Welp, there is a lot of discussion around these claims.
But we are also on Telegram, mostly because I'm using their API for our Home-Assistant instance to deliver status updates (left the bathroom window open for too long, weather-forecast on the morning and evening for the next 3 days). I like it.
I'm using a ready-made sensor for this. It's the same system I'm using for temperature and humidty measurement. It's proprietary [0], but someone reverse engineered it [1], so I can send the data via MQTT to home-assistent. I then wrote an automation using Node-RED. It get's triggered when the window opens. After an initial timeout of five minutes, it will compare the inside temperature and humidity with the outside temperature and humidty, and decide if it should wait another five minutes or fire off a notification. If you close the window before, it will stop everything and reset itself.
[0]: https://mobile-alerts.eu/ [1]: https://github.com/sarnau/MMMMobileAlerts
Kind of odd that I trust Durov more than Zuckerberg, but here we are.
> It has many features other platforms lack, is reasonably privacy-friendly
Telegram still has no E2E encryption by default and their official desktop client dont have it either. So it's worth nothing if no one use it. It's not that I have much trust into proprietary fb code, but there are certainly better apps privacy-wise out there.There is another unique identifier that's stored in the local contact list: email addresses.
Use either email address or a phone number as an identifier, and you've no longer built a offensively privacy-violating service but have exactly the same distributed property.
If you only have access to one phone number and not giving it out is critical, then Signal might not be the right choice for you. But you won’t find a more secure channel that collects less metadata anywhere else.
There's no property of the latter that makes them a better choice than the former, but the existing ecosystem makes a disposable or role email address a much easier thing to obtain, and in general leaking an email address a far-less-damaging privacy violation than leaking a phone number, which can so easily be used to harass and directly track you.
In many parts of the world, disposable mobile numbers are very definitely not a practical thing. The correct starting point here is to use either an email or a telephone number as an external ID. It's still not perfect, but at least it's not a complete disaster any more.
Alas they've been 'working on it' for a very long time now, and are likely to fail because of this painfully slow progress.
Perhaps if they'd pissed around less with trivia like cryptographically secure stickers, they might have increased their chances of becoming a useful product before they end up surrendering the space to an inferior product which gains too much market share to overcome before they're even properly off the starting blocks.
I criticise Signal here because I like the design and hate their botched execution, not because I dislike the protocol. On the contrary, I dearly want something that competent to succeed, but fear we're rapidly losing the chance of that happening because they have launched a privacy-disaster product and most of the potential market will have seen that, dismissed it and forgotten about it before they pull their finger out and fix it.
With significantly worse UX.
> still has no E2E encryption by default
This doesn't make it not reasonably secure in my mind. While the TG people will be able to access your messages, they can also process them, making stuff like large groups even possible (imagine the distribution hell otherwise).
I do tend to think that there's not much of a down side to E2E for private chats though, since you can still share private keys between devices to enable sync.
> So it's worth nothing if no one use it.
Telegram is way more than secret chats.
So your standard for “reasonably secure” communications is Facebook Messenger?
It's not perfect, nothing is. But it makes better compromises than others.
Again, crypto is either broken or not. Telegram crypto is not broken. It's fine. Not everyone might like it, but that does not matter. I don't know story about CIA (although I wouldn't be surprised to find out that Signal is honeypot), so can't comment about that.
Security is not a yes/no thing. It is equal to the price to break it. If the cryptography is well-tested for decades, the price is much higher. This is not true for Telegram. It does not matter how good its creators are.
i'd rather have a foundation of properly functioning, award winning cryptography than "features" designed for people who haven't thought through their threat model sufficiently.
castles made of sand melt into the sea eventually
Signal also makes trade offs in order to het crypto to the masses.
>> reasonably privacy-friendly
> Telegram still has no E2E encryption by default
Right, but e2e encryption is a small part of "privacy".Not leaking your personal data, identity or telephone number, and with whom you communicate is often more important.
Seriously, that's how I feel whenever someone asks me for my WhatsApp number (no, I don't use WhatsApp, and there's nothing called a WhatsApp number) or asks me about Facebook Messenger. Great UX, fast and new features added at a pace that puts other chat platforms to shame.
[I won't talk about the security aspect in this comment, since it has been rehashed many times here]
Oh? I thought it was Qt. I don't want to seem like I'm complaining for nothing as it's definitely much better than, say, Slack client, but I still feel like the Windows client is a bit "out of place". Like the task bar context menu looks different from all the other menus for other apps in there, with rounded corners etc.
This is a harmfully misleading notion that we shouldn't be spreading. Without explicitly invoking "secret chats" which are not even available on desktop telegram is no different from skype and fb messenger and is categorically less secure than whatsapp.
There is still no e2e encryption on GNU/Linux desktop, even as an option.
These layers are used in addition to any encryption done on the transport layer.
The same can be said of Signal or any other chat application distributed through Google Play. How do you know the binary corresponds to the source? Good luck getting reproducible builds on Android or iOS. If you want to be sure your chat app is secure, you need to review and compile the code every time. And, of course, you need the knowledge and skills of a good cryptographer to determine hidden backdoors in the algorithms.
Whatsapp is reasonably secure, as long as you don't upload your unencrypted chats to Google Drive (the backup functionality). Telegram, with E2E enabled, hasn't been proven insecure enough despite its weird custom crypto scheme. However, WhatsApp brings E2E to group chats where Telegram needs manual configuration in private chats to do so. If we want to bring E2E to the masses, WhatsApp is the best option for now.
I'm hoping Matrix will change this or Telegram will implement proper crypto, but until then, WhatsApp is probably the best option we have.