[Replicant] Using signal/textsecure

Aaron Whitehouse lists at whitehouse.kiwi.nz
Sun Nov 8 10:51:47 UTC 2015


Hi Nico,

On 05/11/15 14:12, Laura Arjona Reina wrote:
> On 5 de noviembre de 2015 10:50:57 GMT+01:00, Nico CARTRON <nicolas at ncartron.org> wrote:
>>
>>> No, that's a different program. I want Signal/TextSecure 
>>> specifically not least because it is very widely trusted and used.
>> How about Telegram?
>>
>

I currently use both Telegram and Signal/TextSecure. I prefer them on a
mobile to XMPP-based options, as relying on push messaging seems to make
for more reliable message delivery (and I assume battery life, though I
haven't tested it).

There are lots of pages out there on Telegram vs TextSecure. There are
also a lot of discussions about the underlying technology and security
systems, but I don't pretend to be enough of a security expert to argue
those, though my sense is that Signal's is preferable.

The key differences from my perspective are that Telegram incorporates
user-friendly features faster (e.g. a web client, multi-device), but
Signal only does so when it can make sure they are always secure. I
understand that, at least when I last read about it, group chats were
encrypted on Signal, but could not be on Telegram. Similarly, Telegram
is no more secure than things like Hangouts by default (and
substantially less secure than WhatsApp, now that WhatsApp had Moxie
implement TextSecure-like encryption into it:
https://whispersystems.org/blog/whatsapp/ )--you have to do a "Secret
Chat" to get encryption, and then I believe you lose some of the
multi-device features. Signal has no insecure modes. There are also some
user-desired features that Signal does not appear to intend to
implement, presumably on an idealogical basis, such as read receipts
(https://github.com/WhisperSystems/Signal-Android/issues/2667) and
self-destructing messages
(https://github.com/WhisperSystems/Signal-Android/issues/900), whereas
Telegram has already implemented these. I believe that Telegram also has
substantially more users, so you are more likely to actually be able to
speak to random contacts on it.

For what it's worth, where I have any sway over the other side of the
conversation, I encourage Signal. If I were actually discussing anything
that I needed to be secret, I would insist on Signal.

Hope that helps,

Aaron

 


More information about the Replicant mailing list