GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Paul Cantrell (inthehands@hachyderm.io)'s status on Tuesday, 14-May-2024 11:47:37 JST Paul Cantrell Paul Cantrell

    So…there is a concerted campaign, with Musk as its mouthpiece, to discredit Signal and get people to switch to Telegram. It’s disinformation, but there’s also useful information in it. The useful information is that a hideous, powerful, right-wing crank — or whoever’s yanking his chain — really, really wants people use Telegram.

    We’ve long known Telegram’s security is weak. But now, in light of this new information, we should move forward assuming that Telegram is actively compromised.

    In conversation about a year ago from hachyderm.io permalink
    • clacke likes this.
    • Aral Balkan, BeAware and carl marks repeated this.
    • Embed this notice
      Paul Cantrell (inthehands@hachyderm.io)'s status on Tuesday, 14-May-2024 12:53:41 JST Paul Cantrell Paul Cantrell
      in reply to

      Lest it get lost in that longer post:

      Assume Telegram is compromised. Not just vulnerable. Compromised.

      In conversation about a year ago permalink
      clacke likes this.
    • Embed this notice
      Aral Balkan (aral@mastodon.ar.al)'s status on Tuesday, 14-May-2024 17:37:57 JST Aral Balkan Aral Balkan
      in reply to

      @inthehands Always have. This is just further validation.

      In conversation about a year ago permalink
    • Embed this notice
      pettter (pettter@mastodon.acc.umu.se)'s status on Tuesday, 14-May-2024 17:44:12 JST pettter pettter
      in reply to

      @inthehands I'd assume the same of Signal, to be honest. You're not safe and secure against a nation-state actor, especially not running software from that country communicating through servers run in that country.

      The question is if you're worth them exposing that operation (you're probably not).

      In conversation about a year ago permalink
    • Embed this notice
      Paul Cantrell (inthehands@hachyderm.io)'s status on Tuesday, 14-May-2024 22:28:18 JST Paul Cantrell Paul Cantrell
      in reply to
      • NeoAtlantis

      @neoatlantis
      No. It’s bad tech, including the guts.

      In conversation about a year ago permalink
    • Embed this notice
      NeoAtlantis (neoatlantis@nerv.agency)'s status on Tuesday, 14-May-2024 22:28:26 JST NeoAtlantis NeoAtlantis
      in reply to

      @inthehands@hachyderm.io Can we just do an open source Telegram server that has all the features the official ones have, and modify the clients a bit to allow self hosted servers? Cause telegram still has some good user experience.

      In conversation about a year ago permalink
    • Embed this notice
      pettter (pettter@mastodon.acc.umu.se)'s status on Tuesday, 14-May-2024 22:55:01 JST pettter pettter
      in reply to
      • Johannes Hentschel

      @johentsch All efforts help, certainly. @inthehands

      In conversation about a year ago permalink
    • Embed this notice
      Johannes Hentschel (johentsch@hostux.social)'s status on Tuesday, 14-May-2024 22:55:02 JST Johannes Hentschel Johannes Hentschel
      in reply to
      • pettter

      @pettter
      But it still makes a huge difference that Signal isn't storing messages on their servers, doesn't it?
      @inthehands

      In conversation about a year ago permalink
    • Embed this notice
      Paul Cantrell (inthehands@hachyderm.io)'s status on Wednesday, 15-May-2024 00:32:14 JST Paul Cantrell Paul Cantrell
      in reply to

      Muting this conversation, which has an •unusually• low signal to noise ratio.

      Addressing some greatest hits:

      - “I just use telegram for [some BS]” → It’s probably still leaking your location

      - “Yeah, but if you’re targeted by a state actor…” → Honey, if a state actor is targeting •you• individually, technology is not even the first problem on your list. Opsec is hard.

