TDLib – Build Your Own Telegram Client
telegram.org
telegram.org
We're building an MIT/ZLIB/Apache2 Open Source End-to-End Encrypted alternative that is a fully P2P decentralized app (dApp), see: https://hackernoon.com/so-you-want-to-build-a-p2p-twitter-wi... !
Currently it supports signed/verified messages, haven't added cyphered/private messages yet to the API, but it is available in the SEA (Security, Encryption, Authorization) utility library underneath - but that should be coming soon, and of course love any contributions!
Also, the "server" has no special application logic on it, it is just another peer in the network that can help with WebRTC signaling or being a websocket relay. It cannot middleman the data, because every message is signed via the "client" (technically there are no server/clients, everybody is just a peer) using latest native Web Crypto API!
Here is a demo of an example social network app that is syncing character-by-character with cryptographically verifiable sources across a test network of real world devices: https://youtu.be/C3akdQJs55E
Again, all truly Open Source (ie, MIT/ZLIB/Apache2)!
> So You Want to Build a P2P Twitter with E2E Encryption?
Saw this and immediately wondered: is this just twitterish features (primarily broadcast) or are there plans for private and group chats?
The alternative (using Telegram's homegrown and dubious cryptography and lack of actually encrypted group messages) is significantly worse. Here's a nice summary of the issues: https://security.stackexchange.com/a/49802/43733
IP address is much easier to hide, for example by using a VPN.
Why is Telegram X issued by "Telegram Messenger LLP" while the original Telegram is issued by "Telegram LLC"?
Telegram LLC, which issues the original Telegram app on the App Store has been undergoing litigation with regards to its ownership. It is based out of Russia and a company called UCP with Krelim ties who 'bought' VKontakte has been suing Durov for full Telegram ownership pursuant to VKontakte 'purchase'.
Telegram Messenger LLP however is based in London and seemingly wholly owned by Durov crew. In 2014, Telegram Messenger LLP launched Telegram HD, a separate app from Telegram-LLC-issued-Telegram. Now it is launching Telegram X , another separate app (which was until very recently Challegram, an open source Telegram client, winner of Telegram contest, and purchased by Durov) .
Draw your own conclusions.
EDITED for clarity and details
https://themoscowtimes.com/articles/the-telegram-lawsuits-ex...
http://www.ewdn.com/2014/07/29/pavel-durov-has-cloned-telegr...
https://rusletter.com/articles/ucp_requires_to_recognize_tel...
http://www.frandroid.com/android/applications/securite-appli...
Is this true? I can't find the source anywhere. Not even a dated one, if they had re-licensed it.
https://github.com/DrKLO/Telegram/blob/e9e40cb13ea942b148b25...
The compiled code will be fine, probably. It won't be much different from that would happen if they used the standard method of xml files and separate classes for that stuff, and might even be slightly faster.
But it surely is less maintainable, and the code definitely doesn't look generated to me. Maybe if you count copy-paste as code generation.
I hope they don't use Atom as an editor, because it surely won't be able to cope with such a file. [/s; but might even be true. not tested.]
This is as if someone used a tool to translate UI code from some other platform to Android (completely into Java) and forgot to refactor.
Until then, throwing the "homegrown encryption" argument to argue for Telegram's weakness is hand-waving and a straw man.
Telegram's security is sufficient for the threat model I have to face against now and in the future.
[0]: https://security.stackexchange.com/questions/49782/is-telegr...
I've found Telegram to be more than good enough for day to day communications where I would previously have used email or SMS/MMS.
I'm normally on the Signal side of this argument, Telegram is trash and should not be used, but basic features like message editing are legitimate requests. I use Signal heavily and a number of times a day at least I or someone I'm chatting with corrects a previous poorly phrased or incorrectly typed messages. Because Signal has no mechanism for that, it usually involves retyping most of the message or the relevant word and adding an asterisk. I believe if Signal had built-in message editing support it would be used far more than I currently see corrections.
To be clear, I would expect Signal to allow me to see previous versions of a message and clearly indicate that it's been changed, but message editing is a valid feature that Signal should absolutely implement.
Further, the goal of Signal is not to work well for people who are accustomed to the various quirks of text-based communications that have existed since forever, but to provide a secure, modern communication client that normies don't find difficult to use. Message editing has become a standard feature of any usable modern messaging client.
When Telegram first launched, people were reading their crypto whitepaper and going "Whoa, this is weird. You should probably not be doing it like this", and the reply was "Well, our 6 world champion coders (did you win a coding world championship?) think it is nice. Deal with it".
