>e2ee in general does not have to have those drawbacks.
How come no other messenger simply copies telegrams feature but with e2e? Also what exactly is the point of e2e chats if every user that joins gets a key to decrypt the whole chat. Its completely useless "security".
Oh don't be so vague, go on and name one!
> How come no other messenger simply copies telegrams feature but with e2e?
I've been wondering the same thing, especially for something as young as Matrix that didn't (at the time Telegram was already good) have a decent client themselves yet.
I've also been thinking myself of doing exactly that, but then it's basically a full-time job to get something halfway decent. People worked on reverse engineering a server at all, not an encrypted server but just any working self-hostable server at all. I don't remember the repository name but it's on GitHub. Even this was abandoned because it's just a ton of work that very few people are going to use. Additionally modifying the clients to work with a different protocol is even more work.
So I can see why people aren't doing this because I'm one of them, but yeah what I don't get is why the folks at Signal/Matrix/Threema/etc. would rather start from scratch than do this.
It might be easier to have some sort of plugin that overlays encryption on top of Telegram and uses the existing servers. On F-Droid there's this project called OverSec <https://f-droid.org/en/packages/io.oversec.one/> that I've been meaning to try, though presumably it hooks on an input field level and so it couldn't decrypt images before decrypting so it's not a full solution. You'd need to really modify the client (every one of them) and everyone needs to use your custom clients.
See my reply above.
>I've been wondering the same thing...
Its not possible (or feasible) to implement the key telegram features in Matrix or other always-e2ee protocols.
>It might be easier to have some sort of plugin that overlays encryption on top of Telegram [...] and everyone needs to use your custom clients.
Its against the telegram api ToS. You are not allowed to implement features that require other parties to download your client. You can only add local features that do not affect other user who use the official client.
>See my reply above.
Yeah I saw that. You wrote:
> Not even gonna read it all Have a nice day and keep using whatever you want
so I don't see why I should bother trying to answer your question as well.
I tried to explain it but people like you dont want to know. You just want to argue over e2ee nonsense that no one cares about who uses telegram for public conversations. You could ask HN to make comments e2ee its about that "useful" for what I use telegram for. I want my messages to be read, its that simple.
Which feature?
>clearly explained in their FAQ why they made it.
They absolutely did not.
>How come no other messenger simply copies telegrams feature but with e2e?
Which feature isn't being copied? Signal just implemented effin stickers with end-to-end encryption.
>Also what exactly is the point of e2e chats if every user that joins gets a key to decrypt the whole chat.
Firstly, new users in e.g. Signal groups don't get access to group message history. Secondly, overwhelming majority of Signal groups are not public. Your claim that E2EE in groups is useless assumes anyone can join any group. That's not the case, therefore your argument is completely baseless and thoughtless.
Almost all. Either not possible or not useful. Telegram has huge public community. People need to be able to join/leave and forward stuff to other places etc. etc. It just makes no sense to add any e2ee to that. Even in normal groups the default is that any user can add someone so the new user would need to get the decryption key on invite. Then you have bots that need to be able to read messages so they need the key too. Then you have cloud search so telegram itself need the key as well. Its just completely nonsensical at that point even if it somehow would be possible to implement it.
>They absolutely did not.
https://telegram.org/faq#q-why-not-just-make-all-chats-39sec... I have no trouble understanding it. You may not like it but its clear and easy to understand.
>Which feature isn't being copied?
All the ones that are not possible with e2ee.
>Signal just implemented effin stickers with end-to-end encryption.
Yes, and its an anti-feature for most people. People dont care if a sticker is e2e encrypted send to a chat. But what user care about is how fast it is, how much data it uses and how much it drains the battery. Telegram easily wins all of this because it does not e2e encrypt stickers, instead they are stored in the telegram cloud and the message only contains a file_id for the other user to load the sticker (once, then it is cached locally)
>Firstly, new users in e.g. Signal groups don't get access to group message history.
More anti-features, normal user want a new user in chat to be able to read the history. (If not telegram allows it to be disabled)
>overwhelming majority of Signal groups are not public.
How is that relevant. Use cases are different. I use telegram almost exclusively for public stuff or semi-public stuff. Maybe this is the problem here. You dont use telegram and dont know that it is way more than a messenger. Its more like a social media platform.
"I dont want or use any of that (you, probably?)" Fine, stick with what you use but dont tell me everything telegram does could/should be done with e2ee. Its absurd and nonsensical. It would be like making twitter completely e2ee rather than just give the user and secure e2ee DM option. Which is what telegram did. You have the option for e2ee one-on-one chats if you actually need it. Ive used it a few time like to send someone a password or a private document. But for the most part I have no use for it.
Signal has group invite links.
>Then you have bots that need to be able to read messages so they need the key too.
Signal has bots.
>Then you have cloud search
What you have is search, and Signal has search too, for the local message log. Telegram's log search lacks partial and wildcard searches. It's extremely inferior. Also, Telegram's cloud search gets extremely slow if you try to find anything older than few months.
>You may not like it but its clear and easy to understand.
It doesn't explain why they can't implement E2EE for normal group chats from technical PoV. Neither does Durov's blog post.
> But what user care about is how fast it is
What's the difference? Give me numbers
>how much data it uses
What's the difference?
>how much it drains the battery
What's the difference?
How about some nice facts and sources?
I think it's cute you try to label every secure feature an anti-feature, without understanding security is the fundamental attribute of every feature. You wouldn't use a feature that leaked the content to your worst enemy, why would you upload it to server that when hacked, allows your worst enemy to read it?
>I use telegram almost exclusively for public stuff or semi-public stuff.
Sure, if you personally have nothing to hide, you're welcome to use Palringo (that AFAIK still pushes everything over HTTP) for all I care. Just don't enforce your privileged threat model to anyone else.
>Its absurd and nonsensical
You're in a conversation about security of Telegram. If you don't give a shit about security, go, enjoy your life. Why did you bother come here to brag about your privileged life that doesn't have to be concerned with security?
> It would be like making twitter completely e2ee
That's bullshit. Twitter doesn't e.g. have groups that would enjoy expectation of privacy. Twitter is also not a messaging app, it's a social media, moreover, it's a micro-blogging site. It's content is intended to be public. Sure, the direct messages should probably use opportunistic E2EE, but its not exactly advocating itself as "heavily encrypted", it doesn't IMO have to be.
>You have the option for e2ee one-on-one chats if you actually need it.
No I want E2EE for my group of 10 close friends. I don't want E2EE for 2000 member super groups. And the problem literally is, I don't have the option for E2EE 1:1 chats, they're N O T available for Linux desktop I use. We don't actually have the option. What Telegram has, is a sad excuse of E2EE 1:1 chats on limited platforms, which only functions in online debates. Telegram does NOT have E2EE in practice. If it had, I'd be having my chats on Telegram instead of Signal, and wouldn't have to raise awareness on the issue.