It's a feature: history synchronization between different devices and fast search through hundreds of thousands of messages is, for most uses and users, more important than concerns that Telegram or nation-state level attackers (one capable of silently breaching Telegram infrastructure) would choose to read your chats.
Be aware, wechat sends every message with geolocation to the authorities in real time. It is more critical than ever that we be aware of the mechanisms in the systems we build and use -- else dystopia awaits.
Chat archives are stored encrypted, not in plain text. Please cite your sources if you claim otherwise.
I think that's what the parent wanted to say.
I think saying "chats are stored in plain text" is a reasonable way to convey that message and I think "plain wrong" is an overstatement.
If I keep your messages encrypted in my database and your keys on another unonnected database in another building, would it then be fair to say that I store your messages in plaintext?
No. They are encrypted. It is a matter of fact.
The word you are looking for is "not E2E encrypted" which can be a problem, but a different and smaller problem.
> and I think "plain wrong" is an overstatement.
No. It is a statement of a fact.
If you can still access them, I don't think it is fair (or maybe rather: it is misleading) to say that you store them encrypted.
If you trust me but are worried that someone else might break into the server it makes a huge difference.
So if you are using it on desktop, all your messages belong to Telegram, and whomever they are sharing it with.
This way Telegram can back up messages without dumping them to Googles servers like WhatsApp does by default.
But it’s absolutely homemade by math PhDs (not crypto specialists). And if you search for ‘telegram security’ you’ll find any number of articles pointing out a bunch of weaknesses. It’s also only half open source.
Not just that. The official clients repos (specifically Android) lag several weeks, if not months, behind the apps, or at least they did at one point.
Though that doesn't matter much with not-quite-verifiable releases...