Don't use it, don't let friends use it.
https://twitter.com/matthew_d_green/status/81899003583181619...
https://twitter.com/kaepora/status/819181464369577984
https://twitter.com/matthew_d_green/status/81919238137120358...
Don't use it, don't let friends use it.
https://twitter.com/matthew_d_green/status/81899003583181619...
https://twitter.com/kaepora/status/819181464369577984
https://twitter.com/matthew_d_green/status/81919238137120358...
https://en.wikipedia.org/wiki/Signal_Protocol
Edit: add link http://www.cryptofails.com/post/70546720222/telegrams-crypta...
If you want to argue that Telegram and Signal are comparable because Telegram has better UX and Signal better security and some people prefer UX to security, that's fine (I could not disagree more strongly, but at least it's a coherent argument). But don't pretend the thread isn't about security to make people believe that there's controversy about whether Signal is more secure. There is no controversy: Signal won the Levchin prize this year for the Signal Protocol and sets the standard for secure chat, and Telegram... well, let's just suffice it to say that it does not meet that standard.
I somehow doubt it.
EDIT: Oh, I was mistaken, apparently there is an option now. From Wikipedia:
On October 4, 2016, Facebook deployed end-to-end encryption as an optional feature for Facebook Messenger users. It is available in an optional mode called "Secret Conversations" and uses the Signal Protocol.
Riot is based on Matrix which is a decentralized protocol (you're not tied to one company), and it doesn't need your phone number.
* open source, code on github
* e2e encryption (apparently derivative of Signal's Axolotl double ratchet)
* chat/voice/video, and group chats (all encrypted always)
* based in Switzerland, coding out of Berlin
* clients for iOS, Android, Mac, Windows, Linux, Web
* can sign up with phone number or email (or username? Not sure - I think you can find contacts via username, not sure you can sign up without email)
* reasonably responsive on twitter
* yada yada yada
Things like this: https://github.com/wireapp/wire-desktop/issues/80
Then there is the fact that the client acts as a browser that fetches information from the web automatically without blocking trackers itself. This is leaking metadata and actual data.
I can't believe there still isn't a single usable e2e mobile + desktop chat client that won't drain your cell phone battery super quickly.
The problem is that most people value convenience and speed over security and privacy. Telegram provides a very good trade off, much better than some other apps. If Signal were to be developed at the pace Telegram is, I would use it all the time, but it's not. For my use and likes, both Telegram and Wire are very good fits.
1. They don't claim to do end to end crypto unless you use the secret chats
2. The secret chats still aren't broken. Since 2013, I'd think at least one "crypto expert" (which all said a custom protocol was a bad idea) would have taken the effort to prove it by now.
3. Whatsapp claims to have better encryption, and they probably do, but it's 1) a lot less convenient and 2) unverifiable.
4. Telegram is open source. You can layer your own encryption on top of it if you care, and the clients' implementation is fully verifiable.
PSA: Whatsapp is dangerous snake oil--hidden source code and owned by a company with a terrible track record in terms of privacy.
They simply do a code dump every few months.
both are better options than telegram.
Yeah that doesn't work at all on my phone because it requires me to use Google Cloud Messaging (Google stuff on my phone is firewalled). You can't just connect to the Signal servers -- or your own for that matter -- and be done with it, you need to use Google servers.
I switched from skype to telegram because of its much smaller memory footprint. 400mb+ for skype, 63mb(current) for telegram.
Before you say "but I can compile it myself", think of how many people will ever bother to do that.
That's how literally every security person feels about the argument that closed-source software is unknowable.
We don't need decompilers or special tools to read closed-source applications. Almost all of them --- very much including the Signal-based messengers --- are built with tools that produce straightforward easy to follow assembly code.
But that's sort of besides the point. Reading assembly is more tedious than reading C code, which is in turn more tedious than reading Python code. But you don't get to move the goalposts now. You claimed, repeatedly, that closed-source software was unknowable. It is not; it is in fact very far from unknowable. So the idea that Facebook is going to sneak backdoors into some of its most prominent code under cover of "closed source" is an extraordinary claim, requiring extraordinary evidence.
So, I doubt any security professionals would say its preferable to not have the source, but to do the job of verifying the software you have to do it at a lower level than the source anyway, so having the source is a bonus, not a requirement.
whatsapp 6 out of 7
telegram(in secret chat) 7 out of 7
So i am not going to comment on the quality of whatsapp, because their sources are closed.
Most people are not going to use the secret chat.
Most people don't care about secret chat. This is for people who care. Granted, they don't have secret chat on Desktop which makes the whole app useless in general unless you only use phones for communication.
This is a reason i said "It's ok" in my original comment. Few people need encryption in day to day communication, but if you need it telegram is better.
Try this one: https://www.securemessagingapps.com
Recommends Signal and (with caveats) Threema and Wire.
If anybody really wants to hack you (you exatly) - p-2-p ecryption won't stop them, this is not some kind of absolute defence.
And if you are worried about FSB readin your messages - trust me, they don't, unless you are under suspection already. No organisation in Russian history ever worked this way, only selectively.
I know too well that not enough people care about privacy, sadly.
Does anybody know how many users are on Telegram and who owns them? Can you invest in them?
See Wikipedia and https://www.securemessagingapps.com
As for numbers: http://www.businessofapps.com/telegram-statistics-and-revenu...
https://telegram.org/blog/100-million https://telegram.org/blog/15-billion
> Telegram is a cloud-based mobile and desktop messaging app with a focus on security and speed.
Unfortunately, it tricks a lot of people.
As a user who doesn't care about my chats being 100% encrypted, but does want the convenience of multi-platform messaging, is Telegram a better alternative to Facebook Messenger, Google Hangouts or Whatsapp? My messages on Telegram may not be encrypted, but are they actively used to siphon information from my messages to contribute to my non-anonymized (or poorly anonymized) advertiser profile, and freely passed or sold to third-parties as they are with those platforms?
I've only seen hardline stances on "If you don't care about privacy, Telegram is great!" or "If you care about privacy, Telegram is awful garbage". What about the grey area in the middle? Where does it fit?