Hacker News new | past | comments | ask | show | jobs | submit | bugsbunny123's comments login

Telegram isn't secure? Source please.


http://www.cryptofails.com/post/70546720222/telegrams-crypta...

Also, messages are not encrypted by default, and there is afaik no way to encrypt group chats. You have to create a special "secret" chat for the messages to be encrypted.


All messages are encrypted by default, but not client-client (in order to make cloud sync work): https://telegram.org/faq#q-why-not-just-make-all-chats-secre...


It is possible to create synced messages without depending on a server decrypting the messages. Here's how Tox is going to implement that: https://github.com/Quoturnix/ProjectTox-Core/wiki/Multiple-d...


True, but Tox requires a password for that. Telegram tries to be an alternative to WhatsApp so forcing people to sign up with an account isn't an option.


It's the other way around. Messaging apps need to demonstrate their own security by releasing the source code.

So far only TextSecure does this.


One doesn't demonstrate security by releasing the source.

One needs to have source released, audited and verified to match prebuilt binaries that are actually used by the unwashed gray masses. Without all three checked for each public build you have zero assurance that you are running a binary built from the released source and that the source doesn't have anything fishy in it.

The only app that checks all three, somewhat ironically, is TrueCrypt. PGPfone checked #1 and #3. TextSecure checks just #1 unless I am missing something, so objectively its "demonstrated security" is exactly the same as that of any another app that simply describes what it does in plain English and has a traffic to prove it.


The Truecrypt audit still hasn't been finished yet, has it?


Telegram's client code is also open source.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: