Why Telegram had to follow Apple and Google when they suspended a voting app
telegra.ph
telegra.ph
> Second, this particular demand of the Russian authorities wasn't obviously unconstitutional, as they referred to a law that restricts campaigning after people start casting their votes. Laws against political campaigning while voting is underway exist in many countries and the Russian counterpart had been introduced a long time ago. Had we received a similar demand from any European country, we would have complied with it. On the contrary, had Russia or any other country demanded something that is in clear violation of human rights, we would rather face an outright ban of Telegram in that country than compromise our values.
The article does seem very reasonable, but I'd disagree that it's objective, since the author, Durov, runs Telegram and is writing to justify their actions.
They shared their decision making process which I agreed with, not too sure what would have been a better choice in that situation.
that's another way to say subjective if you aren't willing to admit it. the whole point of objective/subjective is that its supposed to be POV neutral.
What if the request came from the EU or the US, to ban an account that was campaigning in local elections in violation of local election finance laws?
Note that the ban is not even permanent! It's only for the last 2 days of the 3-day voting window. Campaigning was supposed to have been illegal throughout the whole 3-day period.
It doesn't make the content false just colored by the authors point of view.
Whether an app should block a bot/user when the app store blocks the bot app?
=> Whether an app / telegram with third party extension/bot ability would be considered as similar to an app store? => Whether a bot built on a private application ecosystem should be considered as an independent app?
It's basically the same law as in many other countries. The only difference is that citizens of most other countries don't dare to do these tricks, because there are severe consequences for playing with election integrity in the Western world. For example, look at what happened with Dinesh D'Souza when he tried donating to a campaign of a friend more than what the law allowed, using another friend as a lame duck to make the donation to avoid personal limits.
He knows he’s lying. Personally I think he’s found a common ground with Kremlin behind the scenes.
I'm pretty sure that'll play a part in it too. Easy thing to throw away 0.5% of your marketshare, another when it's 20%. Ps I made those numbers up :)
It seems very likely that Apple/Google is actually the problem here. I encourage everyone to download the app from the website or F-Droid not form Google.
The bot runs on someone else machine and telegram most likely just temporary disabled the token to disable the bot from communicating with the telegram bot API. This then ofc affects all front ends/apps.
Now it's disallowed starting from the voting day.
Is that not so?
especially when the only way to get the app is through a bunch of privately held "stores"
>Согласно закону, предвыборная агитация должна быть завершена в 00:00 по местному времени первого дня голосования.
And I love that Durov carefully says
> Telegram gives its users more freedom of speech than any other popular mobile application.
(emphasis added by me)
It doesn't count when you're too small for anyone to bother taking you to court.
Isn't voting right a human right? If people don't have right to fair elections then any other rights they might have aren't guaranteed either.
Let's start with the law application. If you want to apply it like that, you'd have to remove every single positive post about every single candidate from the entire Internet.
In case of Telegram it is even more bullshit because unlike web browsers which (in a common folk sense) show what is available to public and therefore could be compared to public advertisement like a billboard, Telegram bot will only respond to a direct question (yes, I know technically there's no difference).
There is no law in Russia which forces him to ban that channel, and no concept of “silent days” anymore.
Russian authorities has NEVER asked Telegram to remove anything. They pushed Google and Apple to remove links to Navalny application from search and from Apple Store (and Apple removes it only for Russia users, btw, unlike Telegram removes it for everyone), and Telegram was absolutely never in the picture and never asked to do a thing publicly. Just search Russian authorities speakers. They never bring Telegram into the picture.
Durov shamelessly lies. He pretends his application is a speech freedom, but it is not.
When there was a Telegram channel posting information about Belarus policemen who torture their own people — they ban it. When there is still a channel where white men posting personal details of women and attack them — no action.
Why Durov lies?
Because after SEC issued a claim that TON is a security and killed TON as a project, he owed ton of money to investors, including American. He had a real risk of being sued.
Where did he find money to pay investors back? He found them in Dubai, Qatar and Russia. He issued Telegram bonds and buyers of those bonds are affiliated with Russia structures like VTB Capital bank or Russian Government investment fund named “Russian Fund of Direct Investments”.
Moreover, few years ago, Russian authorities tried to ban Telegram. There was a massive campaign against the application, but then all things I mentioned happened, and SURPRISE Russia officially removed Telegram from the list of inappropriate applications and stoped attempts to ban it. Even now after the election, Russia published a list of websites whom they are going to ban because they didn’t stop spread of Navalny information. There WhatsApp and Viber in the list. But no Telegram.
For me it sounds very very directly: Durov lies. He takes money from Russia government to cover his costs from TON failure and in return he, for example, bans Navalny Telegram Bot even while he a) wasn’t asked; b) Apple and Google wasn’t asked to ask Telegram; c) law he mentioned doesn’t exist anymore.
There is no more free Telegram. Remove it now and stay safe
As far as i know, it's not true(meaning there are no signs/proof of that). It's entirely possible, durov does have connections in russian elite, after all he was the creator of vk.com russian most popular social network. Vk was owned by russian oligarchs most of it's life at least partly. At the end of durov involvement with vk, he had some harsh clashes with oligarchs/regime, but ended up making a deal(and got paid well, even if not as well as he should've been). So he certainly knows how to deal with them, but i seriously doubt he enjoyed it, so he must have been really desperate if he got in bed with them again.
The biggest promise of telegram was that it would become a point of entrance to a decentralized economy based on TON blockchain and it's masternode hosted services. If they succeed to launch and than move telegram itself onto ton masternode hosting, telegram would've become the greatest/freest/(and potentially most secure, if they would implement e2ee key synchronization) messaging service ever
End of TON project, ment an end of telegram's future as a not data harvesting company.
https://www.rbc.ru/business/23/03/2021/605a3fbc9a79470b2eb35...
