Telegram: Payments 2.0, Scheduled Voice Chats, New Web Versions
telegram.org
telegram.org
They claim this is improved privacy but it doesn't look like that to me. Instead of my transaction being between myself and a merchant it's me, the merchant, and Telegram. Furthermore, Telegram can now aggregate all my purchases and info across multiple merchants (and whatever else I do).
They say they store, "no payment information" but that's really only a small part of any given transaction. They may still record what you bought and how much it cost along with when it was purchased. All the, "no payment information" claim means is that they're not storing your credit card/account numbers.
An underlying premise is that a user may have an established trust in Telegram and their services, perhaps more trust than the merchant.
It is completely possible to replicate this function of Telegram ourselves with ordinary web technologies and service providers.
Not to mention Telegram is transparent in letting your data out of its ecosystem (at least for now).
Provide that we still have the freedom to host any online service as website or an app on App Store / Play Store, I nelieve we will never decay into the dystopian state that is WeChat.
TLDR: WeChat is way more evil than Telegram, even Facebook.
unlike whatsapp, wechat also does not require me to share my phone number. (at least, for the brief time that i tried whatsapp, i could not find a way to hide my number)
wechat also doesn't announce to everyone who happens to have my phonenumber, that i am now on wechat.
wechat lets me control how people can contact me. the default is that people need to ask for my permission before they can add me as contacts and talk to me.
miniapps are just fancy websites designed to display inside wechat, with easy access to my wechat id. but they actually have to ask permissions if they want to use that id for anything.
a vender being only on wechat is no different than a vendor being only on facebook. or on telegram. it's simply a result of market dominance. not good, but not evil either.
there is only one dark pattern that i noticed, that is it is no easy way to export all the content stored inside wechat.
the only reason i need to be on wechat is to keep in touch with friends. the same would be true elsewhere where some people are only on facebook/whatsapp. (there are some facebook only groups that i would like to join too)
wechat payment is convenient, but there are alternatives. and cash still works (online shopping also works directly with a bank account). i managed to avoid wechat for the greater part of a decade here, until i was no longer able to avoid it because i was locked out of to many contacts who were only on wechat.
Doesn't WeChat in China require users to sign up with their national ID?
the national id is not required as far as i know, because then foreigners would not be able to sign up
Unless you try to export a secret chat from an non-rooted Android phone or a non-jailbroken iPhone. The app not only lack a feature for that but also prevents it from being backup-up -- which is a shame as an offline, adb-based, backup is the safest way of getting data out of aff on Android, IMHO.
Even if they don't want it, they have to. You either become a superapp, or users will flee to other superapps.
>Instead of my transaction being between myself and a merchant it's me, the merchant, and Telegram.
Don't forget about payment processor. That's where data aggregation takes place.
In case of chat apps, payments are IMHO one of the most natural chat app features and won't get debundled - the main point is to be able to send money as a chat message.
There are unbundled payment solutions using phone numbers as user handles like Revolut (that's what I used up until now), but there's still friction in using it to pay back to my girlfriend or send lunch money to the colleague who paid.
Consider ICQ that was really well loved until they bloated it with unnecessary crap. Same with MSN messenger. I think this will happen here too.
WeChat just works because the whole government is pushing for it and because privacy is just not a thing in China.
Telegram lives on big communities where in many of them trading is already a fact, making it easier to do in app is just another useful feature to then, not something pushing away (or that you are forced to use).
Plus, nowadays there are so many ways to send money, that if you don't like one, you can just decide to go with another path
The problem I see is that in order to promote such features, apps often want to ensure that all users are able to use it. So they would force ID requirements on users so they don't have to do this the first time they receive money. This is what I'm worried about. I don't want my chat apps to have my ID on file because I'm sure this will be used for tracking as well, could possibly be leaked etc.
