Talk about network effects and people not doing their research. Or not caring about UX.
Talk about network effects and people not doing their research. Or not caring about UX.
I'm surprised more aren't using Signal, open source, and I believe funded by a non-profit organization. With founders that are known to care about organizational transparency and user privacy.
Also, the owners of Telegram are not on good terms with the Russian government (its been banned before).
It does make Signal a little less usable than some other messengers, and I'd be lying if I said I didn't use Slack a lot more than Signal. But this is also why Signal is what I use when the secrecy of what I'm talking about actually matters.
Which is fine but will never work with the average WhatsApp/Telegram user. First, they have to be educated, they have to care, they have to decide if what they are typing affords that extra level of protection, if the inteded destination is on Signal, etc. It's too much.
I've tried to convert friends and family to Signal but not a single one continued to use it after a few days.
But I think it's fine that Signal is making these compromises in favor of security and privacy. Maybe we don't really need mass adoption, as long as the people that really need it know where to look.
Another way to describe them is people who lost the largest social network in Russia and are now Russian expats and dissidents.
> Signal, open source [...] With founders that are known to care about organizational transparency and user privacy.
Not open source, only partly, just like Telegram. And founders are known to have a radical position on trading privacy for centralizing as much control over the app as they can, tying identity to phone numbers, etc. They have exactly as much control over the app as Telegram has. But they are not dissidents or expats and who knows what they are going to do or did with covert or overt government backdooring attempts. Still, despite all the flaws both Signal and Telegram are in a bit better situation wrt privacy than Facebook owned Whatsapp, being in a business of compromising privacy and all.
Signal is completely open source. I'm not sure why you think it's only partly open source.
Quoting Wikipedia[1]:
> All Signal software are free and open-source. The clients are published under the GPLv3 license, while the server code is published under the AGPLv3 license.
They've also gone to extreme lengths to prove that the software running on their servers has not been tampered with: https://signal.org/blog/private-contact-discovery/#trust-but...
I think your doubts create very unreasonable expectations for Signal.
It doesn't get much more open source than that.
It's just no polished like Telegram. It's painful to use compared to other apps.
Signal may be open source, but it's still as centralized as Telegram is. Signal.org will never federate with other servers running Signal (this is the official position). Signal also lags behind a lot in UX and convenience, when compared to Wire or Telegram.
It's not just about UX or not doing research.
The messages are still available in plaintext at either endpoint, and to the companies if they want them.
Facebook already publicly announced that they are going to use their AI to scan whatsapp messages for content violations (prior to encryption).
https://www.schneier.com/blog/archives/2019/08/more_on_backd...
British-Emirati, but same difference.
When the NSA tapped the dark fibers of Google etc they were also not exactly in bed with the government and yet they found out about the fact afterwards and started encrypting everything only then. (https://www.washingtonpost.com/world/national-security/nsa-i...)
When you look at the surveillance happening in Russia paired with the unclear status of Telegram's encryption and it being off by default I'd say it's valid to be suspicious.
And given how fast the west is moving on backdooring mass communications, in a few years Telegram might end up as one of the few unbackdoored apps left standing.
End-to-end encryption can be pretty useful, but just not in Whatsapp, Telegram, Signal or any app with that level of control.
If Signal has kept their promise so far then all of the messages I have already sent were EtoE encrypted and they never had any way to see those messages, indeed if me and my co-conspirators all destroy our devices the messages simply cease to exist altogether. If tomorrow Signal breaks their promise, that promise was already kept in the past and can't be undone, Signal can't read messages that no longer exist.
If Telegram kept their promise that's permanently conditional, they still have the data, and only their continuing promise not to look at it keeps it safe. Tomorrow they can break the promise and previous messages are now available, but you can't retrospectively stop having sent the messages in the past.
Secondly, as I wrote here recently on another topic: Only impossible things don't happen, everything else is fair game. In choosing to do EtoE Signal gets to make certain things _impossible_ whereas Telegram just promises not to do them. This means those things might happen by accident, or a bad guy might do them and I'm sure Telegram would be very apologetic (if anybody found out) but it couldn't undo them.
Thirdly: Signal actually publishes the software component that behave the way they say it does. Reproducible builds are tricky (as a general problem in modern software) but Signal does a pretty good job of convincing you that the binaries you can download are just the code you can see, built for your platform. So then either they need to not only break the promise but also hide the broken promise in the code, or they need to break the promise AND hide the build difference. It's just easier to keep the promise.
I'm not sure if telegram app developers suck or if IOS, Android and battery saver apps are in collusion with Whatsapp.
An unencrypted voice chat app could do VBR Opus, which would need slightly less bandwidth on average for the same quality but might mess with flow performance estimators in the network and make the experience worse by mistake.
One of the inadvertent benefits of Signal's strong centralisation of control is that they could just go "Opus CBR is great, we're using that now" and do it. No multi-year phase-in with most calls still being "legacy", no need to accumulate "buy in" from third parties who might not prioritize this work, they just did it.
Also Whatsapp UX is much simpler and I value simplicity. Telegram is starting to look like a spaceship with so many features.
Telegram has encrypted chats by default, just not E2E-encrypted.
That is wrong.
I guess there are some real issues with Telegram, but lets be honest and not lie and say it isn't encrypted.
Warning: the above is just my very simplified explanation of my understanding of what I read a while ago.
Edit: again, this is based on something I read a while ago, but I think Gmail has or had a similar system where you have to have access to two different places in the system to get hold of the messages, so yes, Google can get hold of anyones messages bjt it is not like anyone can do a select * from messages where accountid = 12345. (And this is not how I think they store the mails anyway :-)
The founders have lamented that the project is screwed, so you're left with a claim made my Zuckerberg and his buddies?
"As of today, the integration is fully complete. Users running the most recent versions of WhatsApp on any platform now get full end-to-end encryption for every message they send and every WhatsApp call they make when communicating with each other."