But let's not mistake ease of use for security
But what's different is that Telegram doesn't share your phone number to everyone on the same group chat.
Element is such a good alternative that the app store appears to be stubly demoting it in the search result, and never seem to show it as a related messaging client. Strange world we live in.
Edit: furthermore, Matrix tech both for the server and clients is entirely open source, and one can spin up its own network.
Also, 1) you generally don't need end-to-end encryption with people you're afraid to share your phone number to, and 2) Signal is already working on usernames.
I don't care if the chat is encrypted or not, if some malicious actor intercepts our plans for the bake-sale I think we can live with the consequences.
Also like 95% of my Telegram group chats moved over from IRC, which also had zero encryption. What we wanted was feature parity (moderation and bots).
The usernames are in the works.
>I don't care if the chat is encrypted or not, if some malicious actor intercepts our plans for the bake-sale I think we can live with the consequences.
Perhaps double check which historical figure said "you have nothing to fear if you have nothing to hide".
Sure, you have nothing to hide, but don't expect others to not have anything to hide either. And realize when you're only reachable over Telegram, that forces other people to reach you over Telegram.
>What we wanted was feature parity (moderation and bots).
That's totally understandable, apps like Signal do support both however. The way I see it, is Telegram's TLS equivalent group encryption is like upgrading your 1988 IRC to 1995 Telegram. That's how old client-server encryption is. E2EE for 1:1 IMs are introduced by OTR in 2004, and roughly 2013, we get E2EE group chats with Signal.
Does Signal have a bot API, where? Like an API specifically to create utility bots for Signal, not a client API that can be used/exploited to create bot-like users?
* It leaks 100% of messages to server by default.
* It leaks 100% of Win/Linux desktop chats with no chance to opt out
* It leaks 100% of group message content with no chance to opt out.
* It leaks 100% of metadata with no chance to opt out.
* It always leaks the intention to hide messages from telegram chats, Telegram knows with whom you are sending secret chats, it knows when, it knows the message size etc. This metadata is extremely valuable
Telegram is not in the process of fixing these, thus its security isn't reaching the bare minimum. Thus every feature it is implementing is another way for the company to collect data about you.
It's just another Facebook, masquerading itself as "private app for the people". It's run by the man who is literally called "The Mark Zuckerberg of Russia". That man has military education on information warfare / disinformation: He knows how to create a literal cult around his product.
There's almost nothing we know about the company like who it employs, how it makes money, what it does with its data. Journalists who tried to get an interview with Durov travelled to Dubai, only to find empty offices. The office workers next door said they had never seen anyone enter Telegram offices. They suspected Telegram was using the office for tax evasion, which is not a good sign. Telegram's been very enthusiastic about a story where they're evading foreign intelligence. If that's the threat model, why is their security strategy "store all messages on one server" (like the NSA et. al. didn't have zero day exploits);
The claims about how the data stored on servers is protected, are outright lies a first year computer science student whose taken Computer Organization 101 can disprove[0]
Telegram is a dumpster fire and I'd LOVE to be able to say it's security is getting better, but it's NOT. They just implemented group video calls, are those end-to-end encrypted? No, they f'n aren't. Not even NEW features in Telegram are secure by default. You know, the features no-one asked for, that they were in no rush to deploy. It's especially condemnable as the major competition like Zoom, Signal and Jitsi all have end-to-end encrypted group video chats. Telegram staff don't care about me, you or any other user one bit. The only thing they seem to be interested in is "move fast break things" or "move fast f** security".
No matter how you put it, Schneier is right when he says data is a toxic asset[1]. Telegram can't give any guarantees data that sits in their server is forever protected, so they shouldn't be collecting it in the first place. WhatsApp is in the process of deploying client-side encrypted cloud backups. This completely shreds Durov's BS claim that Telegram has to have access to your data. There can only be two reasons they collect it: Either they don't care about your security, or they are actually interested in your data.
[0] https://security.stackexchange.com/questions/238562/how-does...
[1] https://www.schneier.com/blog/archives/2016/03/data_is_a_tox...