Advertisement
sxiii

Is Telegram Secure? Or Signal? Or Tox? What is the best?

Nov 26th, 2015
2,866
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.96 KB | None | 0 0
  1. A small article on security-related questions about private messaging. Can be used as a security cheatsheet in some way.
  2. Will suite everybody: including those who know what computer security is, and those who don't.
  3. Written by SXIII / November 2015
  4.  
  5. Part 1. Is Telegram really secure?
  6. Answers are in the following (googled) results - sorted by importance:
  7. + http://unhandledexpression.com/2013/12/17/telegram-stand-back-we-know-maths/
  8. + https://www.incibe.es/extfrontinteco/img/File/intecocert/EstudiosInformes/INT_Telegram_EN.pdf
  9. + https://gigaom.com/2015/01/12/researchers-slam-telegram-apps-visual-fingerprint-security/
  10. + https://www.quora.com/Which-encrypted-mobile-messaging-app-is-most-secure-Telegram-or-Signal-by-Open-Whisper-Systems
  11. + http://www.infosecurity-magazine.com/news/telegrams-encrypted-mobile-chats/
  12. + http://thehackernews.com/2015/11/telegram-security-privacy.html
  13. + https://gigaom.com/2014/03/25/telegram-now-has-35m-users-but-can-it-be-trusted/
  14. + http://www.pcworld.com/article/2871412/how-much-trust-can-you-put-in-telegram-messenger.html
  15. Result: no, telegram is not so secure. It's better than nothing tho.
  16.  
  17. Part 2. If telegram is insecure, what next?
  18. Answer: Signal by Open Whisper Systems.
  19.  
  20. Part 3. Is Signal totally secure? Is it more secure than Telegram?
  21. Answer: No, Signal is not totally secure. Yes, it's more secure then telegram.
  22. Appendix: It's not safe to transfer something via SMS/MMS/GSM channels, which are mostly unencrypted (they ARE encrypted but everybody know these protocols now).
  23.  
  24. Part 4. What is even more secure then Signal?
  25. Answer: To be even more secure you have to remove the "registration" or "identification" step. This can be done by using of another opensource piece of software which called Tox.
  26. Related link: https://tox.chat/
  27.  
  28. Part 5. Is Tox totally secure?
  29. Answer: No. Nothing is secure if you don't follow some security guidelines.
  30.  
  31. Part 6. What is more secure then Tox?
  32. Answer: Using PGP encryption for your written messages or files which are then sent through Tox. This should also include HTTPS everywhere and probably a trusted VPN or own-hosted VPN on anonymous hosting is a good idea.
  33.  
  34. Part 7. What is even more secure than that?
  35. Answer: Along with all stuff from part 6, plus adding some own-written goodness crypto-tools in steps of your choice. If nobody except you and the receiver will know your cypher then it could take additional time to explore and break your cypher. You'd better read some security articles on writing correct modern cyphers but also you might try to connect your own imagination. You know, it's opensource software, you can always just add a few lines of code and re-compile the software, and here you are: your own homebrewed additionally-secured chat is ready!
  36.  
  37. Part 8. What is most secure thing in the world?
  38. Answer: Just Don't Tell Anybody (C).
  39.  
  40. Additional link:
  41. EFF (Electronic Frontier Foundation) Secure Messangers Scorecard
  42. https://www.eff.org/secure-messaging-scorecard
  43.  
  44. Good luck!
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement