Was I the only one thinking that the author of Careless People was careless herself?
I felt that she is much closer in values to the Facebook executives than she was trying to make it seem. Yes, she failed at her job because it was an impossible one, and she got no shares because she was too late to the party, but the bravery and carelessness she showed were absolutely mind-blowing, for my taste at least.
I couldn't finish the book because my Kindle died halfway, but based on the opening chapters I agree with you.
I admire her for the stance she's taking today and the personal sacrifice it's costing her to this day, but I won't deny that her own account sounds like someone who thought "this will be big" and decided to help without thinking "should this be big?" first.
Yes, I wonder why this is not the most obvious reason.
There are infinite ways to give away money, this scheme allows to align better with what causes other people are ready to support with their own money.
Computer files are very unintuitive concept for humans. That’s why iOS / ipadOS were trying so hard to get rid of files completely. Because any research shows that whatever your solution is - users don’t get it.
Professionals came up with their own ways navigating through that complexity.
Most people prefer the first solution there were introduced to. So people preferring Windows Explorer were using it before Finder and vice versa.
People also don’t spend time learning their tools - that’s why you see a lot of complains in this thread for things that are right in the menu, you don’t even need to read help or ask google, just open the damn menu. And this is HN - a forum for “power” users who spend immense time using their computers.
Try reducing thinking and use lighter models. For example I observed that using Sonnet works much better (compared to Opus) for tasks I want to be in control of architecture and just need a faster code input.
What does heavily encrypted even mean? Fully encrypted? Slightly encrypted? Encrypted enough to call it “heavily encrypted” but not enough to be protected from whoever is interested?
Heavily means the key is large so it takes longer to crack, but also longer to encrypt/decrypt, so the service is more costly to run and slower. At least I've seen it used that way
In this context "heavily" means "we can't legally claim it's end-to-end encrypted because it's not".
Also it's not even post quantum, so it's not heavy. Telegram's Diffie-Hellman breaks instantly with a quantum computer large enough to run Shor against it.
Also, the keys sit on the servers' RAM, no matter what they lie. There is no global distributed RAM system, especially one that encrypts data in distributed fashion and works at the negligible latencies that Telegram boasts.
I've never claimed that anything about telegram's encryption is "heavy", because I don't even know what they use, I just said what "heavy" usually means
> In this context
In this context it's marketing bs for people that only seen action movies where hackers quickly cracked encryption. I'm sure whatever telegram uses is not that ridiculously easy to crack
>telegram is the safest encrypted messaging app. Period, full stop.
Yes, let's see
* Not end-to-end encrypted by default
* No end-to-end encrypted groups
* No end-to-end encryption on any desktop client by the vendor, forcing cross-platform users to drop secret chats. This includes 81% of working age people who sit on their computer during work day, and 100% of college students and IT workers.
* Lacks ALL metadata protection from server like phone number, IP-address and thus geolocation, contact list, group memberships, quantity and schedule of communication, data types. In fact --
* Secret chats leak additional metadata about intent to hide content from TG as the vendor.
Telegram has nothing to do with Russia, other than having a Russian founder, and the Ukrainian military has literally relied upon it in the past, along with many Ukrainian civic services. You people are just racist towards Russians and need help.
Based on the analysis of packet captures above, I believe it is clear that anyone who has sufficient visibility into Telegram’s traffic would be able to identify and track traffic of specific user devices. Including when perfect forward secrecy protocol feature is in use.
This would also allow, through some additional analysis based on timing and packet sizes, to potentially identify who is communicating with whom using Telegram.
I love how the author of your honeypot blog post has nothing concrete other than potential attack vectors and is like "Well this is obviously a Russian honeypot" with no evidence what so ever other than a claim that there are plain text device identifiers, which is something the FSB would do. [insert clown emoji]. You can do similar attacks on signal and whatsapp.. Why is it that the Russian one bothers you so much?
>You people are just racist towards Russians and need help.
That doesn’t exclude the statements about Telegram to be correct though. That is, if some hater against whatever group say 1+1=2 or water is wet, what’s the conclusion?
>You can do similar attacks on signal and whatsapp.
Well yes. Don’t trust devices, they are not humans, they don’t qualify. They can at most have some degree of reliance for some purpose. But assuming that all devices out there are powned by some external parties is a rather sound security baseline approach.
>Why is it that the Russian one bothers you so much?
One don’t need to bother more on any specific oligarchy really, they all use their fellow humans like disposable pawns.
> You people are just racist towards Russians and need help.
>> That doesn’t exclude the statements about Telegram to be correct though.
just attack the telegram from the technical standpoint, then no complains about "racist towards russians" will be given. Like, mentioning the lack of user-friendly E2EE is great already. Saying things like "Durov who supposedly lives in exile has visited Russia over 50 times" is meh. How can one intepret it in any other way is "Russia is evil and visiting Russia is thus evil"?
>Durov who supposedly lives in exile has visited Russia over 50 times
Durov's exile marketing makes him look like he's Alexei Navalny. Navalny was a true dissident and critic and he was first poisoned, and then later arrested when he returned. He was was then imprisoned and he died in prison.
