I've always used Telegram for privacy purposes.
It was amazing to watch the flood of friends "just signing up".
I've always used Telegram for privacy purposes.
It was amazing to watch the flood of friends "just signing up".
https://www.whatsapp.com/security/WhatsApp-Security-Whitepap...
Yes, the signal protocol and signal's implementation are both open source, but you have no way to actually verify that WA has actually implemented the protocol correctly and securely. Sure you could do some basic packet analysis but this wouldn't tell you about the presence of any remotely triggered backdoors.
The only way for you as a user to actually verify the security is by reading the source and compiling the software yourself, or reading the source and verifying the signature via reproducible builds.
I really don't understand the business decision process here. If they just copied Signal with OSS/FOSS code and reproducible builds they would just win outright and tech people wouldn't have anything to complain about. The value of the service is the network anyway -- why care so much about the client?
I mean, it's not blocked so I guess it's better than nothing but it's not a plus for privacy: it's a net negative.
As someone professionally involved in cyber security, I fully understand and agree with the criticism that the protocol is non-standard and does not follow several best practices. On the other hand, it cannot be ignored that it hasn't been cracked yet, despite Telegram being one of the bigger messaging services in the world (especially one attracting a tech-savvy audience) and receiving a lot of attention.
The very least Telegram-haters could do is acknowledge Whatsapp's equally big problem: we cannot verify a thing. Facebok could have either open sourced the clients or published the outer shell of the wire protocol so we can verify the E2E encryption. They chose to do neither.