

          Network effects… Once community picks the app, it ain’t changing.

          I think you’re sidestepping the question though. The question is why the community picked the app.

          • sunzu2@thebrainbin.org
            link
            fedilink
            arrow-up
            1
            ·
            8 hours ago

            Because Russian corpos shoved into their faces and the state was too stupid to see the issue with it despite being at war with Russia since 2014.

            People who criticized this were mercelessly mocked by the normies…

            Aka the same thing happening in the US, at least consequences aint bad here… For now

      • oce 🐆
        link
        fedilink
        English
        arrow-up
        2
        ·
        10 hours ago

        Maybe choosing your poison? Viber belongs to the Japanese company Rakuten, so it may be more interesting geopolitically, depending on your country.

  • Korkki@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    arrow-down
    17
    ·
    11 hours ago

    I would never risk any third party messaging service in military or critical state matters. It’s just common sense, even for a layman. Everything is compromised, Telegram is, Whatsapp is, Signal is, all of them are.

      • TheTechnician27@lemmy.world
        link
        fedilink
        English
        arrow-up
        16
        arrow-down
        2
        ·
        edit-2
        10 hours ago

        It’s not, unless they’re some sort of cryptography expert with a peer-reviewed white paper pending publication. The Signal protocol (GPLv3) is extremely robust and has almost no capacity for metadata generation, and both the app and server-side code are under the AGPLv3 (technically if they were compromised they could use different, unaudited server-side code, but refer back to “basically no metadata”). Signal has essentially no capacity to be compromised; they can’t even bait and switch users with a pre-compiled app whose source code isn’t the publicly available one and actually has a backdoor because their builds are reproducible and it would be caught immediately.

        Maybe they take issue with the crypto bullshit, which is valid but doesn’t compromise messaging security. Maybe they don’t like that they took away SMS, which I completely agree with, but also actually makes it marginally more secure. Either way, I seriously doubt if they had any mathematical insight into Signal being “compromised” that they would be here hanging around on Lemmy right now.

        • Kwozyman@lemmy.world
          link
          fedilink
          English
          arrow-up
          6
          ·
          9 hours ago

          Be that as it may, it’s still an incredibly short sighted decision to use a centralized service that is under 3rd party control for real security sensitive applications.

          • sugar_in_your_tea@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            7
            arrow-down
            1
            ·
            9 hours ago

            Yeah, that does bother me. But it’s also a lot easier to build a centralized service like that than to get people on a decentralized one.

            If you really want something private and are willing to jump through a few hoops, Simplex exists. But most people aren’t willing to jump through a few hoops, and even Signal (a pretty low bar) is a hard enough sell as it is. And that’s why I use Signal, because it’s my best chance to get people onto something better. In other words, don’t let perfect be the enemy of better.

            • helenslunch@feddit.nl
              link
              fedilink
              English
              arrow-up
              2
              arrow-down
              2
              ·
              8 hours ago

              But it’s also a lot easier to build a centralized service like that than to get people on a decentralized one.

              Is it? No one seems to have problems using email.