Dan Romero pfp
Dan Romero
@dwr.eth
The day I can delete Telegram forever will be a great day.
27 replies
13 recasts
120 reactions

Greg pfp
Greg
@greg
It’s better than any other messenger tho
4 replies
0 recast
1 reaction

Thomas pfp
Thomas
@aviationdoctor.eth
Signal: am I a joke to you?
1 reply
0 recast
0 reaction

Greg pfp
Greg
@greg
yes - I don't want to give out a phone number
3 replies
0 recast
2 reactions

Thomas pfp
Thomas
@aviationdoctor.eth
Ah that’s a fair point.
1 reply
0 recast
0 reaction

Greg pfp
Greg
@greg
this is why I like the Farcaster direct casts approach by @cassie - same encryption as Signal as far as I understand but no phone number supposedly XMTP plans to take a similar approach over time but Farcaster DCs don't have good good cross platform support + both don't work with groups, so telegram it is for now
3 replies
0 recast
4 reactions

Varun Srinivasan pfp
Varun Srinivasan
@v
one challenge with x-platform support is that it intrinsically weakens security. how do you know if your counterparty using a different app is not leaking all your data because of a bad implementation? no one has a good answer for this today.
3 replies
0 recast
4 reactions

​woj pfp
​woj
@woj.eth
@polmaire.eth this is a good q what trust assumptions regarding my privacy do i make while using converse?
1 reply
0 recast
0 reaction

pol pfp
pol
@polmaire.eth
Good question indeed. 1/ server side: today, you trust XMTP Labs because they run all nodes and node code is not open source. Tomorrow : open source + decentralization = server side should become trustless.
2 replies
0 recast
0 reaction

​woj pfp
​woj
@woj.eth
honest explanation, thanks whats the best way to show that a client is secure? open source + audit?
1 reply
0 recast
1 reaction

pol pfp
pol
@polmaire.eth
Open source and audits definitely help (the former for transparency, the latter for "proof" of security). The tricky part is making sure that the code that is open source is really the one that runs on your device. For smart contracts it's straight forward ; for clients it's less obvious.
1 reply
0 recast
0 reaction

pol pfp
pol
@polmaire.eth
It seems like there are ways to do so for Android and iPhone apps for example (here's a Telegram article about it: https://core.telegram.org/reproducible-builds#reproducible-builds-for-ios) I also heard that zk proofs could help a lot with that (prove that you're running the code that you say you're running).
0 reply
0 recast
0 reaction