this post was submitted on 23 Dec 2024
119 points (91.6% liked)

Technology

60412 readers
3436 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 2 years ago
MODERATORS
all 29 comments
sorted by: hot top controversial new old
[–] demesisx@infosec.pub 40 points 3 weeks ago (4 children)

“Trust me bro” style hand-rolled encryption.

[–] pgetsos@fedia.io 9 points 3 weeks ago (1 children)

The encryption is not Trust me bro. It is public and tested multiple times. For example an analysis back in 2021:

https://mtpsym.github.io/

It found somes issues in the implementation of MTProto 2.0 from the official apps, with only one of them being actually usable as an attack vector, and they were all fixed before the disclosure of the analysis. They found no issues with the encryption algorithm other than some choices that may make the implementation of it harder

[–] rikudou@lemmings.world 12 points 3 weeks ago (1 children)

The encryption that only works in one-on-one chats? The encryption that's multiple menus deep in said one-on-one chats? The encryption that no one uses because of the issues above?

[–] EngineerGaming@feddit.nl 3 points 3 weeks ago (1 children)

The encryption that is not even available outside of mobile?

[–] anzo@programming.dev -1 points 2 weeks ago (1 children)

That's actually a perk. Means the decryption key is not uploaded to telegram servers.

And, yes. The encryption all of the normies learnt to use for buying illegal goods while the prices were posted in wide open group chats. At least that's how it was working in latin america with drugs.

[–] EngineerGaming@feddit.nl 1 points 2 weeks ago* (last edited 2 weeks ago)

That's actually a perk. Means the decryption key is not uploaded to telegram servers.

You could make encryption work between multiple ends without the server having to share the keys if each device has its own key - like in Matrix, XMPP, etc. And given that Telegram can't do that, the restriction in question is still very arbitrary - in a one-to-one conversation, they just don't allow you to make your end the desktop and not the phone.

Also yes, here selling drugs over Telegram is a very big thing too and given how hard it is to use Telegram anonymously and safely - it is indeed monumentally stupid.

[–] ouch@lemmy.world 7 points 3 weeks ago

What encryption? There is no E2EE by default. It's all plaintext.

[–] lepinkainen@lemmy.world 0 points 3 weeks ago

I exclusively use it for public chats, like I did IRC.

Neither had any encryption and I have no issue with it.

[–] blackfire@lemmy.world 17 points 3 weeks ago (1 children)

This is kind of good news it means there is still a major alt to WhatsApp. Still my second to last app but it does have a lot of linux groups on there

[–] Speculater@lemmy.world 18 points 3 weeks ago (3 children)

Isn't WhatsApp 100% backdoored for the US and Telegram for Russia? I thought Signal was the only reliable app?

[–] Khanzarate@lemmy.world 10 points 3 weeks ago

Yes but that doesn't mean they're not important in ensuring there isn't a messaging monopoly.

Obviously in an ideal world we'd have multiple interconnected secure apps with some cross-platform interoperability, but until then I'll settle for one government/corporation not having all of everyone's private conversations.

[–] accideath@lemmy.world 7 points 3 weeks ago (2 children)

If Telegram is backdoored, not for Russia. While the founder and owner is Russian, him and the company left Russia in 2014 when they didn’t want to comply with their regime (I think. Don’t remember the details). The company is based in Dubai since 2017.

[–] Neon@lemmy.world 4 points 3 weeks ago (1 children)

Telegram is 100% backdoored

Whatsapp only the backups (although I think they stopped?) and Metadata (with whom you chat, when you chat, but not the exact words you chat) are backdoored.

Signal is the only major app tht's not backdoores

[–] Zacryon@feddit.org 8 points 3 weeks ago (1 children)

Telegram is 100% backdoored

What makes you so sure?

[–] rikudou@lemmings.world -2 points 3 weeks ago
  • it doesn't have end-to-end encryption
  • Russia wants the data
[–] prex@aussie.zone 13 points 3 weeks ago
[–] hsdkfr734r@feddit.nl 12 points 3 weeks ago (5 children)

The app is free. What do they sell?

[–] pgetsos@fedia.io 18 points 3 weeks ago (1 children)

Along with the premium version, they have a crypto currency (TON) that can be used to buy things on the platform from other users, and I think you can also buy things with real money and they keep a small commission. Also there are some small ads in very large channels (not groups, channels only) and ways to gift "stars" to other people, like Patreon or sth

[–] hsdkfr734r@feddit.nl 6 points 3 weeks ago

Thanks. That makes sense to me.

[–] Jiggs@lemm.ee 15 points 3 weeks ago* (last edited 3 weeks ago) (1 children)

There is some premium version iirc. Bigger files can be sent, custom emojis, that sort of things

[–] hsdkfr734r@feddit.nl 6 points 3 weeks ago

Ah. They are profitable through premium accounts? Impressive.

[–] MangoPenguin@lemmy.blahaj.zone 9 points 3 weeks ago

Premium upgrade version.

[–] ouch@lemmy.world 8 points 3 weeks ago

Telegram always seemed a bit sus to me. I have hard time trusting that they don't sell all that non-encrypted data somewhere.

[–] GhiLA@sh.itjust.works 5 points 3 weeks ago

It's the backend for web3 scams.

All of memecoin shittery happens on telegram.