Many Telegram users are away of it's quirks and how it operates differently to other IMs. Any tool will do damage in the hands of a bad workman.
A good way to infer Telegram is reliable is how many despotic tyrants and corrupt countries ban it.
That's false. Encrypted messages aren't searchable by third-parties. End-to-end encrypted messages are searchable by only the communicating parties regardless of where they're stored.
There's also the issue of mirroring by third-parties, but then we're talking about data in transit versus at rest, your backup methods, and so forth. (And I don't have time to get into that this morning.)
Telegram is used a lot in developing countries which are using phones made 3-7 years ago. Or phones that are made recently but with old chips and tech. Maintaining a search index across literally millions or billions (some groups are really really big) messages isn't something your phone can reasonably do.
I do wish telegram was e2ee for IMs, but for groups and super groups and channels I don't particularly care.
Of course there are people who are much more popular than me, so it might be possible and I am not aware of it. :)
https://t.me/durovschat Has 9500 members
https://t.me/swhkdemocracy Has 6000 members
https://t.me/linux_group Has 6000 members
https://t.me/PublicTestGroup Has 18000 members
There is no limit to joining these chats. These design decisions Telegram has picked has allowed the app to be quasi social media, rather than just IM. You can't index these and maintain chat history locally. You'd need way more bandwidth and energy and computational power than the average cellphone has.
Pretty much what I said.
No, this only tells you that it's used en mass in those countries.
E.g. Whatsapp has now taken the place of telegram in Iran but it's still not banned. Despite literally everyone using it.
Whatsapp didn't win many users, even when Telegram was banned in Russia for months.
Telegram even worked in Belarus despite the whole internet shutting down there. [3]
[1] - https://techcrunch.com/2016/07/19/whatsapp-blocked-in-brazil...
[2] - https://www.theverge.com/2015/12/17/10386776/brazil-whatsapp...
[3] - https://www.latimes.com/world-nation/story/2020-08-21/telegr...
That's probably true, but a significant proportion of users are not, and do not realize that their chats are not encrypted. It's no surprise either, given that security is one of the core things that Telegram markets itself on -- unfairly so, in my opinion.
Source: https://discovery.ucl.ac.uk/id/eprint/1560501/1/Abu-Salma%20...
Refer this video from computerphile for more details. Start watching from 5:24. https://youtu.be/Q0_lcKrUdWg
Which discusses how Telegram was banned in many countries for refusing cooperation while WhatsApp suspiciously was never banned, which could mean that WhatsApp gives governments everything they demand.
WhatsApp had perfectly usable encrypted backup - which took up space on your Google backup. And then, all of a sudden, it wasn't encrypted and didn't take up space. But you don't have access to it yourself - only Google does (and WhatsApp if it is recovering). This is a perfect way to provide all the data to various governments for 99.9% of users, without killing the E2E encryption.
WhatsApp backup in iCloud is not encrypted.
Anyways, something like 6 months after launch a Russian guy found that they were seeding their secret chat keys with entropy from the server, meaning the server could trivially MITM any secret chat. Pretty embarrassing.
Iirc it got quite little publicity since most of the discussion was in Russian, and the disclosure was in a forum post in an obscure forum.
You aren’t going to find any cryptographers anywhere who’d be willing to repeat your “They didn’t backdoor it” lie.
If it looks like a backdoor, swims like a backdoor, quacks like a backdoor, then it probably is a backdoor.
FiloSottile described it as “The most backdoor-looking bug I’ve ever seen” https://twitter.com/filosottile/status/987376021589692416?s=...
Do you have any recent bugs? Or 'backdoors'? All their official apps are open source and reproducible. Must be easy to find bugs for security researchers. They even offer much larger bounties compared to other apps.
Anything? I want to believe people saying bad crypto, but it looks like there's no actual proof.
Here's something that says it is good, published more recently.
https://web.archive.org/web/20180727070936/https://www.susan...
https://kryptera.se/assets/uploads/2015/12/Telegram-cryptana...
