Telegram's protocol... is not that.
[1] https://www.schneier.com/blog/archives/2016/06/comparing_mes...
[2] https://twitter.com/matthew_d_green/status/72642891296898252...
But yes, not having encryption on by default speaks poorly of them. OTOH it’s not concrete proof that the encryption still sucks as of now.
Also, Signal has no upper group size limit but E2EE would make group with 100,000s a bit sluggish. But that's a problem that reduces with Moore's law.
The world's best audit of Telegram would make the following obvious findings:
1. It's not E2EE by default therefore it's not private and secure by default.
2. It's not E2EE at all for groups therefore it's not safe for use of dissident groups
3. It's not E2EE at all for desktop clients therefore it's not practical in daily messaging.
Any audit of the E2EE part is meaningless when E2EE is so impractical it's not used by users at all.