Hacker Newsnew | past | comments | ask | show | jobs | submit | crossroadsguy's commentslogin

But then if it still runs "out of capacity" you will be billed, right? Or you put on the credit card and then set some kind of charge limit as 0 or something?

They kill those instances for both abuse and unuse. Mind was killed for the latter.

You mean a website A can have login/auth cookies of website B, D, Z, HK… etc? SOP doesn't work? Or is there some sort of exploit on top of third party cookies? (Just curious. I don't know anout browser dev/etc).

By the way, they don't have just one web apps. They have A, they have K, and apparently a Z – subdomain is webz, or maybe that's actaully A. Not sure.


One of the challenges with Telegram is - they regularly re-enable settings inside the app/account that you had specifically disabled. So at any point you don't know what is happening and what is not. Meaning, even if you didn't see a thing, a malicious file might be sitting all warm and fuzzy on your computer - among possible other things. I used to like the snappiness of this app (and it is still snappier than almost all other IM apps combined, by a margin), but after a while I realised it was a ticking time-bomb (to keep it installed on the desktop) and possibly a scammer safe haven, nothing else.

A lot of companies do this but I always get a ton of hate for saying this: Telegram is the worst offender I've seen. If you start digging through their apps, you see a ton of security practices that are anything but secure. And one of the hundreds of reasons I treat Telegram as the plague: get it away from me and burn it with fire.

I've never seen a legit good hearted person ever use Telegram. It's usually what grifters and scammers prefer to use. Or Signal.

Signal is legit. The entire stack is open source, and messages are E2EE.

Telegram is connected to Eastern European and the Middle Eastern countries and not in a good way, and the server-side components are closed source. There is no E2EE by default.


Signal requires a phone number and does not want anonymous users, so I do not want it too.

The phone number is only required to create an account, and is never used again IIRC. The rationale for it was to prevent abuse/spam, but I believe there is now an option to purchase an account for a small fee without needing a phone number.

Purchase can be done only through Apple/Google Pay which require a phone number and a bank card on top of that. Do not be deceived by marketing people.

Yeah having to doxx yourself to avoid giving a phone number is a bit disappointing for a privacy-conscious messenger app.

Especially because they have their own crypto coin right there in the app so why not allow payments with that?


so does Telegram

But Matrix does not. I wish they removed email requirement too though.

It depends on the matrix server, they don't have to require an email address per se.

The Signal desktop app is complete and utter garbage.

Maybe that's regional but here in Spain it's very popular for clubs. We use it for our makerspace and also for several other clubs. The moderation and access tools are way better than WhatsApp's.

It's not end to end encrypted but for big group channels that anyone can join that doesn't really matter.

Here it's all WhatsApp and Telegram. iMessage isn't really a thing at all except for expats. Because most locals use smarties. I don't accept sms or rcs either.


My family uses it to communicate on devices that don't support iMessage (mainly Windows and Linux installs) because it's one of the precious few cross-platform messengers that doesn't treat desktop users as second class or as an afterthought.

There's a few communities that use Telegram because it seems to be one of the few that is both generally usable by the average person and by default has at least a little respect for separating your online identity from your real life identity. Which is sad because I agree it's a bit of a dumpster fire when it comes to security and privacy beyond that.

Counterpoint: I have. Although Telegram is less popular in the US. I try to get all my friends using Signal.

I prefer to keep the contents of my message secure from the panopticon.


> Or Signal

It's kind of hard to hash out what you're saying here


There's at least millions of such persons

> I've never seen a legit good hearted person ever use Telegram. It's usually what grifters and scammers prefer to use. Or Signal.

TIL I'm not a legit good hearted person.

Guess I'll remove myself from the organ donation registry.


All big companies pull these kind of tricks. Another variation is to retire the old setting and introduce a new one with a deceptive name that is default on again.

This hasn’t happened to me absolutely ever in 10+ years.

In the distant past this meant more. Vendors shipped one option for everyone. Now with things like A/B testing and other application 'smart' behavior which ends up meaning we all have different experiences.

Presumably the risk is mitigated somewhat with the Flatpak version (`org.telegram.desktop`)?

Flatpak has "classic mode" which means no sandbox, which you will never guess if you did not read the docs, because why tell the users the truth when you can use marketing speak. Also, Flatpak allows reading identifiers from /proc and /sys.

Not on Linux. But if that is a safe variant then yeah great. Also, I see https://flatpak.org (is this the one you meant?) has Telegram has one of the showcases apps on the homepage so I guess they would have done their due dilligence.

Can you please tell me what settings get auto re-enabled? I use Telegram as my primary messenger app. I just want to make a more informed decision if I should switch to Signal or something.

>if I should switch to Signal or something.

Yes

https://news.ycombinator.com/item?id=48923935


Note there’s no info on that page on which settings get reenabled, only general list of grievances with telegram, mainly from a privacy/security perspective.

Which privacy/security aficionados think everyone is obsessed about.

Some of us aren't paranoid and don't care, and instead just enjoy a messenger that works and doesn't throw bullshit limitations at you.


>Which privacy/security aficionados think everyone is obsessed about.

If you want to vomit your entire digital social life to some random company in Dubai and to every party who hacks their servers, you do you.


You absolutely should use Signal instead.

Is not Signal inferior? In Telegram you can communicate with strangers without disclosing a phone number, in Western messengers until recently you had to disclose it so that your contacts can conveniently find you and punch you in the face if you are a man or just annoy you with indecent messages if you are a woman (probably not scary in a country where everyone has a gun and every home is a castle, but not all world is like this). What Western genius thought of such a feature, displaying a phone number in a group chat?