They then launched a bullshit crypto challenge (which would have been secure even using crypto primitives we _know_ are insecure). People told them that wasn't how it was done. They replied something cocky about world champion coders.
A couple of months later, someone found an gaping hole where the server could MITM every newly started secret chat (which their hack for forward secrecy a couple of years later would have made possible for every 100 messages).
I think their attitude towards encrypted messaging hasn't left puberty yet, and I recommend against it for everyone looking for a secure messenger. For anyone looking for a more convenient whatsapp without caring much for privacy by default, I don't mind recommending Telegram.
Regarding your future threat model: I certainly can't say whether having a copy of a significant chunk of my private communication on a server in Russia is a future threat to me. On the other hand, I don't use any social media, and have proper data retention policies on most of my online communications.
To be fair, Telegram doesn't have servers in Russia.
It might have been an intentional tradeoff when Telegram came out, but it's not any more. It's not a great defense for the fact that you chat history exists in plain text on Telegram servers.
I personally use Telegram when talking to my wife because it lets me have a client on every platform i use and the messages follow me. I could do that with some of the other platforms as well, but im already on this platform, the wife is on the platform, and some other family members as well. Now would it be better if it was "more" secure? Of course it could, I mean, we could all be communicating with PGP as well, but most people don't because its a pain to use. So to me personally, Telegram is a useful middle ground between great security and usability.
As a added bonus, using the bot framework that Telegram offers, i have started creating a home automation bot. The framework is really fun and easy to use.
Same. I tried Signal a couple of years ago but the iOS app was prone to crashing, corrupting messages, and just plain losing words. Not really what you want.
> The framework is really fun and easy to use.
Yeah, I've done a couple of bots for it and it's pretty handy.
https://medium.com/@wireapp/making-your-conversations-secure... does not state any information on key management solution: how encryption key is transferred to another device.
But it has links to https://en.wikipedia.org/wiki/Double_Ratchet_Algorithm which has nothing about cross device key sharing and https://wire.com/resource/Wire%20Security%20Whitepaper/downl.... I've read it through and found nothing on cross-device key sharing as well. Can you point me to the right part?
What I do know is that you don't have access to messages that happened before you first signed in to the device you're using. My message history is complete on the phone I created my Wire account on, but I installed it on a laptop a few days later and as such is missing those first days. Messages get delivered to all your active devices without problem though.
The source code for all their different client varieties (iOS, Android, Web/Electron) and server software can be found here if you're interested [0].
Source? https://telegram.org/blog/sessions-and-2-step-verification says:
"It allows you to set up a password that will be required every time you log into your account from a new device – in addition to the code you get in the SMS.
Be careful though: if you forget this password, you won't be able to access your messages from other devices."
This sounds to me that the chat history is encrypted with the password which doesn't leave my devices and therefore I'm not able to recover the history if I lose it. Since all clients are open-source, it should be possible to verify this.
edit: Okay the option for a recovery email could mean that they still have the password (or a key derived of it) on their servers - so basically plain-text.
iMessage does that† (is that what you mean by "key transferring"?). I wish it could display the device key fingerprints somewhere, allow for key pinning, as well as offline key exchange between parties though††.
† in fact history is not centrally shared: messages are encrypted and published once per receiving device by the sender.
†† And be cross-platform. But the optimist in me says it's to control the security experience while the cynical in me says it's about network effects (although mitigated by SMS integration) for commercial reasons.
That doesn't mean it "has a poor security record" (implying that the security is broken), it means it is not as secure as other options.
> not at all for group chats
May not be a requirement for group chats
> the cryptography is a bigger unknown than with others
Unknown does not mean bad, it means unknown. Almost definitely worse than Signal, but almost definitely better than Facebook Messenger.
To say Telegram is less secure than e.g. Signal is true. To say it "has a poor security record" is disingenuous and misleading. Once Telegram has had several security breaches, then that would be a fair phrase. Until then, there are levels of security for given threat models, and Telegram's is not as secure as others', by design.
That assumes the Telegram team aren't part of the nation state apparatus, surely.
People(IME at least) use Telegram(or WhatsApp) because it’s a nice to use app, both mobile and desktop.
It should be resolved soon: https://twitter.com/durov/status/958990254396059648
What is wrong with the current app? Or was that not official? I find it better than the Facebook Messenger (light or not) and it's definitely much better than the Hangouts app from Google.
Explains why it doesn't take a minute to start and doesn't need a gigabyte of memory.
The effort that went into that thing is amazing. It's fast on my 5 years old Pentium.