Telegram stalking
oflisback.github.io
oflisback.github.io
There is one exception to this: people will see you online for a brief period of time right after you send THEM a message (otherwise it would feel like talking to a wall).
See: https://telegram.org/faq#q-can-i-hide-my-last-seen-time And: https://telegram.org/faq#q-who-can-see-me-online
Seriously, how is this even on the front page? It seems that people lately are coming up with excuses to call out any app/software/company based on privacy concerns, just so they get some attention.
(And even if it were general default behavior doesn't mean it isn't pretty crappy from a privacy point of view)
I find it amusing that we are raising 'privacy concerns' now for pretty much anything. How does sharing whether you are keeping your phone in your pocket or in your hands (and telegram active) affect your privacy? Its meaningless data.
Facebook too, will show a user as instantaneously online even if they have chat turned off for you (I think). On the plus side, Facebook recently disabled API access for online/offline status of your friends unless they've consented.
Is this for just the messenger app or the facebook mobile app?
The limitation is in the API only, you can still see the statuses in-app and online, but you would have to resort to a webscraper to get them.
I'm open to changes but I absolutely need a system with a desktop client and an API or something to interface it with hubot. So Signal, as the author suggested, is not a valid alternative for me.
Ideally, it would be great if Signal and Ricochet could merge best of breed features. That could mean a unified app across mobile and desktop with good security over Tor...
> Anyone with the onion address can still estimate availability by watching descriptors
" Hey there Telegram!
I have been an early Telegram user since late 2013 and was highly optimistic that it would become a perfect messenger. It's quite perfect from a UX point of view – which is important to gain users – but other things aren't that perfect.
You claim to be open and secure, but taking a closer look that doesn't seem to be true. Your API is open and the client apps were released as open source, but your server-side code remains closed source. It's been 2 years now and you still haven't open sourced the server. Do you still plan to release it? You say that you will eventually add paid options, which doesn't seem to be compatible to open-sourcing the server.
Of course one would have to trust you that you actually use that version of the server on your side, which leads to the second issue that concerns me. You advertise being secure a lot, but default chats don't use end-to-end encryption and secure chats aren't even possible for group chats. Even for encrypted chats a bunch of concerns were raised by much respected people in the security community, I'm sure you are aware of that and will not brag about that here.
I opened an issue on the Android app's issue tracker in early 2014 about end-to-end encryption (https://archive.is/9SfYt). There have been dozens of comments on that issue, discussing how it could be implemented but there was no official reply by the Android maintainer or any official Telegram account, despite numerous attempts.
The Android app's maintainer also doesn't seem to understand version control / git and commits tons of changes in a single commit and also doesn't use tags for versioning. He also doesn't merge pull requests but rather includes them in his large commits (thus also removing all attribution). There are also binary blobs in the source code and there are various licensing issues. All these issues have been raised but the Android maintainer doesn't seem to care about it.
The issue tracker for that app has now been closed by the maintainer and there was no explanation for this. Several people tried several times to reach out to the maintainer, but he never replied. I believe this is a huge problem for a security app, and for open source apps in general.
Last but not least, the current version of Telegram on the Google Play Store (3.2.4) is not open source.
Of course, client apps don't have anything to do with the server implementation, API, or general issues about Telegram. You've linked a Trello board somewhere deep on your website, but the link is broken. It's a major issue that there is no way to discuss problems, feature requests, or ask questions to the developers (we don't even know who the developers are). There is a community-run Telegram support account and a press contact and there's this email address and a Twitter account. Obviously none of these work as a discussion / issue platform, and you don't seem to reply to Telegram questions or Twitter.
A very good way to fix this is creating an organization account on GitHub and create a repo where you can use the issue tracker and wiki. You could also move the "official" clients to that account to have them at one place and you could use it to open-source or document other things related to Telegram.
It's also not clear at all who runs Telegram. All your website says is that it's financially supported by Pavel Durov and technically supported by Nikolai Durov. Your official apps and AS Networks are registered by " Telegram Messenger LLP" or "Telegram LLP" and your website claims your headquarters are based in Berlin, although no such company seems to be registered in the EU. You are legally required to publish your address and contact information to comply with German law §5 TMG. Additionally, both the LLP's and Nikolai's address are apparently at (different) British P.O. boxes. Is Nikolai the only developer or are there more? How are the official maintainers related to the LLP? Are they paid? Are they employees? Are there any employees at all? Who runs the company?
I'm really trying to not hate you and hope that you are what you claim to be, but it seems like you advertise security and openness successfully, so that the average user and the press buys it, but taking a closer look you seem rather shady without being very open. I feel very sad about this and hope you'll improve that.
Please shed some light and address these issues, most importantly a public issue tracker / discussion forum.
Thank you! – jomo "
After a year we are already well-established company and fully open source platform.
I was posting a link to a link to personal information (the phone numbers were censored in the version I referenced) and thus it was considered witch hunting.
Witch hunting every single user of Snapchat...
What I would like to see is the ability to periodical regenerate endpoint ids like what Burner does for phone numbers. Also, optionally add the ability to traverse Tor like ricochet.im
That would be nice.
only problem is that nobody uses it. so i might as well not use as well. which increases the problem that nobody uses it.
it is really hard to break into the IM market.
My other group is still on Whatsapp but I guess we'll move that one over as soon as we can get everyone to install Telegram.
As much as I loved Whatsapp and have happily not only paid for it but enjoyed paying for it Telegram is so much betterwith replies, hashtags and last but not least a standalone client for PC.
It's too bad, because I would use it otherwise.