Sadly it was the only nice alternative when the snowden stuff was published. That means those of my peers who made it away from skype/fb/whatsapp are now on telegram.
Sadly it was the only nice alternative when the snowden stuff was published. That means those of my peers who made it away from skype/fb/whatsapp are now on telegram.
How do you accomplish a seamless swap from desktop to a mobile session using end-to-end encryption?
Most seamless end-to-end encrypted solution I've come across. And it's still in beta. Every piece is open source (I'm running my own server), it's federated, supports history sync as a first-citizen feature, individual read receipts for group messages. The UX is not as polished as Telegram, but it's improving rapidly and is more than usable as a daily driver.
If it's because Apple tells me so then I think can see that the end to end encryption is broken and interception is possible.
Are old messages re-encrypted with the new key?
This would be even worse.
It would still be possible to implement this in a secure way (including out-of-band key verification) by having the "original" key (the one you've compared out-of-band) sign keys for new devices and have the server deliver that signature (which the sender can then verify). I don't know if there are any implementations of this.
The thing which is really sad is that there are no end to end encrypted group chats.
e2e is in beta still, but they have key list management/verification in place already.
In iMessage specifically, or in general? WhatsApp/Signal do use E2E-crypto for group chats.
They seem to focus on bringing new features (like an alien voice FX feature) when they should try to fix the basics first.
The worst thing that happened to me was that UI told me I was in a chat with Alice, but I soon realized I was actually chatting with Bob. So much for E2E...
Now we use https://riot.im. I'm kind of surprised a federated solution offers a decent UX and is less buggy.
Wire is buggy but generally works. The main problem with it is that metadata is collected by default.
I'd say we had a 40% chance of actually connecting a call with Wire. Suddenly there was an update to the app and calling didn't work _at all_ until the next update came (this happened more than once).
A close relative finally gave up and yelled something along the lines of "who the f* uses this POS app", and I couldn't really argue. :)
I'm a firm believer that Matrix is the future. But right now I wouldn't recommend it to anyone that isn't an early adopter.
All official clients are open source so you can fork them or create a new one from scratch.
That's not what you get when you have a secure system, that's what you get when you design a system that can collect (and possibly monetize) the data of millions of users.
Telegram is secure from device to device, not from account to account. If I send you a secure message from my iPad I don't have to worry about the web session I opened a week ago on someone else laptop.
https://timtaubert.de/blog/2016/01/build-your-own-signal-des...
The second layer (Megolm) encrypts each sent message once per room, using a ratchet described by session key data. The session key data is shared 1:1 between the appropriate devices (past and future) over Olm.