Telegram: 200M Monthly Active Users
telegram.org
telegram.org
And unlike WhatsApp you don't need to carry your phone with you all the time just to send a message to someone on desktop.
Their bot API is also really rich. I am thinking of rewriting some of the Alfred workflows I wrote in Go as Telegram bots. For example I always wanted my Web Searches workflow (https://github.com/nikitavoloboev/alfred-web-searches) be present on my phone in some way. It seems I can actually do just that and reuse the Go code I wrote already.
Also, Telegram has private keys stored on their server, and recently the Russian government demanded they hand over the key otherwise they will be banned from Russia. This can only happen because the key is on their server. I think that's a big deal.
That's a cheap price to pay for E2EE only.
It also has a pretty solid API[3].
One downside for JS haters, though, is that while the application isn't a wrapper for the site it is still Electron.
1. https://wire.com/en/security/ 2. https://github.com/wireapp/wire-server 3. https://developer.wire.com
Solid crypto (Megolm)[1], open source, federated.
One other issue I have with Matrix is the fact that they're in the process of completely rewriting their reference implementation in Go despite the fact that - as far as I remember - the first one, in Python, isn't entirely complete[2]. Combined with the app-bridge song and dance[3] there's too much in flux for me to recommend in good conscience.
Finally, and perhaps most importantly (speaking as a "regular" user - the type needed to achieve mass adoption), the client is horrendous. This is especially apparent when compared with Wire, but I'd go as far as saying it's apparent even when compared with some IRC clients. At least Signal's UI/UX is passable. Encryption didn't catapult Telegram to 200 million monthly users. A slick UI, a half-decent UX, and some good marketing did.
1. Your link - https://about.riot.im/security/
Edit: Aside from that, while the Telegram UI is nice, it doesn't even try to compete with the interfaces commonly found in IRC clients (i.e. no bubbles, one or more lines per message, can actually fit more than a handful of messages without scrolling, and so on... see qwebirc).
2) Synapse (python impl) is however “complete” (for implementing the Matrix 0.3 spec at least, and newer stuff) and has been for several years. We should spell this out better in the README.
The reason for Dendrite (go impl) is to escape the python GIL and switch to a multidb/multiwriter architecture to keep up with the load on massive HSes like matrix.org’s.
3. I have no idea what the “app-bridge” song and dance is that you’re complaining about: bridges are one of the most powerful and fun bits of Matrix. Perhaps you don’t like the config used to provision them? I’m not sure how this impacts normal users.
4. You may need to give more info on why you feel Riot is “horrendous” so we can fix specifics :)
Once they're all linked you don't have this issue again so it's kind of a one-time thing.
It may be cheap for you.
But why not let me make that decision? You're assuming
- a) everyone has a phone number
- b) everyone has ONE phone number
- c) everyone has a phone
- d) everyone has ONE phone
- e) said phones have a good battery life, lots of storage, and are always on a fast unlimited internet.
- f) you want to give your phone number to everyone you want to talk to
For some of my chats, I'd want that sure, and the price in those cases is cheap.
For many other cases, no, I'm not willing to pay that price. I'm not willing to keep my phone on and with me all the time and provide it with fast expensive internet, just so I could say hello to some people.
You might say that I can find another service, or that I don't understand the price I'm paying. I did and I do. I'm only debating your claim that the price is cheap and putting it into general perspective.
As far as I know, secret Telegram chats don't have a private key stored anywhere but your phone.
No, they can ask them for the keys even if they don't have them on their servers. And one would think that a likely response would be "We can't do that, we don't store the keys on our servers". Which is exactly what happened
https://www.theregister.co.uk/2018/03/21/telegram_ordered_ha...
The performance and convenience of their desktop app is also very good. As a "I'll use it if I have to" WhatsApp user, I find having to re-authenticate the web app basically every time I launch it, and it constantly complaining about me switching off WhatsApp on my phone is almost a dealbreaker.
