Top
Best
New

Posted by e_daigle 23 hours ago

“Super secure” messaging app leaks everyone's phone number(ericdaigle.ca)
581 points | 277 commentspage 2
higginsniggins 21 hours ago|
When you go the website the first line is literally “Say hello to Freedom Chat—a next-generation messaging app that keeps your conversations actually private
Bengalilol 20 hours ago|
... and then you encounter things like "Privacy’s been lost. We’re here to take it back." or "World-class security".

It looks like "Freedom" is a sure thing.

nielsbot 18 hours ago||
> Neither of us had prior experience developing mobile apps, but we thought, “Hey, we’re both smart. This shouldn’t be too difficult.”

Is this an actual quote? Because it sounds like a standup joke.

Havoc 22 hours ago||
When something is "super secure" you know it's full of holes. It's right up there with "impossible to hack" and "military grade" aka lowest cost bidder.
lesuorac 21 hours ago||
And "complies with all applicable laws"; as-in we're operating at the lowest possible standard we can.
maqp 20 hours ago|||
Yup. As the guy who put together the most secure FOSS messaging system*, it's not "impossible to hack". It's a caveat ridden, inconvenient to use, tedious to setup, hardware-isolated, multinode application, with long must-read documentation, and that requires experience with electronics and soldering.

* github.com/maqp/tfc

hamdingers 21 hours ago|||
Unsinkable
shreddit 20 hours ago||
At least the Hindenburg was iceberg proof

https://xkcd.com/2350/

hbarka 22 hours ago||
“We’re clear on OpSec.”
jakeydus 22 hours ago||
Obligatory Colin Jost Pete Hegseth warrior ethos post: https://www.youtube.com/watch?v=vZb1WO1_lGI
LordGrey 22 hours ago||
> Screenshots aren’t really crucial to anything being discussed here, but I like to provide only the best blog posts to my tens of readers ....

A sentence clipped from a point a little past the introduction, but catchy nevertheless.

I suspect there will be more than "tens of readers" shortly.

fn-mote 14 hours ago||
I’m glad “super secure” is in scare quotes.

I’m glad I have never heard of this app.

Security and trust go hand in hand.

netfortius 21 hours ago||
Why in the world would any sane person utilize such an app, knowing what kind of people will be "at the other end" of communication, and what topics would be discussed, even if the most secure piece of software ever developed?
the_gipsy 19 hours ago|
The president of the USA is on the equivalent alternative to Twitter.
kevin061 21 hours ago||
Why would you use a messaging platform that requires you to sign up with a very difficult to change piece of information that in many countries is tied to your ID and pretend it is secure?

looks at Signal

Oh.

TZubiri 21 hours ago|
You can register on telegram without using your phone number as an account identifier.
maqp 19 hours ago||
Yeah if you buy a number with Durov's TON shitcoin. The original sales are over and number auctions start from opening bid of 37 dollars, and run all the way to 14,000 USD https://fragment.com/numbers, and they take very long, even up to one year to close.

Also, Telegram is not private.

1. It's not E2EE by default

2. It's not E2EE for groups on any platfrom

3. It's not E2EE 1:1 on desktop clients forcing you to downgrade from secret chats to insecure chats

4. It's collecting 100% of your metadata, including

* who you talk to, when, how much, what type of data you exchange,

* your IP-address which sort of defeats the purpose of having no phone number, and

* when you enable secret chats

Telegram is also not transparent about its funding, about who develops it, and who has access to the plaintexts stored on their server (meaning, anyone with a zero day or two).

Journalists who went to look for Telegram's office in Dubay found out no-one in the neighboring office had ever seen Telegram staff enter the space https://www.youtube.com/watch?v=Pg8mWJUM7x4

Telegram was built with blood-money from VKontakte, and Durov has been marketed as living in exile, when in reality he has visited Russia on average once every 2.4 months since the exile began, and strangely Durov has not had his underwear poisoned and windows have been kind to him despite supposedly betraying Putin's interests.

tl;dr Telegram reeks of FSB/SVR honeypot.

r721 3 hours ago|||
>Durov's TON shitcoin

>Telegram reeks of FSB/SVR honeypot

Btw interesting connection between Durov/TON and Jan Marsalek (alleged Russian spy) was recently uncovered by FT:

>In 2018 Marsalek invited Ben Halim and other backers of the Libya projects to invest in a new crypto token being launched by messaging platform Telegram, whose founder Pavel Durov had met Marsalek and invited him to participate.

>A special purpose vehicle was set up for them to pool their money and invest but Credit Suisse, which was organising the sale of the token, blocked the transaction. It turned out the bank was happy to take money from Marsalek, whose role in the biggest corporate fraud in recent European history had yet to be revealed, but was wary of his Libyan friends.

>As a workaround, Ben Halim and others decided to let Marsalek invest their money in his name, sidestepping Credit Suisse’s money laundering checks. However, the US Securities and Exchange Commission blocked Telegram’s issuance of the tokens and Marsalek refunded his Libyan associates.

https://archive.fo/7evmm

baobun 18 hours ago||||
> Yeah if you buy a number with Durov's TON shitcoin

Not even. If you actually try you will discover at the last step (after full KYC, signing some dubious agreements, and linking an existing TG account) that the Fragment "market" is actually fully centralized and has not been open for new buyers-users for a good while. No secondary markets out there (maybe not even possible on their network) afaik.

maqp 16 hours ago||
That's... all sorts of funny and sad to hear.
eviks 12 hours ago||||
And the authorities are blocking it to protect people from falling into the honeypot, right?
kevin061 19 hours ago||||
Anyone using Telegram and expecting it to be a secure messenger is delusional.
TZubiri 10 hours ago|||
I mean as in the number is not tied to the identity, maybe you are asked your number to verify the account, but after that you can have a non number linked account. The account is tied to a username @blablabla.

I think Telegram is filth as much as the next guy, but I'm just making that technical point.

nunez 19 hours ago||
Wow; that's a 101-level exploit.
TZubiri 21 hours ago|
For every conscientious hacker that tries to do everything right and have a secure and reliable app. There's ten naïve hackers that just publish whatever.
More comments...