      - “I already knew that” → Good for you, we’re trying to reach people who didn’t

      In conversation about a year ago permalink
    • Embed this notice
      TJ Olsen (tjolsen@mas.to)'s status on Wednesday, 15-May-2024 00:34:38 JST TJ Olsen TJ Olsen
      in reply to

      @inthehands I literally heard the fraze "right wing social media site Signal" on a podcast yesterday.

      In conversation about a year ago permalink
    • Embed this notice
      Paul Cantrell (inthehands@hachyderm.io)'s status on Wednesday, 15-May-2024 00:34:38 JST Paul Cantrell Paul Cantrell
      in reply to
      • TJ Olsen

      @tjolsen Then you need to stop listening to that podcast; at best it’s comically ignorant, and at worst it’s disinformation

      In conversation about a year ago permalink
    • Embed this notice
      Paul Cantrell (inthehands@hachyderm.io)'s status on Wednesday, 15-May-2024 00:35:55 JST Paul Cantrell Paul Cantrell
      in reply to

      More greatest hits:

      - “I want to learn more. Do you have links?” → Sure! Here’s a good post: https://kolektiva.social/@Voline/112437280384669007

      - “No tech is perfectly secure, therefore it doesn’t matter what you use” → This logic is exactly as stupid as “any car can crash, therefore it doesn’t matter if you wear a seatbelt”

      - “Let’s argue about [tech A] vs [tech B]” → Find a forum, you two

      - “But I heard X invested in alternative Y and [conspiracy theory]” → This is why we like open source comm apps, to vet security

      In conversation about a year ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Voline (@Voline@kolektiva.social)
        from Voline
        @thegibson@hackers.town @Mer__edith@mastodon.world @inthehands@hachyderm.io Did someone say “Telegram”? [Crashes into the thread like the Kool-Aid man] Please do not use #Telegram Messenger for any message that you would not want to see on the side of a building. Don't take my word for it, listen to these folks. Here's Dan Goodin (@dangoodin@infosec.exchange) in Ars Technica summarizing an exploit discovered by Ahmed Hassan: "Using readily available software and a rooted Android device, he’s able to spoof the location his device reports to Telegram servers. By using just three different locations and measuring the corresponding distance reported by People Nearby, he is able to pinpoint a user’s precise location." https://arstechnica.com/information-technology/2021/01/telegram-feature-exposes-your-precise-address-to-hackers/ Independent security researcher The Grugq (@thegrugq@infosec.exchange) on Telegram's many problems: "In summary, Telegram is error prone, has wonky homebrew encryption, leaks voluminous metadata, steals the address book, and is now known as a terrorist hangout. I couldn’t possibly think of a worse combination for a safe messenger." https://grugq.tumblr.com/post/133453305233/operational-telegram Former maintainer of the Golang cryptographic libraries Filippo Valsorda (@filippo@abyssdomain.expert) on a bug in Telegram's cryptographic protocol: "To this day, itʼs the most backdoor-looking bug Iʼve ever seen." https://buttondown.email/cryptography-dispatches/archive/cryptography-dispatches-the-most-backdoor-looking/ Prof of cryptography Matthew Green (@matthew_d_green@ioc.exchange) on Telegram's custom encryption: "Like seriously. Wtf is even going on here." https://twitter.com/matthew_d_green/status/582249709286326272 And finally, Bruce Schneier: "Don't Use Telegram." https://www.schneier.com/blog/archives/2016/06/comparing_messa.html If you want to communicate confidentially, use @signalapp@mastodon.world https://theintercept.com/2016/06/22/battle-of-the-secure-messaging-apps-how-signal-beats-whatsapp/
    • Embed this notice
      Paul Cantrell (inthehands@hachyderm.io)'s status on Wednesday, 15-May-2024 00:37:29 JST Paul Cantrell Paul Cantrell
      in reply to

      Last but not least:

      - “[Elaborate chain of logic I made up where I put 2 and 2 together and come up with 22]” → Disinformation is still disinformation even if you invented it yourself. At some point, you’re going to have to trust someone who knows more than you; puzzling it out yourself from a point of inexpertise is not better.

      In conversation about a year ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.