The clients are very nice, as the data is stored on the server, you can access it from any device (great on desktops and tablets, I hate not being able to send whatsapp messages from my iPad) and it doesn't fill your phone with the stupid videos people send to groups (many of my family members ask me why their phones are full and WhatsApp is always the culprit).
Furthermore, Telegram Channels are great. It is all the advantages of Twitter, without the noise. Some Spanish journalists that I like are starting to create Telegram Channels and it is a great experience to just receive their messages, without the RTs, and angry answers of other users.
Furthermore, I have a Channel myself which I use to publish opinions. It has only 10 followers, which are friends of mine which I know will appreciate. I really like the experience.
Also, Telegram has great integration with IFTTT, which I use a lot!
By the way, there is Whatsapp Web where you can type with your keyboard. But it's clunky (somewhat less clunky with the Opera integration, if you use Opera), fickle and still requires you to have your phone on and with enough battery in the same wifi as the computer, which isn't always trivial.
(I'm assuming TGUIKit is responsible: https://github.com/overtake/TelegramSwift/tree/master/TGUIKi...)
If that is not already the case...
People should stop worrying about whatsapp, telegream etc.
The biggest security hole are the keyboards on your phone. Especially on android. Has anyone bothers to check what data for example Swiftkey collects or potentially could?
Thanks to this structure, we can ensure that no single government or block of like-minded countries can intrude on people's privacy and freedom of expression. Telegram can be forced to give up data only if an issue is grave and universal enough to pass the scrutiny of several different legal systems around the world.
To this day, we have disclosed 0 bytes of user data to third parties, including governments."
2. No keys splitting will protect you if fsb has hold on the company (and they most likely have)
It's a pity 200M people do not understand that
Edit: formatting
Telegram is ran by Russian oligarchs that built the local equivalent of facebook. Telegram was developed in the st. Petersburg offices of the local facebook equivalent.
Telegram developers have deliberately made encrypted conversations impossible to use, despite selling their app on it’s “encryption”. Telegram developers also choose to use pretty questionable crypto, why?
Why are people so inclined to trust Telegram?
I don't understand why chat apps are so hard for large companies.
How to make a good chat app:
Just copy Telegram, but end to end encrypt everything by default.
https://twitter.com/bershidsky/status/910169626989953024
https://twitter.com/ChristopherJM/status/910186197598838784
https://theoutline.com/post/2348/what-isn-t-telegram-saying-...
Oddly enough, your exilee friend Pavel has been a regular sight in St. Petersburg despite supposedly eluding the reach of the Russian authorities https://tjournal.ru/52954-durov-back-in-ussr
He even assaulted someone in 2017 because they were trying to take a photo of him in St Petersburg https://lenta.ru/news/2017/03/20/durov/
>Durov has no desire to aid people who robbed and exiled him.
It seems strange to think that he'd have a choice.
And anyway, Telegram is designed in a manner which allows its operators to easily read ~99% of the conversations between users. The same is not at all true of Signal or Whatsapp. Do you think that's a coincidence?
"On March 12, 2014 the owner, Alexander Mamut, fired the Editor-in-Chief Galina Timchenko and replaced her with Alexey Goreslavsky. 39 employees out of the total 84, including Director-general Yuliya Minder, lost their jobs. This includes 32 writing journalists, all photo-editors (5 people) and 6 administrators. The employees of Lenta.ru issued a statement that the purpose of the move was to install a new Editor-in-Chief directly controlled by the Kremlin and turn the website into a propaganda tool. Dunja Mijatović, the OSCE Representative on Freedom of the Media, referred to the move as a manifestation of censorship."
https://security.stackexchange.com/questions/49782/is-telegr...
Putin gives the Trump administration information on activists in the US, people part of the so called resistance, that are using telegram. Pavel Durov is told to keep quiet, or he'll get to eat some polonium.
A modern COINTELPRO.
I'm not saying that's likely, however given history, it also wouldn't be surprising.
