▲ 253 ▼ Is Telegram really an encrypted messaging app? (blog.cryptographyengineering.com) submitted 2 years ago by db0@lemmy.dbzer0.com to c/technology@lemmy.world 118 comments fedilink hide all child comments
[+] umbrella@lemmy.ml 12 points 2 years ago* (last edited 1 year ago) (5 children) [deleted] permalink fedilink source parent hideshow 5 child comments replies: [–] pressanykeynow@lemmy.world -4 points 2 years ago (4 children) That's incorrect, their client is opensource, you can check their e2ee yourself. permalink fedilink source parent hideshow 4 child comments replies: [–] todd_bonzalez@lemm.ee -5 points 2 years ago (3 children) The encryption algorithm may be open source, but they rolled it themselves. It is proprietary encryption. permalink fedilink source parent hideshow 3 child comments replies: [–] pressanykeynow@lemmy.world 7 points 2 years ago (2 children) Again, it's not, go to their github, check the code of the client, compile it yourself, and make a reproducible build to check that the client they ship to your phone is the same. You are talking nonsense. permalink fedilink source parent hideshow 2 child comments replies: [–] skeezix@lemmy.world 6 points 2 years ago Todd is a known bullshitter permalink fedilink source parent [–] todd_bonzalez@lemm.ee -2 points 2 years ago* (last edited 2 years ago) You're not getting what I'm saying, because you don't understand what "proprietary" means in this context. Proprietary encryption ≠ Proprietary code. You can roll your own shitty novel encryption algorithm and license it under GPL if you want, it's still proprietary encryption in that Signal has its own unvetted encryption algorithm instead of using a trusted existing algorithm. EDIT: How are people not understanding this? Proprietary licensing is different from a proprietary way of doing things. If you folks think that a GitHub repo and GPL license are all you need to vet an encryption algorithm, and you think that absolves an novel untested algo from being called "proprietary encryption" you're gonna get burned one day because your trust was built on not understanding encryption. Signal built their own encryption algorithm. That's proprietary encryption. If you still think I'm wrong, pick up a dictionary, look up "proprietary" and "encryption", and you might just have a chance at understanding that "proprietary" is an adjective that can apply to a lot of different words. permalink fedilink source parent
[–] pressanykeynow@lemmy.world -4 points 2 years ago (4 children) That's incorrect, their client is opensource, you can check their e2ee yourself. permalink fedilink source parent hideshow 4 child comments replies: [–] todd_bonzalez@lemm.ee -5 points 2 years ago (3 children) The encryption algorithm may be open source, but they rolled it themselves. It is proprietary encryption. permalink fedilink source parent hideshow 3 child comments replies: [–] pressanykeynow@lemmy.world 7 points 2 years ago (2 children) Again, it's not, go to their github, check the code of the client, compile it yourself, and make a reproducible build to check that the client they ship to your phone is the same. You are talking nonsense. permalink fedilink source parent hideshow 2 child comments replies: [–] skeezix@lemmy.world 6 points 2 years ago Todd is a known bullshitter permalink fedilink source parent [–] todd_bonzalez@lemm.ee -2 points 2 years ago* (last edited 2 years ago) You're not getting what I'm saying, because you don't understand what "proprietary" means in this context. Proprietary encryption ≠ Proprietary code. You can roll your own shitty novel encryption algorithm and license it under GPL if you want, it's still proprietary encryption in that Signal has its own unvetted encryption algorithm instead of using a trusted existing algorithm. EDIT: How are people not understanding this? Proprietary licensing is different from a proprietary way of doing things. If you folks think that a GitHub repo and GPL license are all you need to vet an encryption algorithm, and you think that absolves an novel untested algo from being called "proprietary encryption" you're gonna get burned one day because your trust was built on not understanding encryption. Signal built their own encryption algorithm. That's proprietary encryption. If you still think I'm wrong, pick up a dictionary, look up "proprietary" and "encryption", and you might just have a chance at understanding that "proprietary" is an adjective that can apply to a lot of different words. permalink fedilink source parent
