There's Secret Chats feature which they claim to be end-to-end encrypted, meaning that it's no more secure than Facebook's Messenger (also end-to-end encrypted in Secret Conversations). Even less so considering that they roll their own encryption (MTProto), while Facebook's Messenger uses Signal's protocol.
Further info (which will also lead you to problems with their MTProto protocol, if you're interested): https://security.stackexchange.com/questions/49782/is-telegr...
Facebook is planning to merge Messenger, WhatsApp and Instagram, which makes it even more awful of a choice.
> Some of its channels helped unconnected, scattered rallies mature into well-coordinated action.
This line alone makes their encryption rather meaningless for this use case, since Secret Chats only work between two people.
This has nothing to do with secure chats and everything to do with Telegram's Channels feature. But a ton of people that have never used Telegram nor read the article don't know that.
A multitude of proxies, shadow optic cables over the border and a bit of whitelisting from the government to allow payment processing made Telegram invincible.
Facebook can't read your WhatsApp messages (of course they can add an update any time to do that), but Telegram has access to all your messages right now.
¹ Yes, you can select the end-to-end encrypted sessions, but they're very crippled from a usability perspective. I don't remember the last time anyone used it with me, yet all my chats on WhatsApp are end-to-end encrypted without anyone doing anything.
Are we sure it can't? Because WhatsApp is closed-source, its GDrive backups are unencrypted and Facebook's whole profit model is based around snooping. Unless they make the app open-source, I'm not trusting them even with a grocery list. People act like E2E is the be-all and end-all but trusting an incredibly shady company on its word is not something I'm comfortable with.
GDrive backups are not readable by Facebook, they're readable by Google. End-to-end, if properly implemented is the be-all and end-all. Except for metadata, which is a problem, but a different one, and Facebook definitely abuses that. But they don't/can't read the contents of chat messages (for now).
It's not merely trusting that shady company, but also realizing that the news of FB not having E2E-encrypted messages would definitely make the news, you'd be aware of it.
Right.. consider what your adversary would be giving up by revealing such a secret, even if it was true. That alone provides a not-insubstantial amount of security.
Open source means anyone can audit and verify nothing was done after audit.
Moxie more or less audited WhatsApp's Signal protocol implementation, and people are right to be concerned about whether changes have been made since FB bought the app.
> Are we sure it can't?
Google can remotely uninstall, and install a trojaned version of any app regardless of app signature on an official Android distribution.
No, there's a 1..2% chance of backdoor.
The real question is, why is Telegram more secure? There's a 100% chance it can read your group messages, because it says so on their documentation that describes the cloud encryption. There is no E2EE at all for groups. There is no E2EE at all for desktop. Together these mean E2EE are completely neutered and useless. I'm a privacy researcher and I don't use them at all. Why would an average joe?
Facebook does get your WhatsApp communication metadata, and has been for years now. As the three letter agencies showed, metadata is actually quite valuable in many respects without needing to trawl through massive amounts of content.
Really? I haven't seen a single credible audit, nor a clear reason for rolling their own
The fact Telegram's E2EE has not been available
1. by default
2. on desktop apps
3. for group messages
for seven years tells you exactly how secure it is.
"the only other criticism comes from a direct competitor"
Fuck this attitude. Everyone has the right to criticize. If Telegram can't own their mistakes it's their fault, not that of the people who are beating them. Also, impartial professional cryptographers like Bruce Schneier and Matthew Green have told people not to use Telegram. Why is that if not because it's so horribly insecure. Why isn't there a single recommendation for Telegram from ANY cryptographer on the entire planet?
"they recommend WhatsApp despite the fact that it's closed-source and nobody can verify if its encryption truly works."
Because they've helped implement the encryption? Also if proprietary tools doing encryption are not secure, then why do Telegram users think it's ok for Telegram to use closed-source server that's doing the "distributed datacenter encryption" for group messages' at-rest protection. There's not even documentation available for this let alone source code.
But secret chats are only for 1-to-1 chats, not for groups as far as I know (or has that changed?)
There are also options for invite only channels ( I manage several TG channels, public and private) in which nobody can join without having been given the invite link, or added to the channel if their settings permit other users adding them to channels.
The world's best audit of Telegram would make the following obvious findings:
1. It's not E2EE by default therefore it's not private and secure by default.
2. It's not E2EE at all for groups therefore it's not safe for use of dissident groups
3. It's not E2EE at all for desktop clients therefore it's not practical in daily messaging.
Any audit of the E2EE part is meaningless when E2EE is so impractical it's not used by users at all.
Telegram's protocol... is not that.
[1] https://www.schneier.com/blog/archives/2016/06/comparing_mes...
[2] https://twitter.com/matthew_d_green/status/72642891296898252...
But yes, not having encryption on by default speaks poorly of them. OTOH it’s not concrete proof that the encryption still sucks as of now.
Also, Signal has no upper group size limit but E2EE would make group with 100,000s a bit sluggish. But that's a problem that reduces with Moore's law.
This is demonstrably false. Telegram's apps are open sourced (except Telegram X for some reason), same as Signal's (no exceptions). None of the two offer you their server's code.
> And who "rolled" the Signal protocol, Moxie Marlinspike? Did he not design that himself?
It passed the scrutiny of the best cryptographers out there. This comment provides more info: https://news.ycombinator.com/item?id=24237791
And again, this is completely irrelevant because even if Telegram's end-to-end encryption was absolutely the best there is, a) it doesn't work on group chats, and b) it's not enabled by default, only in Secret Chats. The vast majority of Telegram's usage is not end-to-end encrypted at all.
Signal server source code:
https://github.com/signalapp/Signal-Server
"The vast majority of Telegram's usage is not end-to-end encrypted at all."
This. This is the backdoor right here. It was never going to be shady flaw in the implementation. It's SO much easier to put it out there in the open, spread misinformation about Telegram being at the forefront of privacy battle and silence all criticism (my links were shadowbanned on their subreddit), and to attack straw men like people posting example's of Telegram's bad track record. tl;dr: damage control.
The open source Telegram client tells us
1. That E2EE is not enabled by default
2. That E2EE is not available at all for group chats
3. That E2EE is not available at all for desktop clients.
So just. No.
"Are you a cryptographer?"
Here's the world's most famous cryptographer, Bruce Schneier saying don't use Telegram: https://www.schneier.com/blog/archives/2016/06/comparing_mes...
Here's the world's second most famous cryptographer, Matthew Green saying don't use Telegram https://twitter.com/matthew_d_green/status/72642891296898252...
Now show me the cryptographer who recommends Telegram. You can't. Because there isn't _any_.
"And who "rolled" the Signal protocol, Moxie Marlinspike? Did he not design that himself?"
No, it was co-authored with Trevor Perrin[1] who is a cryptographer.
[1] https://twitter.com/trevp__
Telegram's encryption OTOH was designed by Nikolai Durov who is not a cryptographer, but a geometrician. That's like asking a gynecologist to perform brain surgery, lol.
Don't depend on asking someone else's device to delete the data as that data being gone.
But as far as I know Telegram has no equivalent feature.
Ammendment to my above statement: This does not apply to Signal.
Why can't they look at the TCP headers of incoming packets to determine source-IP? Also, why can't they look at session identifier or signal ID like phone number to determine who the sender is?
> All compatible Android devices newly launching with Android Q are required to encrypt user data, with no exceptions.
Unless the OS+HW provide API for some sort of TPM, it's not possible to provide strong protection for app databases without asking for strong password every time the app is opened. Android has had some sort of sandboxing for a while but it's not comparable to secure enclaves etc. AFAIK.