" Hey there Telegram!
I have been an early Telegram user since late 2013 and was highly optimistic that it would become a perfect messenger. It's quite perfect from a UX point of view – which is important to gain users – but other things aren't that perfect.
You claim to be open and secure, but taking a closer look that doesn't seem to be true. Your API is open and the client apps were released as open source, but your server-side code remains closed source. It's been 2 years now and you still haven't open sourced the server. Do you still plan to release it? You say that you will eventually add paid options, which doesn't seem to be compatible to open-sourcing the server.
Of course one would have to trust you that you actually use that version of the server on your side, which leads to the second issue that concerns me. You advertise being secure a lot, but default chats don't use end-to-end encryption and secure chats aren't even possible for group chats. Even for encrypted chats a bunch of concerns were raised by much respected people in the security community, I'm sure you are aware of that and will not brag about that here.
I opened an issue on the Android app's issue tracker in early 2014 about end-to-end encryption (https://archive.is/9SfYt). There have been dozens of comments on that issue, discussing how it could be implemented but there was no official reply by the Android maintainer or any official Telegram account, despite numerous attempts.
The Android app's maintainer also doesn't seem to understand version control / git and commits tons of changes in a single commit and also doesn't use tags for versioning. He also doesn't merge pull requests but rather includes them in his large commits (thus also removing all attribution). There are also binary blobs in the source code and there are various licensing issues. All these issues have been raised but the Android maintainer doesn't seem to care about it.
The issue tracker for that app has now been closed by the maintainer and there was no explanation for this. Several people tried several times to reach out to the maintainer, but he never replied. I believe this is a huge problem for a security app, and for open source apps in general.
Last but not least, the current version of Telegram on the Google Play Store (3.2.4) is not open source.
Of course, client apps don't have anything to do with the server implementation, API, or general issues about Telegram. You've linked a Trello board somewhere deep on your website, but the link is broken. It's a major issue that there is no way to discuss problems, feature requests, or ask questions to the developers (we don't even know who the developers are). There is a community-run Telegram support account and a press contact and there's this email address and a Twitter account. Obviously none of these work as a discussion / issue platform, and you don't seem to reply to Telegram questions or Twitter.
A very good way to fix this is creating an organization account on GitHub and create a repo where you can use the issue tracker and wiki. You could also move the "official" clients to that account to have them at one place and you could use it to open-source or document other things related to Telegram.
It's also not clear at all who runs Telegram. All your website says is that it's financially supported by Pavel Durov and technically supported by Nikolai Durov. Your official apps and AS Networks are registered by " Telegram Messenger LLP" or "Telegram LLP" and your website claims your headquarters are based in Berlin, although no such company seems to be registered in the EU. You are legally required to publish your address and contact information to comply with German law §5 TMG. Additionally, both the LLP's and Nikolai's address are apparently at (different) British P.O. boxes. Is Nikolai the only developer or are there more? How are the official maintainers related to the LLP? Are they paid? Are they employees? Are there any employees at all? Who runs the company?
I'm really trying to not hate you and hope that you are what you claim to be, but it seems like you advertise security and openness successfully, so that the average user and the press buys it, but taking a closer look you seem rather shady without being very open. I feel very sad about this and hope you'll improve that.
Please shed some light and address these issues, most importantly a public issue tracker / discussion forum.
Thank you! – jomo "