Hacker News new | past | comments | ask | show | jobs | submit login

Telegram is available on F-Droid. It's similar to Signal with more functionality and greater ease of use - https://f-droid.org/packages/org.telegram.messenger/

You need a phone number that can receive texts for the initial setup, but once you're set up people can add you by @username and never need your number. Stuff like https://www.textnow.com/downloads works just fine for the initial text. Once you have a single device set up, it messages your existing devices rather than sending SMS when you try to connect another device.

One of the main people behind Signal actually tried to spread a bunch of FUD about Telegram years ago, saying the crypto was weak, but it's really not. No working POC code was provided to decrypt anything, just FUD.

Protocol details here: https://core.telegram.org/mtproto They just released MTProto2 in the last year.




Telegram isn't remotely similar to Signal. Telegram communications aren't encrypted by default, and Telegram group chat messages aren't encrypted at all.


This is 100% false. EVERYTHING that goes over the wire is encrypted, always, just like when you're on a TLS website such as your bank.

Group chats aren't end-to-end encrypted, and 1 on 1 chats are only end-to-end encrypted if you make it a Secret Chat.


Did you really think they were talking about SSL in this context? Of course they meant E2E.


To say there's no encryption AT ALL when it's fully encrypted over the wire is still false. Not having E2E encryption is different than not having encryption AT ALL.


They are encrypted in the same sense that the Sesame Street website is encrypted.


So, it's similar to Facebook Messenger rather than to Signal?

(Actually I think Messenger might support E2EE group chats, but I'm not sure.)


All crypto is weak until proven otherwise. Telegram never received a good review from cryptographers. The fact that no POC was provided may just as well mean no cryptographer cares enough to find a bug.


No, he said the crypto was weird (which it is. Who the eff uses IGE mode?) and that their competition to find vulnerabilities was bullshit and would be secure even using crypto primitives that are known to be weak.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: