Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Privacy
  3. Telegram is indistinguishable from an FSB honeypot

Telegram is indistinguishable from an FSB honeypot

Scheduled Pinned Locked Moved Privacy
privacy
17 Posts 5 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • andromxda@lemmy.dbzer0.comA This user is from outside of this forum
    andromxda@lemmy.dbzer0.comA This user is from outside of this forum
    [email protected]
    wrote last edited by
    #1
    This post did not contain any content.
    J C C H 4 Replies Last reply
    47
    • andromxda@lemmy.dbzer0.comA [email protected]
      This post did not contain any content.
      J This user is from outside of this forum
      J This user is from outside of this forum
      [email protected]
      wrote last edited by
      #2

      What jurisdiction does the FSB have over you? None, and it has zero interest in helping those that do. This is the rationale for not worrying about backend security on Telegram. Transport security is a another question.

      1 Reply Last reply
      6
      • andromxda@lemmy.dbzer0.comA [email protected]
        This post did not contain any content.
        C This user is from outside of this forum
        C This user is from outside of this forum
        [email protected]
        wrote last edited by
        #3

        The two decisions Telegram made (choice of infrastructure provider who happens to cooperate with the Russian FSB, and attaching a cleartext device identifier to encrypted messages) taken together reinforce surveillance capability of the FSB considerably more strongly than either of these decisions would have on its own.

        1 Reply Last reply
        2
        • andromxda@lemmy.dbzer0.comA [email protected]
          This post did not contain any content.
          C This user is from outside of this forum
          C This user is from outside of this forum
          [email protected]
          wrote last edited by
          #4

          For every smart educate person it is obvious that Telegram is honeypot created by Russian-Dubai oligarch

          1 Reply Last reply
          3
          • andromxda@lemmy.dbzer0.comA [email protected]
            This post did not contain any content.
            H This user is from outside of this forum
            H This user is from outside of this forum
            [email protected]
            wrote last edited by [email protected]
            #5

            Telegram is very successful in getting people off Meta's ecosystem. It has open source clients and very good Linux support.

            This is why western media is obsessed with Telegram and spend a lot of time smearing it.

            andromxda@lemmy.dbzer0.comA 1 Reply Last reply
            3
            • H [email protected]

              Telegram is very successful in getting people off Meta's ecosystem. It has open source clients and very good Linux support.

              This is why western media is obsessed with Telegram and spend a lot of time smearing it.

              andromxda@lemmy.dbzer0.comA This user is from outside of this forum
              andromxda@lemmy.dbzer0.comA This user is from outside of this forum
              [email protected]
              wrote last edited by
              #6

              Telegram literally stores all your messages, metadata, etc. in plain text on their servers. This means that it provides considerably worse security than even proprietary messengers, such as WhatsApp and Facebook Messenger. Telegram has an option for encrypted chats, but it's not available for groups, lacks support for voice and video calls, and Telegram deliberately goes out of their way to make the experience of using encrypted chats as painful as possible.

              You're even better off using WhatsApp, but if you actually want a good messenger, switch to Signal. It's free and open source (both the clients and the backend server), developed by a nonprofit organization, and it's basically the gold standard for encrypted communications.

              H 1 Reply Last reply
              1
              • andromxda@lemmy.dbzer0.comA [email protected]

                Telegram literally stores all your messages, metadata, etc. in plain text on their servers. This means that it provides considerably worse security than even proprietary messengers, such as WhatsApp and Facebook Messenger. Telegram has an option for encrypted chats, but it's not available for groups, lacks support for voice and video calls, and Telegram deliberately goes out of their way to make the experience of using encrypted chats as painful as possible.

                You're even better off using WhatsApp, but if you actually want a good messenger, switch to Signal. It's free and open source (both the clients and the backend server), developed by a nonprofit organization, and it's basically the gold standard for encrypted communications.

                H This user is from outside of this forum
                H This user is from outside of this forum
                [email protected]
                wrote last edited by
                #7

                nothing you say will make me use a closed source app like whatsapp.

                andromxda@lemmy.dbzer0.comA 1 Reply Last reply
                0
                • H [email protected]

                  nothing you say will make me use a closed source app like whatsapp.

                  andromxda@lemmy.dbzer0.comA This user is from outside of this forum
                  andromxda@lemmy.dbzer0.comA This user is from outside of this forum
                  [email protected]
                  wrote last edited by
                  #8

                  Literally no one here is advocating for the use of WhatsApp. Stop making up straw man arguments.

