- world's most secure protocol – I’d consider this statement as false, I don’t know what they mean by most secure and what protocols were considered. May be messengers available at app store, better to ask them
Why do you think that they “rejected any attempt from the crypto community to help them”, especially after bug bounty proposition?
Why do you think that they lie more then TextSecure advocates? Each of these messengers is safe to passive listening. But unsecure to similar degree if user downloads them from app store and runs on hardware and software that could be easily patched. Current implementation of telegram api is prone to MiM attack but I would not consider TextSecure completely safe app and that every other app should be thrown out.
It's an interesting contrast in cultures that you phrase it like "Why do you think Telegram lies more than TextSecure advocates?" .... As far as I'm aware, TextSecure advocates haven't lied at all. TextSecure's interest is in security, whereas Telegram's interest seems to be in money and power.
Current implementation of telegram api is prone to MiM attack but I would not consider TextSecure completely safe app
I just don't know what to say to this. Telegram has been proven insecure, TextSecure hasn't. Telegram isn't designed by cryptographers, TextSecure is. There is absolutely every reason to assume Telegram is broken.
Each of these messengers is safe to passive listening.
This is mistaken because Telegram has been proven vulnerable to MITM attacks. Even after they patch this latest security problem, it would be very unwise to trust them.
> Current implementation of telegram api is prone to MiM attack but I would not consider TextSecure completely safe app
> I just don't know what to say to this. Telegram has been proven insecure, TextSecure hasn't. Telegram isn't designed by cryptographers, TextSecure is. There is absolutely every reason to assume Telegram is broken.
Textsecure is designed by cryptographers, and hasn't been broken yet, but that doesn't mean that it is secure. People need to risk assess when they're using any software.
> If you want to be secure from the NSA, use TextSecure [...]. It's really that simple.
That claim is far too confidant! If you want to be secure from NSA you need to do many things - have a look at the specifications for buildings that handle secret documents for example, as well as just using a piece of well designed but relatively untested software.
Most people do not have nearly enough operational discipline to withstand investigation by well funded government agencies. Merely using this software is not enough.
> If you want to be secure from the NSA, use TextSecure [...]. It's really that simple.
That claim is far too confidant! If you want to be secure from NSA you need to do many things - have a look at the specifications for buildings that handle secret documents for example, as well as just using a piece of well designed but relatively untested software.
That's why I removed it 15 seconds after I wrote it. But perhaps it could be downgraded to "if you want to live in a world where it's very difficult for governments to vacuum up all your data by default, then use TextSecure, because it's the first step towards that." Telegram offers no such protection since it's vulnerable to MITM attacks (even after they fix this one).
If you rely on a single secure (for certain values of the word 'secure') messaging system or protocol you're absolutely insane. You'd want to be splitting your communication across multiple communication sources, with none of them ever seeing enough data to compromise whatever it is you're worried about. Deep and computationally expensive is great; deep, computationally expensive and broad is better. If one form (e.g. Telegraph) falls they've not got the full message, and they've still got a lot more work to do to get the whole thing.
Telegram seems to be interested in money and power because they've turned down offers from Moxie (the creator of TextSecure and a well-known cryptographer) to join forces. There's no reason to do that unless they were interested in money or power more than security.
I didn't say TextSecure is completely safe. I said Telegram has been demonstrated to be broken.
Telegram is prone to passive listening because their design doesn't prevent it. There's nothing stopping someone from MITM'ing every Telegram secret chat when it's first initiated. It's in the design.
Their contest means nothing, because due to the way the contest is designed, it's impossible to MITM or other side channel attacks like timing attacks. These are the real attack vectors, yet the format of the contest prevents anyone from employing them.
>Telegram seems to be interested in money and power because they've turned down offers from Moxie (the creator of TextSecure and a well-known cryptographer) to join forces.
Is there a cause-effect relationship I'm missing here?
Yes you do. "TextSecure completely safe app" was copied from your message before you or someone else edited it. I've not typed it but copied exact phrase from your message.
You seem to be missing the larger point. Nobody is proposing that secure messaging apps should not exist. Everyone is better when more people try, iterate and fail (then recover and fix) to create secure messaging solutions.
What's unsafe and unproductive is when bozos jump in the pool, apparently ignorant or otherwise misrepresentative of the reality of how difficult it is to create a correct solution -- and confidently declare their implementations to be trustable.
If the messaging on Telegram had been, the world needs a secure messaging solution and we're committed to building it starting with this thing which we think is pretty good for XYZ, nobody would be objecting. Instead, these guys presented themselves as having solved a problem which is known to be difficult, and moreover using an unlikely method.
- military-grade encryption – true
- world's most secure protocol – I’d consider this statement as false, I don’t know what they mean by most secure and what protocols were considered. May be messengers available at app store, better to ask them
Why do you think that they “rejected any attempt from the crypto community to help them”, especially after bug bounty proposition?
Why do you think that they lie more then TextSecure advocates? Each of these messengers is safe to passive listening. But unsecure to similar degree if user downloads them from app store and runs on hardware and software that could be easily patched. Current implementation of telegram api is prone to MiM attack but I would not consider TextSecure completely safe app and that every other app should be thrown out.