logoalt Hacker News

erelong • today at 4:49 AM • 4 replies • view on HN

I thought telegram was flagged as insecure like a decade ago, it's never really been "very secure"

Like any number of articles like this: https://hackernoon.com/7-reason-why-telegram-is-insecure-by-...


Replies

misiek08 • today at 6:42 AM

Still we are using it, because UX kills any other app and people that are (probably) behind it will cause almost no harm to casual, not-interesting people :)

And yes, I know that by default chats are not E2E, that phone number has way too many effects on accounts etc. Still, UX and agencies interested in important people are more welcome than data selling, ad-based companies.

➕ show 2 replies
g-b-r • today at 4:52 AM

Absolutely, but mostly for their protocols, statements, people and infrastructure.

A file exfiltration vulnerability is still noteworthy.

TZubiri • today at 7:12 AM

It has this feature where it tells you about other users that are on the platform. I mean it's not a huge leak, but right off the bat it's pretty poor security posture. For an app that competes with other chat apps on supposedly being more secure and privacy aware, it does worse than whatsapp on that end.

phoronixrly • today at 5:54 AM

Here's one from Filippo

The Most Backdoor-Looking Bug I’ve Ever Seen - https://words.filippo.io/telegram-ecdh/