Here in Europe all money sending/receiving apps now require a photo of passport etc due to money laundering laws. Which is fine for a money sending app, but not if I just want to chat :)
the key issue with digital payments is to verify the payer and the payee. the nice thing about having that built into wechat or telegram is that most payers or payees are already verified because i am already in contact with them
The part about a transaction being between you and a merchant is true only if you use cash and only if you physically buy something with a physical receipt or no receipt. If you use any digital payments, then the transaction metadata is known to several parties (beyond your card issuer and the merchant’s bank). If you buy something online, usually your email provider also has access to your entire purchase history.
So the main question is whether you trust Telegram more or less than your email provider and/or all the parties who get your transaction data.
edit: Links for those interested
On a second note, I'm surprised that both the new web versions are so similar. Seems just a couple of margins changed and other minor changes (profile picture filling the background vs being a centered circle for example), but built differently. Wonder if they both worked towards the same design maybe?
Edit: found explanations to the multiple-codebases behavior further down: https://news.ycombinator.com/item?id=26943653
webz.telegram.org and webk.telegram.org look amazing.
That's web apps done right. Small .js files intead of 20MB main.min.js crap.
The competitive angle is really delivering a fast/snappy/responsive experience on mobile or desktop. That in itself isn't going to save you, but it is an advantage if part of the sell is a high quality experience.
Re:interesting, for instance I just started experimenting with inlining all css/js into index.html (so far the js part is problematic), minifying classnames, and I'm curious if it'd be possible to even minify js module names etc.
Later I think they absorbed the X features into the core app.
I can't decide if I think it's an awesome strategy to launch a self-competing project, or if it just leads to terrible internal issues. I'm leaning more towards the former--I'm a huge believer in the instructive power of contrast, and it's a lot "safer" to contrast against another one of your own products than a competitor. You control much more of the "experiment", and you don't run the risk of cannibalizing your own users.
Plus, from an engineering standpoint, it forces you to have portable technologies and configs, and probably gives your team opportunities to learn from greenfield stuff that can then encourage refactors or other paying-down-tech-debt activities.
It's also just dang impressive that they're able to spin up multiple versions of the same app, and deploy them, and maintain them. That speaks volumes to me about their internal systems, build systems, resource allocation, etc.
AFAIK this is the main documentation page: https://core.telegram.org/bots/api which, subjectively speaking is really hard to read, and, objectively speaking, offers no sample responses/interactivity.
This page tries to fill the gap on tutorials/how-to: https://core.telegram.org/bots but without sample code.
There are a few bots you can find on GitHub, but nothing official that I could find.
Documentation on bot limitations in channels vs. groups is also really spotty.
Trying to detect who joined a group/channel and greet them, for example, or trying to send a message on departure, is non-trivial.
There's also wrappers for many languages that will have auto-documentation on IDEs like IntelliJ and usage examples.
What I really dislike is Telegram's avoidance of E2EE. Very sketchy.
curl -X POST \ -H 'Content-Type: application/json' \ -d '{"chat_id": "123456789", "text": "This is a test from curl", "disable_notification": true}' \ https://api.telegram.org/bot$TELEGRAM_BOT_TOKEN/sendMessage
I even have a MotionEye cam send me little videos when it detects motion. Telegram is amazing for this.
And it's FAST.
Really good engineers they got over there.
Signal is all about privacy. It trumps everything else. There are no "mainstream" payment options that align with their privacy requirements.
It's not a 1:1 comparison. They both want to achieve the same goal(payment integration) buy have vastly different requirements.
I'm in the cryptocurrency space though I don't know too much about privacy coins. However, I've seen some abstracts of studies auditing the true privacy of Monero. Specifically, it can de-anonymize users who make multiple transactions to the same recipient due to its design.