                  H 1 Reply Last reply
                  1
                  • andromxda@lemmy.dbzer0.comA [email protected]

                    Literally no one here is advocating for the use of WhatsApp. Stop making up straw man arguments.

                    H This user is from outside of this forum
                    H This user is from outside of this forum
                    [email protected]
                    wrote last edited by
                    #9

                    Just above you said "You’re even better off using WhatsApp".

                    I will use Signal if Signal devs get over their hate of F-Droid.

                    andromxda@lemmy.dbzer0.comA 1 Reply Last reply
                    0
                    • H [email protected]

                      Just above you said "You’re even better off using WhatsApp".

                      I will use Signal if Signal devs get over their hate of F-Droid.

                      andromxda@lemmy.dbzer0.comA This user is from outside of this forum
                      andromxda@lemmy.dbzer0.comA This user is from outside of this forum
                      [email protected]
                      wrote last edited by
                      #10

                      You're better off using WhatsApp compared to Telegram, but that's a very low bar, and it absolutely doesn't mean that anyone should use WhatsApp.
                      Signal, Threema, Wire and SimpleX are far better options. I prefer Signal, because it's very easy to use, the UI/UX is basically the exact same as on WhatsApp. It's also free, unlike Threema, and uses either phone numbers or user names as identifiers, unlike SimpleX, which requires you to share a QR code.
                      Signal is also the most popular of these messengers, so there's a larger chance that someone is already using it.

                      As for F-Droid: It's not a good way of distributing such privacy/security-relevant apps like Signal. F-Droid doesn't have certificate checks built in, thus the APK could easily be modified without the user ever noticing. Again, I don't like Google, but you're better off downloading Signal from the Play Store.
                      The best option is to use Obtainium and automatically fetch the latest version of the Signal APK directly from their website https://signal.org/android/apk/
                      That way, you're at least getting the app from an official source, built and signed by the Signal developers, not a random third party.

                      You can use AppVerifier to verify the integrity of the downloaded app aginast the certificate fingerprint on the website.

                      H 1 Reply Last reply
                      0
                      • andromxda@lemmy.dbzer0.comA [email protected]

                        You're better off using WhatsApp compared to Telegram, but that's a very low bar, and it absolutely doesn't mean that anyone should use WhatsApp.
                        Signal, Threema, Wire and SimpleX are far better options. I prefer Signal, because it's very easy to use, the UI/UX is basically the exact same as on WhatsApp. It's also free, unlike Threema, and uses either phone numbers or user names as identifiers, unlike SimpleX, which requires you to share a QR code.
                        Signal is also the most popular of these messengers, so there's a larger chance that someone is already using it.

                        As for F-Droid: It's not a good way of distributing such privacy/security-relevant apps like Signal. F-Droid doesn't have certificate checks built in, thus the APK could easily be modified without the user ever noticing. Again, I don't like Google, but you're better off downloading Signal from the Play Store.
                        The best option is to use Obtainium and automatically fetch the latest version of the Signal APK directly from their website https://signal.org/android/apk/
                        That way, you're at least getting the app from an official source, built and signed by the Signal developers, not a random third party.

                        You can use AppVerifier to verify the integrity of the downloaded app aginast the certificate fingerprint on the website.

                        H This user is from outside of this forum
                        H This user is from outside of this forum
                        [email protected]
                        wrote last edited by
                        #11

                        I don't trust an app that tells me to download from Google Play. Sorry, not going to happen. Signal has too many red flags.

                        andromxda@lemmy.dbzer0.comA 1 Reply Last reply
                        0
                        • H [email protected]

                          I don't trust an app that tells me to download from Google Play. Sorry, not going to happen. Signal has too many red flags.

                          andromxda@lemmy.dbzer0.comA This user is from outside of this forum
                          andromxda@lemmy.dbzer0.comA This user is from outside of this forum
                          [email protected]
                          wrote last edited by
                          #12

                          I don't trust an app that tells me to download from Google Play.