Durov has been visiting Russia more than I've been visiting my friends over the same period. Him returning to Russia that many times shows he isn't really living in exile. He's not on the run, and he's not getting arrested when he visits Russia. The disparity between the stories forces one to ask, is he working with the Russian government instead. He can prove he isn't by deploying ubiquitous end-to-end encryption, until then there's very little reason to suspect he isn't, again given the mismatch between what's claimed (the exile) and what's happening behind the scenes (the visits the public doesn't know about).
That article doesn't even mention the cracking contest. The XOR-nonce bug was also found by Valsorda in 2021 https://words.filippo.io/telegram-ecdh/ so looks like that 2013 post you linked to never even led to a fix during the EIGHT years. No idea if it still exists.
Also, you can't be racist towards Russian government that's OBVIOUSLY evil. From Navalny, to Bucha, to bombing hospitals, to kidnapping children, to the illegal war in the first place.
I've never had a twitter account so all these people hating durov for his exile marketing look weird to me. I'm not disagreeing with what you say but it's like a whole another subsection of world opened to me
I'm not going to speak for the author of that article. But I agree with his conclusion. Telegram is indistinguishable from a honeypot.
In the world of infosec, stuff isn't secure until someone proves you wrong (which you reject assuming racism). Stuff is secure when you prove it's secure.
Practically every major secure messaging app vendor has proven they can not be a honeypot, by end-to-end encrypting their communications, offering open source clients with public key fingerprints to verify that end-to-end encryption is working correctly.
Telegram hasn't done that. Telegram's lack of end-to-end encryption, paired with zero effort for metadata protection (not even stuff like sealed sender) shows they don't give a damn about actual security.
But what they do is also what an FSB op would do.
* It would advertise "heavily encrypted" and bash WhatsApp day after day convincing average Janes and Joes about it being really really secure, and confuse readers who take a closer look, with claims of all chats using MTProto but also calling both client-server and end-to-end encryption protocols MTProto.
* It would construct a narrative that the face of the app is a rebel dissident in exile.
* It would be banned temporarily or poorly
* It's role would be obfuscated by releasing an obviously backdoored app like Max, to make Telegram seem safe compared to it. Like Russian intelligence really believed they could use Max to monitor Russian dissidents. FSB isn't dumb. Russian military deception is world famous. https://en.wikipedia.org/wiki/Russian_military_deception
The backdoor sits in the fact nothing is end-to-end encrypted, groups can't be E2EE, but troll army can still defend it, claiming it does have 1:1 E2EE if you want. Yes, it does, if you really want the highest friction UX possible. People try and drop secret chats when they want to be able to alt-tab into the conversation instead of digging into their phones 100 times a day. This backdoor is ingenious because the users can only blame themselves when their 1:1 messages end up to the server.
A good messaging app creator knows this, so they make E2EE default so that users don't encounter such friction. E.g. Signal allows you to have E2EE 1:1 and group chats between all of your devices. That's what proper privacy by design looks like. Would Telegram do that, they would've proven they stand for their users, and I'd actually recommend them.
Data is a toxic asset. Even if Telegram isn't a honeypot, it's a massive data collecting apparatus, that has all that data sit on its servers, from which the hacking team of any major intelligence agency can access it en mass. That's the life of 1B users worldwide. So ultimately, it doesn't even matter if Telegram is a honeypot, it's equally usable to https://en.wikipedia.org/wiki/Fancy_Bear or NSA TAO or whoever.
This isn't about hating on Russians. This is about Durov not passing the minimum bar of what modern secure communication is about.
You've so far claimed telegram is the best with nothing to back that claim, ignored every counter argument, attacked argument of someone other than me, and you're now replaying Russian government shill tactics to try to rally people behind you for emotional reasons, when I'm explicitly giving technical critique.
It is interesting that both options of either not using CC entirely or using CC but paying it off by the end of the month are equivalent, but you’ve somehow reframe the second ine as some virtuous skill one have to master (I’m not just buying bread, I’m also managing my finances by repaying the value of it in full by the end of the month to avoid being charged for interest and simultaneously improving my credit score).
Business model of banks in regard to CC are preying on people not paying it all in full for various reasons.
Financially, they're not equivalent. If you buy your bread on credit, you get an interest-free loan, and benefit from the time value of the money that you otherwise would have paid immediately. As you correctly point out, this value comes from those fleeced by the arrangement. If my comment attributed any moral valence to the two options, that was unintentional.
That only works if you keep less money than your monthly spend in high interest accounts. I always have a cushion on the account linked to the card. The only benefit of credit in the US is rewards cards that transfer wealth from those with poor discipline and financial illiteracy.
NextCloud generally appears to use their own design system everywhere, Android apps are also not in Material or on iOS (iirc) in Cupertino. It makes for a subpar experience in general but is consistent.
I felt that she is much closer in values to the Facebook executives than she was trying to make it seem. Yes, she failed at her job because it was an impossible one, and she got no shares because she was too late to the party, but the bravery and carelessness she showed were absolutely mind-blowing, for my taste at least.
reply