[–] todd_bonzalez@lemm.ee -5 points 2 years ago (3 children) The encryption algorithm may be open source, but they rolled it themselves. It is proprietary encryption. permalink fedilink source parent hideshow 3 child comments replies: [–] pressanykeynow@lemmy.world 7 points 2 years ago (2 children) Again, it's not, go to their github, check the code of the client, compile it yourself, and make a reproducible build to check that the client they ship to your phone is the same. You are talking nonsense. permalink fedilink source parent hideshow 2 child comments replies: [–] skeezix@lemmy.world 6 points 2 years ago Todd is a known bullshitter permalink fedilink source parent [–] todd_bonzalez@lemm.ee -2 points 2 years ago* (last edited 2 years ago) You're not getting what I'm saying, because you don't understand what "proprietary" means in this context. Proprietary encryption ≠ Proprietary code. You can roll your own shitty novel encryption algorithm and license it under GPL if you want, it's still proprietary encryption in that Signal has its own unvetted encryption algorithm instead of using a trusted existing algorithm. EDIT: How are people not understanding this? Proprietary licensing is different from a proprietary way of doing things. If you folks think that a GitHub repo and GPL license are all you need to vet an encryption algorithm, and you think that absolves an novel untested algo from being called "proprietary encryption" you're gonna get burned one day because your trust was built on not understanding encryption. Signal built their own encryption algorithm. That's proprietary encryption. If you still think I'm wrong, pick up a dictionary, look up "proprietary" and "encryption", and you might just have a chance at understanding that "proprietary" is an adjective that can apply to a lot of different words. permalink fedilink source parent
[–] pressanykeynow@lemmy.world 7 points 2 years ago (2 children) Again, it's not, go to their github, check the code of the client, compile it yourself, and make a reproducible build to check that the client they ship to your phone is the same. You are talking nonsense. permalink fedilink source parent hideshow 2 child comments replies: [–] skeezix@lemmy.world 6 points 2 years ago Todd is a known bullshitter permalink fedilink source parent [–] todd_bonzalez@lemm.ee -2 points 2 years ago* (last edited 2 years ago) You're not getting what I'm saying, because you don't understand what "proprietary" means in this context. Proprietary encryption ≠ Proprietary code. You can roll your own shitty novel encryption algorithm and license it under GPL if you want, it's still proprietary encryption in that Signal has its own unvetted encryption algorithm instead of using a trusted existing algorithm. EDIT: How are people not understanding this? Proprietary licensing is different from a proprietary way of doing things. If you folks think that a GitHub repo and GPL license are all you need to vet an encryption algorithm, and you think that absolves an novel untested algo from being called "proprietary encryption" you're gonna get burned one day because your trust was built on not understanding encryption. Signal built their own encryption algorithm. That's proprietary encryption. If you still think I'm wrong, pick up a dictionary, look up "proprietary" and "encryption", and you might just have a chance at understanding that "proprietary" is an adjective that can apply to a lot of different words. permalink fedilink source parent
[–] skeezix@lemmy.world 6 points 2 years ago Todd is a known bullshitter permalink fedilink source parent
[–] todd_bonzalez@lemm.ee -2 points 2 years ago* (last edited 2 years ago) You're not getting what I'm saying, because you don't understand what "proprietary" means in this context. Proprietary encryption ≠ Proprietary code. You can roll your own shitty novel encryption algorithm and license it under GPL if you want, it's still proprietary encryption in that Signal has its own unvetted encryption algorithm instead of using a trusted existing algorithm. EDIT: How are people not understanding this? Proprietary licensing is different from a proprietary way of doing things. If you folks think that a GitHub repo and GPL license are all you need to vet an encryption algorithm, and you think that absolves an novel untested algo from being called "proprietary encryption" you're gonna get burned one day because your trust was built on not understanding encryption. Signal built their own encryption algorithm. That's proprietary encryption. If you still think I'm wrong, pick up a dictionary, look up "proprietary" and "encryption", and you might just have a chance at understanding that "proprietary" is an adjective that can apply to a lot of different words. permalink fedilink source parent