Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Encryption Privacy Your Rights Online

Signal Slams Telegram's Security (techcrunch.com) 33

Messaging app Signal's president Meredith Whittaker criticized rival Telegram's security on Friday, saying Telegram founder Pavel Durov is "full of s---" in his claims about Signal. "Telegram is a social media platform, it's not encrypted, it's the least secure of messaging and social media services out there," Whittaker told TechCrunch in an interview. The comments come amid a war of words between Whittaker, Durov and Twitter owner Elon Musk over the security of their respective platforms. Whittaker said Durov's amplification of claims questioning Signal's security was "incredibly reckless" and "actually harms real people."

"Play your games, but don't take them into my court," Whittaker said, accusing Durov of prioritizing being "followed by a professional photographer" over getting facts right about Signal's encryption. Signal uses end-to-end encryption by default, while Telegram only offers it for "secret chats." Whittaker said many in Ukraine and Russia use Signal for "actual serious communications" while relying on Telegram's less-secure social media features. She said the "jury is in" on the platforms' comparative security and that Signal's open source code allows experts to validate its privacy claims, which have the trust of the security community.
This discussion has been archived. No new comments can be posted.

Signal Slams Telegram's Security

Comments Filter:
  • real takeaway... (Score:2, Insightful)

    by dfghjk ( 711126 )

    These comments are unprofessional and reflect someone with little education. It shows that these social media sites are run by thin-skinned, immature, poorly educated and selfish people. We knew that already, but now there isn't even a PR veneer to it.

    • Re:real takeaway... (Score:5, Informative)

      by Midnight_Falcon ( 2432802 ) on Friday May 24, 2024 @12:25PM (#64496255)
      Huh? Meredith Whittaker is a well educated person who in this instance is 100% right. Telegram markets a false sense of security while not having end to end encryption outside of secret chats. Signal's security model is far superior, and Telegram should not be trusted for any communication you don't want intercepted.
      • Iâ(TM)ve been suspicious of Telegramâ(TM)s security for a while. Russia tried to ban Telegram, but after a while gave up. It makes me think they have a backdoor.

      • by AmiMoJo ( 196126 )

        Signal has its own issues though. Lack of federation and 3rd party clients being the two biggest ones. At least you don't need a working phone number to sign up now.

        The protocol is okay, but not very resilient to traffic analysis.

        • The issues you describe in Signal are trivial compared to the huge, gaping freight-train sized hole in Telegram's security: Your messages and group chats sit plaintext in a database they control. Signal's protocol makes such a thing an impossibility.
          • by AmiMoJo ( 196126 )

            My point was that we need something better then either of them.

            • Yes, unfortunately; it will most likely take a new generation of self-disinterested cryptopunks to spawn a new incarnation of Signal. Moxie Marlinspike wrote Signal, ended up having a bit of an inconvenient life because of it (searches at borders, harassment by federal agencies); and ended up eventually deciding to try to monetize it via the WhatsApp sale and some shenanigans at a crypto company.

              Nadim Kobeissi gave up on trying-to-be-easily-accessible-to-normal-users cryptocat.

              Most of the talent in c

    • It shows that these social media sites are run by thin-skinned, immature, poorly educated and selfish people.

      That is a fantastic description of the guy who runs Shitter. Bravo!
    • by Hadlock ( 143607 )

      The real takeaway is that signal was the best end to end encrypted solution, right up until they dropped SMS support, at which point I had to stop using it. Telegram is trash garbage and everyone should shout it from the rooftops, which they are. Encryption nerds have always been rough around the edges, get used to it.

      • by unrtst ( 777550 )

        ... right up until they dropped SMS support, at which point I had to stop using it.

        Curious... why? And what do you use instead?

      • > they dropped SMS support, at which point I had to stop using it

        Had to?

        Did your boss make you?

        There are so few situations in which this might be true.

      • by ceoyoyo ( 59147 )

        If end-to-end encryption is important to you why were you using SMS, and why in the world would you stop using Signal because it stopped supporting unencrypted messaging?

  • by backslashdot ( 95548 ) on Friday May 24, 2024 @12:36PM (#64496297)

    She went hard. And she's super correct about Telegram being shitty. But one gripe with Signal is how many God-damn updates they have. They seem to pushing builds to production every time someone changes a line of code. They really take the "CD" part of CI/CD seriously. Good Lord. Are people independently checking this stuff for backdoors?

    • by ddtmm ( 549094 )
      There's a problem with a lot of updates? It's not like you have to install them yourself. Devices update apps automatically I would never know an app has been updated unless there was a UI change. I'd rather get security updates as soon as possible.
      • The concern he pointed out was third-party auditing of a fast-moving target.

        It's a fair point; perhaps not as concerning as the prior Chairman of the Board of Signal Foundation having /deep/ Intelligence Community ties.

        As far as we know Signal is secure but was that yesterday's build or Tuesday's build?

        If we're suspicious and a national emergency happens and a new build comes out ... then what.

        We should learn from the xz penetration.

      • I'd rather my software not get borked because an install was forced on me. I'll update when I feel like it, if ever. It's bad enough software companies insist every update changes the UI or removes features. Having to deal with a mangled piece of software is even worse.

        The first thing I do is turn off updates or, in the case of Firefox, tell it to piss off when it autistically shrieks there's a newer version available because the option to never be harassed is no longer available (see above).

    • https://signal.org/blog/reprod... [signal.org]

      though it would be hilarious if, after setting up a reproducible build system, no one bothered to actually check the build.

    • by unrtst ( 777550 )

      But one gripe with Signal is how many God-damn updates they have.

      Yes! But I wouldn't mind them if they didn't forcefully deprecate the previous version and halt its ability to communicate.

      FWIW, I'm specifically referring to the desktop client for Linux. When a new version comes out in the middle of the day, it suddenly stops working and displays a banner saying it's outdated and must be updated in order to sent messages.

      If the messaging API changes in a non-backward-compatible way, then of course they would need to force updates so everyone could continue messaging (or s

  • Having used Signal for some time, the assurance of its end-to-end encryption has been a real comfort. But I also get why some might prefer Telegram for its social media features. Reading about it reminded me of an essay example I stumbled upon on this website [papersowl.com] about social media and fake news. Security is so crucial in today's digital age, especially with the spread of misinformation.

A commune is where people join together to share their lack of wealth. -- R. Stallman

Working...