I didn’t know that the described functionality even exists, and it is off on my phone. TG is one of the apps that implements 0 dark patterns, imo.
By comparison, whatsapp regularily tries to cloud-ize me by making a backup and re-enter my personal data. I just tap “never”, “done” once a month, but it is annoying af when it happens at the incoming call. It also forced users to enter a status (but there was a bug that allowed to enter empty one). And if you have a sim-less device, it is such pita to install it there. No updates will be available, ofc.
The reason why WhatsApp is more secure is simple: it uses e2ee for all chats, and consequently has issues with multudevice usage and chats syncing, while Telegram just stores all chats in its servers, sans so-called "Secure chats". (I'm yet to see one person who is using them to contact me)
As of source code... do you really need a source code if you can login with just your username/password and instantly see all your chats? For anyone who has some remote understanding of the matter it clearly tells that chat history is stored on servers without meaningful encryption and that server owner can access all chat history at will.
Personally I'd never bother to start a secret chat with a person that I don't trust enough anyway. Neither do I trust an e2e messenger that my country didn't even bother to "pucker" legally.
>users (wrongly) perceive it to be magically more secure
This is claimed often, but I'm yet to see these users. Do they really believe that, is it just tg opponent's agenda that became popular, or both?
I often see these users. Most tend to just blindly trust a vendor. Also, I recall a talk at a Secure Messaging Summit 2020 given by Nikolas Unger [1], where he referred to a study about this (mis)perception.
They do have access to the metadata, i.e. whom you messaged and when.
--
[0] https://techcrunch.com/2016/04/05/whatsapp-completes-end-to-...
I love Signal and all the work Moxie and his team have put into it and the protocol, so this isn't a diss to them, but just wondering what the disadvantages would be for someone just looking for an E2EE communication app.
One difference I suppose would be that Facebook would have all the message metadata; just not the contents.
Whatsapp still does E2E encryption. (Same as Signal) Facebook can't read your messages. (There's still the scenario of you getting a special version of the app with that functionality disabled of course) You can also enable notification for changed signatures, which I do see changing as people replace their phones.
Personally I use Telegram because they don't mind non-official clients like the FOSS builds. Whatsapp on the other hand is known to ban non-official clients. API access isn't available either unless you are a big corporate user, at which point you need a facebook ads account and cooperate with some API reseller... no joke lol.
I agree that closed source is harder to verify, but that’s not the same as insecure.
WhatsApp is end-to-end encrypted by default (using same protocol as Signal) and there’s no way to disable encryption.
On the other hand Telegram chats are by default unencrypted ... you have to specifically start a “Secret Chat” to benefit from end-to-end encryption.
As I have heard, Telegram is unencrypted by default. Both WhatsApp and Telegram are poor at making this 100% clear 100% of the time despite privacy being a major purpose of the apps. I'll admit I really haven't used telegram much but WhatsApp encourages backing up chats to cloud storage. WhatsApp also only provides a single alert that a contact's security code has changed. It also doesn't encourage verifying the security code on the initial contact. i.e if someone out of the blue contacts you on WhatsApp the only security is the phone number.