1. Low volume during calls
2. The UI needs work.
Like for example, I click on my contact messages. To call that contact. I now have to select a ... menu item. Or once I start typing a message, the option to attach photos disappears.
1. Low volume during calls
2. The UI needs work.
Like for example, I click on my contact messages. To call that contact. I now have to select a ... menu item. Or once I start typing a message, the option to attach photos disappears.
Telegram can have the best privacy policy, but they can always read your messages. You have to trust Telegram to do the right thing. (Except those few who opt in to use encrypted chats.)
Compared to maybe-evil-in-the-future WhatsApp, default Telegram is already evil, because they have access to all communication right now. What do (or will) they do with all that data?
(Opt-in E2E - and only for 1-on-1 chats - is almost useless. Encryption should be the default.)
If your threat model includes WhatsApp/Telegram developers, you can't use WhatsApp but you can actually (carefully) use Telegram's E2E chats, because Telegram's client is an open-source app with reproducible builds. E2E in a closed-source app is useless, and all UX inconveniences of E2E are just "security theater".
Sure, open source WhatsApp would be better. However, we are comparing detectable potential backdoor with totally undetectable existing access to all non E2E chats on Telegram servers. Telegram developers can already see everything right now. (By the way, opt-in E2E encryption is almost useless. Encryption should be the default, and enabled for group chats too.)
Between these two options WhatsApp situation is clearly better.
- That backdoors are routinely detectable in closed-source applications. They are not just "not easily" detectable, they are impossible to detect without a good amount of luck, and even so, the knowledge about a new backdoor will come after years, after all of the damage was done. Numerous discovered RCEs in Windows, some of which laid there for more than a decade after being found, confirm this.
- That there are incentives for security researchers to routinely disassemble WhatsApp binary and provide results of their inspection to the public, and not just report to employers or use the knowledge about a Facebook-authored backdoor to blackmail Facebook. There are none.
If you discard these two assumptions, you can see that Telegram model is better because it gives users clear choice between passing data to Telegram (in exchange for chat sync) and using E2E, with strong guarantees of E2E that are backed by reproducible builds, not by trusting Facebook or "oh, but that would be a scandal". The "almost useless" E2E of Telegram (I don't see how it's almost useless, it's there, it's working, and it provides value for users) is better than the completely useless E2E of WhatsApp.
(But yeah, group chats have no option of E2E in Telegram, that sucks.)
- I'm not saying backdoors are "routinely" detectable, I'm simply saying it's possible to detect them. In contrast, we have zero possibility to find out if Telegram is doing something nasty with your chats. Telegram may well do it already, and we may never learn.
- Regarding the incentives - security researchers often disclose vulnerabilities to the public. Obviously they have the incentives to do it.
As for the optional nature of Telegram E2E encryption - Signal and WhatsApp successfully demonstrated it's possible to make E2E the default (and only) option. There's no competition here. I wonder what proportion of Telegram users understand the ramifications. Many people migrating from WhatsApp to Telegram probably don't.
I do use Signal when possible, but I find WhatsApp to be secure enough for my day to day messaging with friends and family.
I can't say the same about Telegram since it does not have E2E encryption on by default on all messages.
It doesn't make since to move away from one company for privacy reasons onto another company with even worse privacy.
2. I could have a hard time choosing between Signal and Telegram some days. With WhatsApp I know Facebook will do metadata analysis on my contacts and my conversations (possible even with E2E-encryption). They'll also upload some or all my messages unencrypted to Google if I or any of my contacts enable backups.
Does that explain it?
E2E is an insurance against:
* bugs
* rogue employee
* server vulnerabilities
* acquisitions (imagine Telegram being acquired by Facebook)
As for metadata analysis, I still fail to understand how is it comparable to Telegram having access to all messages.
IMHO Telegram has the best UI and UX of all other "family friendly" chat app.
I do agree on the Voice and Video calls that need more improvement.