1. Durov got ousted out of his own company (VK, basically Facebook in Russia) by Putin. He then decided to live in exile in Germany
2. Telegram is incorporated in Germany (which has some of the toughest privacy laws in the world), not Russia
3. Their keys are segmented and hosted in different jurisdictions, that are picked to be likely antithetical to each other. This means an adversary has to go through multiple legal systems, and power blocs (China, EU, N. America) can’t just use their regional sway to force key collection.
If there is one thing you can dislike Telegram for, its that they rolled MTProto instead of something more default. But in terms of personel, legal and UI/UX, they’re golden.
Edit: not meant as a whataboutism, Russia would certainly be more aggressive in doing so, and Durov is an easier target.
They moved to Dubai: https://www.bloomberg.com/news/articles/2017-12-12/cryptic-r...
It's one message though, I personally don't mind.
I'm very surprised by this. To me the bot that sends me the login tokens does only that. I received this because I subscribed to an official channel named Telegram News where they share this.
If they're sending news thru the login bot to people who aren't subscribed to news, that's not nice behaviour of them in my view.
Solid E2E crypto (Megolm)[1], open source, federated, clients for most platforms, Android client on F-Droid.
I use Signal myself and it's nicer than Riot, IMHO, but I can't get anyone else on to it other than my other half.
Regarding its popularity I would have expected a lower quality product. In fact the UX and the UI are superior to slack.
Furthermore while not needed, it was _very_ easy to host my own matrix server and to use bridges to access my preferred IRC channels. So my server keep track of the messages written when I'm not logged in.
Really its just great and I recommend everyone to give it a try.
No thanks.
I ended up preferring Matrix via Riot.im though...
I've been using signal for a while and I have successfully converted all my family and friends to using it. That includes a 70+ year old mother and father.
There have been no issues in using it's function from sending messages to video chat and everything in between.
One of the reasons people use Telegran (aside from chats\groups\bots) - is channel, for many people this is new RSS.
When I tried Signal, it frequently crashed, corrupted messages (requiring a reinstall of the iOS app), dropped messages, etc. As a result, all the people I persuaded to use it stopped and I currently have zero contacts on there.
Telegram is currently using 87MB of my system memory on my linux box. Furthermore, under linux there is no way to minimize signal to tray, it always stays visible in task list. No thank you, but I refuse to use electron-based "native" apps.
However, I couldn't get people to use it. It's constantly under political pressure because big bad encryption and Bad People are using it, despite the fact that lot of other messengers offer the same (including basically anything with OTR plugins, say, ICQ via Pidgin).
Telegram could and should be great, but the pressure needs to go away from it. I really wonder why Whatsapp, with it's encrypted-by-default approach is not under this level of attack. It's good I'm not into conspiracy theories.
Anyway, in the end, I ended up using it with my wife and nobody else. This made me realise I could just set up an XMPP server (Prosody in this case) next to my already existing mail server and use that with her. At least I have complete control over that.
Basing their company in Russia, they knew exactly that the government would come for the data eventually.
I tried Wire first, I really wanted to like it. It lost messages. It got it's crypto state horribly confused and couldn't read messages from one of my contacts. It maxes out at some annoyingly low number of "devices" - which includes things like different browsers, different OSes, private browsing windows opened on someone elses computer, etc. And it generally felt like a poorly built UI.
It was just OK instead. I haven't seen lost messages, but I've seen them taking several minutes to go through with both clients online and on the same LAN. The UI was not quite there yet too. Routine basic operations required extra taps, it felt less snappy and responsive than you'd expect it to be. So, yeah, it can be used in a pinch, but it's not yet ready as a drop-in replacement for Telegram.
Think of it this way: not everybody can wrap their heads around computer security and privacy on the internet, but almost everyone can tell when an app isn’t pleasant to use or has gaping holes in its feature set.
In short, if any E2EE messenger is going to come to dominate IM, its developers are going to invest just as much time and effort into its UI + UX as they do its encryption — you can’t ignore the former and wonder why the masses aren’t interested.
