Building a chat service with server-side chat history but without E2EE is like building a car with very nice headlights that doesn't actually move.
https://support.signal.org/hc/en-us/articles/360007059752-Ba...
Not being on by default has an impact on other things, that the users value more. If they were on by default, they would lose it and Telegram would lose part of its appeal. This way, users themselves can choose the trade-off they are happy with.
Privacy is a human right; it shouldn't be part of any "trade-off", just like you can't sell yourself into slavery, even if you really wanted to.
Yet, there we are. People value that other functionality more. You may not like it, but that's how they are.
> Privacy is a human right; it shouldn't be part of any "trade-off", just like you can't sell yourself into slavery, even if you really wanted to.
You are now off the rails. The problem with the trade-offs is not social.
I've once listened to a presentation given by someone from the company behind AdBlock Plus. They were explaining their (back then) new "Acceptable Ads" program and how an overwhelming amount of users chose to let the program enabled.
They even had a pie chart showing over 90% participation in the acceptable ads program and interpreted it as user choice. ("That's how they are")
After the presentation I asked whether they've tested how many users actively enable Acceptable Ads participation in the settings if it's off by default. To noones surprise they did not run such a test.
Not changing the defaults should not be interpreted as user choice if the same settings end-state is not reproducible with other defaults.
Usually any default, no matter how hostile, stays set. The reality is that users can be nudged easily and rarely ever change any settings at all.
This is about that one functionality being mutually exclusive with other functionality. If you enable E2EE, you disable cloud sync/history, multi-device use, message forwarding, etc. In normal use, users want the latter and if they need the secret chat, it is available.
In your example with Adblock Plus, there was no trade-off (to the user; there obviously was for the company). With Telegram, there is.
That is a design decision made by Telegram. My e2ee Signal and Matrix groups sync just fine across devices, preserve message history, allow message forwarding, etc.
Not enabeling those features is a nudge against using the e2ee-feature. Facebook Messenger does the same by crippling their encrypted chat experience.
The reason most people on WhatsApp enable unencrypted cloud backups is not because they really desire their message history to be leaked to Google/Apple but because they get occasionally nudged by a popup to enable it.
Those nudges work. It does not matter whether it's a good or a bad action they nudge to make one central assumption about them: settings should not be interpreted as user choice if the results aren't tested against complementary nudges.
Signal does it relatively right; but the nuances are difficult to explain. Even here, on HN, it is difficult to explain the Telegram's tradeoffs, how would you explain that to common users?
> it is difficult to explain the Telegram's tradeoffs, how would you explain that to common users?
I think that serves as an additional indicator for the trade-off decision not being a conscious user choice.
I'm not sure many people would opt for unencrypted chat even if they fully understood those particular multi-device limitations you described.
"Telegram is not E2EE" is factually incorrect.
WhatsApp has E2EE however it ships your private keys to cloud storage by default. So it's even less secure than Telegram.