Telegram also allows to delete any chat in one click. Telegram has support for HTTP, SOCKS, MTPROTO and WEB proxies to evade censorship, Western messengers do not. Telegram is written in C++. Although it is a piece of proprietary garbage and might be connected to the government, at least it is well made piece.

Also it became difficult to register in Telegram, it often asks for 1 euro when trying to register with a fake number. And with a real number the OTP code simply doesn't get delivered to Russia.


I am not sure what you mean by "Western messengers" exactly. If it's Whatsapp, then I don't think it's any better than Telegram, even though Whatsapp claims to provide E2EE. The entire stack is closed source, and in any case it leaks huge amounts of metadata.

And no, Signal is not inferior. If you are really concerned about the phone number issue, use a burner eSIM or purchase a Signal account. Last time I checked though, payment was tied to Apple/Google, inexplicably.


You can pay money to register without a phone number https://support.signal.org/hc/en-us/articles/11197884108826-...

Requires Apple or Google Pay, linked to a phone number and a bank card, crypto not accepted.

> What Western genius thought of such a feature, displaying a phone number in a group chat?

Well, most of those apps try to inject themselves in between you and the rest of the world, by "helpfully" offering to be your SMS handler and phone call replacement.

No thanks.


For example?

I won't be surprised if you will have to boot into recovery, disable SIP, come back to user-space and run those unsafe 'ls' and 'cat' commands you were trying to live dangerously with on '~/Library', and then go back to recovery again to renable SIP to stay safe. You may also have to do that to install every software you want to install and use on your (is it?) mac other than the ones that are from companies that had tied up with and signed Apple's USA certificaiton (i.e User Safety Alliance™; involving non-publicly disclosed deals), or from the smaller devs who were not small enough and could pay a few thousand dollars annually and sent Apple 3 kidneys annually to publish softwares with very reduced scope and access on the device/OS. The data transfer between your mac and those app endpoints will be so protected that even your own self-destructive hands and insufficient intellect won't be able to gather what is happening beneath the Apple's hardware hardcoded encryption. All for safety beyond the UNIX way. So not all surprising.

Have you ever considered, oh maybe using a Mac rather than making up complete bollocks(*)? Or perhaps looking up the well-documented and fully supported procedure for installing unsigned software? Or maybe noticing that the procedure is usually only needed for applications like FreeTube where the developer has a reason to remain anonymous? Yes, you can disable SIP. But you will struggle to find a need to do so.

(*) My lawyers have asked me to point out that the case of Regina vs Sex Pistols (1977) established that this term refers to a priest in Old English (https://en.wikipedia.org/wiki/Never_Mind_the_Bollocks,_Here%...).


Ah, the triggering at mere mention of an iFan.

> oh maybe using a Mac

If that’s what you get reading that comment then maybe ask your lawyer to pump some grey grease into the upper few inches next time you two are at a petrol err gas station.

> usually only needed for applications like FreeTube

No, looks like that won’t be sufficient. Pumping grey won’t be sufficient. Ask the lawyer to also do a “recent top posts on hn” search for you, assuming their marbles don’t yet melt at first sight of fruit company criticism/rant.

> you will struggle to find a need to do so.

Right. A member of the “you are holding it wrong” + “this is how it’s supposed to be used” genus spotted. Not your fault then. Here you go: yeah, you are right. Consider yours truly enlightened and in your immense intellectual debt.


Except you don't.

Is this “make shit up” day, or something ?

> make shit up

When it's about the fruit company, is there a difference? Unless it's for the eyes of the beholden i.e., le iFans.


oh no! security measures! scary!

They are, when used against the user.

It seems your courtship survived the shutdown :)

I don’t miss IRC at all. All I remember is harsh treatments and general harassment I received in those places as a kid/teen when I was trying to learn things, figure things out on the Internet. A lot of them were non-subtly targeted at my geography and race. I can never forget that. In fact those days taught me how people from different places look at racism in different ways and how for some there’s good racism and bad racism and then acceptable racism, including here on hn. It seems the “good early Internet” is a phenomenon experienced by very small subset of people even considering only the West.

There’s a difference — (essentially) everybody was on Google+ and no one is on Signal.

Maybe it's just how my friend groups have changed over the years, but I've had the opposite experience

Yeah. I know zero people from HN or, say, Reddit, and even from the tech/coding world (and past workplaces; not that they were a Signal weilding crowd even by a stretch). I have friends I can count on the fingers of one hand, at most both hands. I will never have to reach for the toes :) So if that's the opposite for you, then it might be the case. Or, honestly, even if that's not the case, it might be so. And since I don't have empirical research other than what I see "around me," I can't just say that's how it is "generally," even though that's exactly what I see :D

(PS. There was a time when WhatsApp ended up having really bad press a few years ago and I was abl to make almost 30-40 of my contacts to Signal but Sigal being Signal and its team/leadership successfully pushed them all away, a lot were crashes and what not. Even I was frustrated. It was the first time I was "using" Signal beyond "trying" it which is like an annual or half-yearly ritual now)


A majority of those of my friends and family who are on any IM platform at all are on Signal.

I don't know a single person who used Google+, unless you mean in the sense that Google forced it on everyone with a Google account.

In the days before Mastodon it was the geek/nerd social network of choice, and the majority of all the people I knew in the Linux and FOSS world were active on G+.

When Facebook arrived Orkut was dying as it was essentially left to die and Google+ absolutely had no chance. Even this new Orkut, if it happens, will be DoA if it tries to become everybody’s social network. “Everybody” wants doom scrolling.

That limitation is what stops me from using Pi for anything serious. I may have to configure it and then configure it and it will eventually become a codex, a claude code or so. I recently heard the maintainers added mcp to it (in stock, not via plugin), I wonder what stopped them from adding subagent function, and decent loop capacity to it.

Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: