HN user

exo762

520 karma
Posts7
Comments461
View on HN

I still don't see how you can keep something anonymous and still rate limit it.

Constructions like this exist for many years. E.g. semaphore RLN (rate limiting nullifier). This particular construction was found unfeasible 7 years ago, but since then zksnark tech made huge progress and it is way cheaper now.

Messages by default are encrypted in transit. Client to server.

By this metric Facebook and Google are encrypted, because TLS. Sorry, Telegram's messaging is an attempt to mislead users, plain and simple.

The library IS used for all encryption.

They could chose to use TLS for for almost all chats, and instead they've "invented" MTProto. Why go with MTProto?

As far as I can tell from casual use the other end does not need to be online per se.

You are wrong. Phone on other side has to accept "secret chat request" (no user interaction is needed). Until its accepted, initiator's app interface is blocked with a spinning circle. And to add insult to injury, one can't initiate secret chat from desktop client.

Telegram client(s) are also open source.

Yes, it is very refreshing to be able to verify that they can read all of my messages. /s

The comment was about the server and interoperability with other clients.

Signal leadership explicitly stated that they care about secure comms and don't care about ecosystem around the chat. You can create your own client, you can't market it as Signal because that might "endanger lives".

- The phone bits in your and the other commenters response sound a little bit handwavy to me.

I issue you a formal apology on behalf of HN hive mind. /s

On serious note - palata's point is right, but a bit outdated. Functionality is still there, but it became opt-in. New users have phone number automatically hidden and phone number is collected only as an anti-spam feature.

I'll repeat my point again. Telegram is a honey pot of messengers and nobody should use it.

What is encrypted and how is public information. If it doesn't fit your use case don't use it. There is no "spin".

Correct way of speaking about Telegram is - nothing* is encrypted. (encrypted chats are not more than 0.5% of all chats). That would be a "no spin" take.

one guy dared write a crypto library rather than using their own

Red herring. This library is NOT used for more than 99.95% of chats on Telegram. It is applied only to "secret chat", which is a torture device with horrible UX. I guess that horrible UX is the result of choice of using custom crypto library instead of going with something capable of working when addressee is not online.

Another darling is Signal who refused to stop collecting phone numbers until recently even though they never needed it, does not allow open source or other clients to use their servers (and won't release the actual server code) and frankly does not work half as well as Telegram in terms of UX.

Phone numbers are still used as anti-spam measure. You are free to get a burner, register an account and throw away the SIM card.

does not allow open source

Signal client is open source.

frankly does not work half as well as Telegram in terms of UX.

It works well where it does matter. Vide Telegram's "secret chats".

All of this is really confusing for me.

You are clearly misinformed. That explains the confusion.

Post is lacking in technical details. What it seems to be doing echoes the way ChatGPT is integrated into iOS - your requests are anonymized so your profile can't be (easily) built.

How can I make confer.to work on my Linux machine? Modern CPU.

No Socials November 9 months ago

There is a plugin called Unhook. It allows to remove shorts, recommendation feed, or even set subscriptions as your default page.

I have this in my .bashrc:

  function retry {  
      until $@; do :; done  
      alert  
  }
  export -f retry
Works reasonably well for non-scripting usecases.
Why I use Firefox 2 years ago

Do you consider it to be useless or is it something else? Privacy concerns (it is e2e encrypted btw)?

Except this is not about community. Communities are often exclusionary (e.g. "we, who are not those smelly hippy leftists"). This is about credible neutrality, an attempt to soar above tribal politics. Credible neutrality is an important aspect of money. Many (including Vitalik) think that cryptocurrency can't be considered money if it is not credibly neutral.

Scenario one. Individual (while working in a startup) is receiving some tokens as a compensation. Time passes. Their remuneration being on-chain and visible is a problem when negotiating salary in the next job.

Scenario two. I want to have on-chain identity (e.g. exo762.eth domain name). To register it I need to have some ETH (gas, registration fee). If I sent this ETH directly from my "money" account, I will forever link my public identity to my money, which is like walking around with "my net worth is at least XYZ USD" banner.