Now, I haven't personally looked into Mobilecoin deeply, and am highly skeptical at the moment. But I do think there's a valid reason to shy away from Monero based on the above, or due to it still being PoW (which is environmentally unsustainable). Signal does seem to care about privacy, and perhaps ethics to some degree. Whether or not it's "proven" (in the sense of having a large number of people using it) is quite meaningless. I really like that the CEO of Mobilecoin, who has been active in engaging with various communities, has been getting a ton of very rigorous questions here in HN, and I don't think his responses have been illuminating enough to instil trust. But I don't think it's fair to write it off as a good choice either. Presumably, Signal has access to information about Mobilecoin that we don't (which is a bad smell for a cryptocurrency, but I do hope the information about who owns how much Mobilecoin becomes public soon enough).
I'm also very interested in what the implications of Signal being a non-profit are here. Are they required to publish information about their dealings?
As to Moxie's involvement in MobileCoin it does make sense that he would push for something that has a fast transaction time. I wish they were more open about what they were doing (AMA got canceled) but I understand they are trying to avoid legal pitfalls (like Telegram did originally). But it is still early so time will tell.
Strong disagree with this claim. Signal exposes your phone number to others when you chat. I can add random phone numbers to my address book and find out if those numbers are tied to a Signal account and get to the profile even. Telegram hides phone numbers by default and also has settings to prevent such enumeration, wherein you cannot know that I’m on Telegram by adding my number to your address book unless I also have your number in my address book.
Now they seem to be diverging from that.
Telegrams selling point was a better WhatsApp, and IIRC this started back when WhatsApp was still unencrypted (yes, not point-to-point encrypted but unencrypted).
Since then they've always taken the lead over WhatsApp everywhere except on E2E-encryption.
That's the difference IMO.
There is 0 evidence signal is diverging from being a secure messaging app. Are they adding non-chat related features? Yes. Are they making their app any less of a secure chat platform? Absolutely not.
I'm just explaining the backlash.
My pharmacist is on WhatsApp and it's nice to just shoot a message saying "Hey I'll be needing a refill on xyz, thanks". He is pretty into technology and trying new things out so not too surprising he had incorporated WhatsApp.
However here we already has support at pretty much every merchant for tapping to pay with phones or tapping with our credit/debit cards so I don't see a huge amount of benefits to this. For example the ordering of pizzas almost seems like it would just be easier on a website. Often when ordering pizza for the family we do things like getting half the pizza with 3 toppings and the other half with 3 different ones. This would start to get annoying to order from a bot.
So I am having a hard time finding use cases for the payment side of things in North America. I just can't think of many text based interactions I'd have with merchants that would be more ideal than using a website.
There's a background to the new web download, however: They've recently started blocking some channels with the message "This message can't be displayed on Telegram apps downloaded from the Google Play Store".
It's also new (and quite cool) to me that reproducible builds are apparently now a thing - the FOSS version of Telegram used to lag way behind the official one which made it pretty difficult to use.
Is that... normal? I've never seen IQ mentioned in a job posting, and it leaves a bad taste in my mouth. Doubly so considering that it's likely the CEO had a hand in writing it.
iMessage approach is to treat every conversation as a group chat between all the recipient devices and all of yours. There's another risk here, that Apple doesn't let the end user verify the list of devices the chat is encrypted for.
Which is to say, a perfect E2E experience isn't trivial to design, but you don't have to drop the ball completely.
In the first row of the "Why telegram?" section, right in the middle, it says:
> Private
> Telegram messages are heavily encrypted and can self-destruct
Basically they are amassing an enormous amount of personal data, chat logs, etc. while their marketing and the public opinion is still that "Telegram is secure". That's a disaster waiting for the company to be acquired or turn evil.
What do you even mean by this?
Group chats aren't E2E encrypted and there is no way to enable it for them. In contrast, standard one-to-one chats are also insecure but there is the alternative of using secret chats with E2E encryption (however, unlike Signal chats, they don't synchronize among devices).
Then write something about that instead.
As recent developments have shown there is so extremely much more to security than just E2E-encryption.
This is insane, comparing with little functionality of other apps that easily 'weigh' 200+MB.
*Depending on many factor that might not be true