> Or 'backdoors'?
You might argue that their deliberate decision to not encrypt most chats is exactly that, more of a front door really.
Telegram is a bad actor.
Telegram's a down-right bad IM experience compared to WhatsApp despite Facebook's forced integration: You see ads and the chats aren't encrypted.
This is essentially the Google model. Your search queries and browsing history (and Android and Chrome) are essential to targeted ads shown on every website "the webmasters choose to enable them on".
What? Google uses all your info for creepy personalized ads. Telegram is showing the same ads to everyone in a channel. And it isn't in 1:1 chats cuz they're supposed to be non-intrusive and gives a feeling of privacy.
Who is the 'maintainer'? Telegram is the only entity here.
https://gizmodo.com/the-dangers-of-techs-privacy-promises-18...
How? Google has all the whatsapp chats via the drive backups which 98% of users enable. fake E2EE
Telegram has an open API, alternative clients and free cloud storage.
They explain very well why they didn't want to give misleading e2ee claims like whatsapp https://telegra.ph/Why-Isnt-Telegram-End-to-End-Encrypted-by...
It is open source.
In addition 100% of Telegram traffic is encrypted over the wire (like this website, your bank, etc). The only difference with secret chats is that they're end to end encrypted.
Signal is a very bad user experience if you use several devices (phone, tablet, home computer, work computer). Continuing a chat on a different device doesn't work nearly as well as on Telegram where it's flawless.
I'd say forcing me to type on a shitty tiny on-screen keyboard (or use a _browser_ while still keeping the network on my phone running) is such a terrible experience that literally everything else wins in comparison to this.
I think you do realise that WhatsApp uses E2E and there's no way to do it any more securely unless the messages always go through your phone; and so, I believe you have already made a choice to use insecure services because "convenience", but in the context of current discussion (privacy and security), WhatsApp comes out superior despite Facebook's involvement. And that's saying something.
This isn't just misleading but actually plain wrong.
Unless you want to tell my your internet banking is unencrypted too ;-)
Edit: as seen downthread there a number of ways to make this more or less correct, but as it stand, and particularly with the "at all" at the end of one of the claims it is just plain wrong.
> Telegram can see most of your messages.
This part is technically correct however. Telegram says they taken steps to prevent rouge admins from seing it and to prevent themselves from being able to produce copies for governments, however there's no way for us to know if it was true then, if it is true now, if it is true in the future or at any point in between so worthless if you don't trust them.
If this is a problem for you generally I recommend stop using email, stop sending letters etc and rely only on Signal or Matrix.
For many of us however this is acceptable: we send letters or even post cards fully unencrypted fully aware that they might be read.
We send mails fully aware that it can be read at any server from we send it to the one the recipient download it from.
But for some reason the same level of security is deeply problematic when Telegram is mentioned.
Besides, here is what I replied to:
> As a reminder, Telegram groups are not encrypted at all[...]
(emphasis mine)
This is very possible to misunderstand for someone who isn't aware and the result might easily be that they stay in their abusive relationship with WhatsApp because of such FUD.
As can probably be seen from my comment history I'm no stranger to criticizing Telegram but we should stick to the facts.
Facts matter.
Let me use an example:
Would you want to ride the absolutely bulletproof and soundproof taxi that has one disadvantage: that it is well known that the drivers make notes about who you are and who you visit and sell that data to companies like Cambridge Analytica?
Or would you take another more ordinary taxi that might not be armoured and soundproof and might or might not log your visits - but at least no one has caught them red handed?
The answer depends on who you are I guess: [edit: if your main fear is that someone might be listening to your conversations and you don't care if the known shady taxi company logs who you visit, go with armoured, bulletproof taxi. I admit] there are times when E2E is a massive difference but for me this is mostly about preventing future Cambridge Analytica situations.
there are times when bulletproof is important and in such cases you absolutely should go for it.
But most of the time and most places it is just a giant waste.