this post was submitted on 23 Dec 2024
119 points (91.6% liked)

Technology

71502 readers
4320 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] demesisx@infosec.pub 40 points 5 months ago (4 children)

“Trust me bro” style hand-rolled encryption.

[–] pgetsos@fedia.io 9 points 5 months ago (1 children)

The encryption is not Trust me bro. It is public and tested multiple times. For example an analysis back in 2021:

https://mtpsym.github.io/

It found somes issues in the implementation of MTProto 2.0 from the official apps, with only one of them being actually usable as an attack vector, and they were all fixed before the disclosure of the analysis. They found no issues with the encryption algorithm other than some choices that may make the implementation of it harder

[–] rikudou@lemmings.world 12 points 5 months ago (1 children)

The encryption that only works in one-on-one chats? The encryption that's multiple menus deep in said one-on-one chats? The encryption that no one uses because of the issues above?

[–] ouch@lemmy.world 7 points 5 months ago (1 children)

What encryption? There is no E2EE by default. It's all plaintext.

[–] oktoberpaard 1 points 5 months ago

I’ve been telling people about the lack of standard E2E encryption for years, so don’t interpret this as me defending them, but plaintext suggests that they send it unencrypted over the network, which is not the case. It’s encrypted between the client and the server and supposedly it’s also encrypted at rest. The issue is that Telegram has full access to your data, as well as anyone that they share it with (or that has managed to find their way in). This may include government agencies, employees, etc.

[–] lepinkainen@lemmy.world 0 points 5 months ago

I exclusively use it for public chats, like I did IRC.

Neither had any encryption and I have no issue with it.