It's not just "working better", the experience is throughout downright stellar compared to anything else, on every aspect I can think of.
I moved friends+family to Signal after a month.
I as one of those 200M users ask you kindly to please add Kosova (+383) since entry codes +386, +377 and +381 will be disabled by the august of this year.
So Pavel, if you're reading this, how 'bout it? Add an option for a private server for those who'd like to use Telegram in places where the powers that be are pulling tricks like in Russia. In that context it would be interesting to know how Telegram can survive in Iran, does the government there have access to anything they shouldn't?
Sort of a canary by proxy. Maybe they could get (per-country, ideally) warrant canary pages on their web server.
Russian here.
FSB is bluffing yet again, just like they were bluffing with youtube block. Too many people use it, too many politicans use it and even troll army based in Olgino use it.
They won't ban it.
Personally Signal is nearly unusable for me (check my posting history for why, this has been coming up a lot recently). I think Telegram has the highest quality UX of any modern IM, yet I still mostly use Facebook Messenger because everyone is on it.
I'm aware it is not secure as I would like to but I'm gonna use whatever my friends use anyway.
Most people I know uses about 3 IM apps and they don't bother caring about privacy anyway (by using products of Facebook and Google, where Telegram, despite it's problems is still better choice for privacy).
I hope Telegram resolves issues everyone is concerned about.
Or all my friends switch to Signal.
Or something.
This doesn't just "suck", it's completely unacceptable.
Their secret chats are so annoying. No multi device support. And the cleartext everything by default. Blah.
Now that I think about it, administering a mail host is exactly like being a nurse, only people die slightly less often."
You can set-up a password. Also you can login with a Telegram device nearby, e.g. a tablet or laptop. No phone required.
> Second, it collects and uploads all of your contacts to Durov's servers.
No, you can deny access or don't use the app from your phone. Contacts can be added by username, too.
> Third, all the messages are stored on the servers too so Durov can read them at his spare time.
No, the so-called secret chats are end-to-end encrypted and not stored on their servers.
This feels dishonest to me. Nobody ever uses the secret chats because Telegram devs have deliberately made them impossible to use.
I use it, so it isn't nobody.
> not implemented by apps
It's implemented by the Android and iOS apps, which are the most used ones.
> actively discouraged by UI
How is this actively discouraging? https://img.gadgethacks.com/img/original/18/79/6363832577010...
>Telegram is more secure than mass market messengers like WhatsApp and Line
Why are you defending these fraudsters?
>I use it, so it isn't nobody.
Don't play silly word games, you just said "I would guess that usage is definitely below 1%"
>It's implemented by the Android and iOS apps, which are the most used ones.
Ah, so it'll only fail to work 30% of the time? That's not terrible UX at all.
>How is this actively discouraging?
Why do you have to press a button to chat securely, when the "less secure" WhatsApp does not require that? Is it because of Durovs superior encryption technology?
You simply can't justify that button.
Them being fraudsters doesn't make all of your allegations true.
> Don't play silly word games, you just said "I would guess that usage is definitely below 1%"
So? 0.1% is below 1% and would still correspend to ~200000 users. That is NOT nobody.
> Ah, so it'll only fail to work 30% of the time? That's not terrible UX at all.
Source for the 30%?
> Why do you have to press a button to chat securely, when the "less secure" WhatsApp does not require that?
It's a trade-off. WhatsApp / Telegram's secure-chats are lacking other features Telegram's non-secure chats have.
And yeah, having to click "Start secret chat" is deliberately making things difficult. Signal or Whatsapp don't require that.
supported:
Telegram for Android
Telegram for iPhone and iPad
Telegram for WP
Telegram for macOS
not supported: Telegram for Windows/Mac/Linux
Telegram for Firefox OS
Telegram Web-version
Telegram Chrome app
I guess we have a different definition for "most".To log in you have to either confirm your number (receive SMS or a call) or to give a code sent to your previously logged in device. There is no traditional login and password as far as I know.
assuming 5 million of the 200 million are there for the ICO's :)