                          So almost any Android app in existence?

                          H 1 Reply Last reply
                          0
                          • andromxda@lemmy.dbzer0.comA [email protected]

                            I don't trust an app that tells me to download from Google Play.

                            So almost any Android app in existence?

                            H This user is from outside of this forum
                            H This user is from outside of this forum
                            [email protected]
                            wrote last edited by
                            #13

                            No, but an app like Signal claiming to care about privacy should at least make an effort to be on the largest open source appstore. The fact they don't, despite very loud complaints from the community, makes me question their commitment to privacy and security.

                            andromxda@lemmy.dbzer0.comA 1 Reply Last reply
                            0
                            • H [email protected]

                              No, but an app like Signal claiming to care about privacy should at least make an effort to be on the largest open source appstore. The fact they don't, despite very loud complaints from the community, makes me question their commitment to privacy and security.

                              andromxda@lemmy.dbzer0.comA This user is from outside of this forum
                              andromxda@lemmy.dbzer0.comA This user is from outside of this forum
                              [email protected]
                              wrote last edited by
                              #14

                              Again, I just explained to you that the "largest open source app store" is an insecure mess and isn't suited for apps like Signal. You don't need to use Google Play, you can find the APK on GitHub, or the Signal website, together with the certificate fingerprint.

                              makes me question their commitment to privacy and security.

                              That doesn't make sense. F-Droid neither secure nor trustworthy. Signal not being on F-Droid is a good security choice. I recommend reading through this thread.

                              H 1 Reply Last reply
                              0
                              • andromxda@lemmy.dbzer0.comA [email protected]

                                Again, I just explained to you that the "largest open source app store" is an insecure mess and isn't suited for apps like Signal. You don't need to use Google Play, you can find the APK on GitHub, or the Signal website, together with the certificate fingerprint.

                                makes me question their commitment to privacy and security.

                                That doesn't make sense. F-Droid neither secure nor trustworthy. Signal not being on F-Droid is a good security choice. I recommend reading through this thread.

                                H This user is from outside of this forum
                                H This user is from outside of this forum
                                [email protected]
                                wrote last edited by
                                #15

                                Signal devs accuse f-droid for not being secure, but do not offer any convincing arguments to back it up. Just saying it doesn't make it so.

                                F-Droid works. I have 20+ apps installed on my phone from F-Droid. I am not going to go back to installing apks from website or Google Play just so that I can use Signal.

                                andromxda@lemmy.dbzer0.comA 1 Reply Last reply
                                0
                                • H [email protected]

                                  Signal devs accuse f-droid for not being secure, but do not offer any convincing arguments to back it up. Just saying it doesn't make it so.

                                  F-Droid works. I have 20+ apps installed on my phone from F-Droid. I am not going to go back to installing apks from website or Google Play just so that I can use Signal.

                                  andromxda@lemmy.dbzer0.comA This user is from outside of this forum
                                  andromxda@lemmy.dbzer0.comA This user is from outside of this forum
                                  [email protected]
                                  wrote last edited by
                                  #16

                                  I linked you to a whole page of evidence, explaining the significant security issues in F-Droid before.

                                  Here's that link again: https://privsec.dev/posts/android/f-droid-security-issues/

                                  Just read it

                                  H 1 Reply Last reply
                                  0
                                  • andromxda@lemmy.dbzer0.comA [email protected]

                                    I linked you to a whole page of evidence, explaining the significant security issues in F-Droid before.

                                    Here's that link again: https://privsec.dev/posts/android/f-droid-security-issues/

                                    Just read it

                                    H This user is from outside of this forum
                                    H This user is from outside of this forum
                                    [email protected]
                                    wrote last edited by
                                    #17

                                    I read that article and had a good laugh about it. It is nonsensical. It does raise good points occasionally, but that is drowned by nonsense.

                                    1 Reply Last reply
                                    0
                                    Reply
                                    • Reply as topic
                                    Log in to reply
                                    • Oldest to Newest
                                    • Newest to Oldest
                                    • Most Votes


                                    • Login

                                    • Login or register to search.
                                    • First post
                                      Last post
                                    0
                                    • Categories
                                    • Recent
                                    • Tags
                                    • Popular
                                    • World
                                    • Users
                                    • Groups