They created a very elegant scheme when through a fictional Arabic investment fund they put russian government money (Government fund invests into Arabic fund which invests into bonds). It is kind of Russian classic and they did it a lot in the last.
Nowadays Telegram Bonds are traded at Saint-Petersburg stock exchange and there are a lot of rumors that Durov attends a lot of private parties in Russia for kids of oligarchs.
bonds being traded wherever they are traded isn't really a proof of anything as well, wouldn't be even if it was shares of a company, but as bonds it's not that much of an influence, especially if accumulating big share of them would cost a fortune.
As to rumors, i would love to see any of it, again it's entirely possible, after Telegram official's attendance of government pr public forum(will use the same source, but it was all over the internet https://www.rbc.ru/technology_and_media/09/07/2020/5f0730bf9... ) it would be surprising if telegram isn't dealing with them in any way.
The article does not really describe anything controversial or out of the ordinary.
I'm sure many countries do similar investments and arrangements. For example, IDA Ireland has offices in the US, and runs ads on Bloomberg TV. How's RDIF that much different?
Durov can ask any day of the month for a donation and I'll give it as soon as I have money in hand. $10 - $100, no problem, more in 6 months.
In fact even if he bust released a dumb sticker collection I'd buy it just to support Telegram even if I don't use stickers.
I guess this holds true for many other ex-Whatsapp enthusiasts as well.
Investments are a bit harder for me right now since I don't have capacity to do that right now.
But I think saying he has nowhere to go except data harvesting that shows you don't know how important Telegram is to how many people.
In my country, we use telegram to communicate, rather than WhatsApp or SMS. Older people might use Viber, but Viber is a total nightmare. Just having it installed, I get dozens of spam messages per week from shops where I’ve bought things.
SMS is very expensive here.
Comparing telegram to WhatsApp or other competing apps isn’t even worth doing - there is no other app as user friendly or as functional and well thought out as telegram. It’s niche features like scheduled messages are a Godsend.
During the events of Jan 6, I was very worried that Apple would pull TG from the App Store. Thankfully they didn’t, but it’s not white supremicist groups that they would be hurting - it’s ordinary young people in foreign countries.
Yes.
> what would be an average annual donation per user?
I don't know but if it was entirely voluntarily, somewhere between 0 and $10 yearly.
> I bet it would be a lot less than what big tech makes, and there is no reason to believe durov would settle for that
That doesn't seem to be Durovs goal.
completely disagree, he is definitely focused on making telegram some huge IT project that would put him on the same level as great IT entrepreneurs of our time. The whole TON project was all about making tons of money from becoming the main beneficiary from first decentralized consumer economy. It's a mystery how he is going to achieve anything similar now, but that goal was so ambitious, it's unlikely he will settle for something as small as this
let's use 2017 as a reference https://www.statista.com/statistics/268604/annual-revenue-of... https://www.statista.com/statistics/264810/number-of-monthly...
so it had an annual revenue of $20 per user, and your assumption is a mere $10 max(likely lower), that's extremely low for someone like Durov
He didn't have to pay back the TON investors because the deal included that if the network does not go live by a set date (and the reason isn't telegrams fault) he would return the remaining of the investment not the part used for the development. This is the risk the investors took and they lost. telegram itself only had to pay the sec fine which was peanuts for Durov.
Don't know anything about you other claims so I cant debunk but please post sources so we can check for our self.
Telegram remains the only mainstream free speech platform on the web today, with the least amount of censorship and the most resiliency against being taken down.
The law that prohibits campaigning during the election is still very much there, just like in many other countries, just not one day in advance like it used to be - this is debunked in the other thread - https://www.kommersant.ru/doc/4800223 Btw, strange you didn't quote any sources for your claim - just a claim.
> Russian authorities has NEVER asked Telegram to remove anything
Yes, he starts the article by saying "has to follow rules set by Apple and Google", so he is not even talking about the Russian authorities. Apple and Google have been well known for swiftly taking down the apps that they think are troublesome for them.
Finally, Telegram was a massive channel for Belarus protests - in fact, Telegram was probably the main coordination mechanism for those - have you ever heard about Nexta?
I’m not familiar with the situation you are referring to, but I’m curious why you specifically mentioned the race of these men. How is their race relevant?
Also that law is applicable to certified mass media like TV, radio, magazines, news papers e.t.c., but not social media, chats, apps, forums e.t.c.
- https://www.wired.com/story/telegram-encryption-whatsapp-set...
- https://portswigger.net/daily-swig/amp/multiple-encryption-f...
Also, the optional E2EE encryption is way more limited (e.g., single-device, rather than having a key sharing mechanism) than most other, possibly more genuine, alternatives (Matrix, Signal).
- https://telegram.org/faq#:~:text=Remember%20that%20Telegram%....
And they have no desire to switch from their Python based server.
The Python server is a memory hog, and instead of rewriting it in a more performant language they have decided to scale horizontally instead.
How is that feasible for the average guy who wants to run it on the their own server?
https://matrix.org/blog/2020/11/03/how-we-fixed-synapses-sca...
https://news.ycombinator.com/item?id=16747174
After a $30 million funding round we should be seeing a lot better from them in the next few years. That python server ought to go.
Dendrite is literally rewriting it in a more performant language
> How is that feasible for the average guy who wants to run it on the their own server?
The average guy likely doesn't host for thousands of people
The python server already has trouble if you subscribe to large rooms. I'm all for promoting Matrix (it's a great project), but the default server has warts and nobody is served by trying to hide them.
Seems you've mixed something up. Dendrite is a matrix.org project, just like Synapse. Conduit is written by Timo Kösters who is currently employed by Famedly and is on good terms with both matrix.org and Element staff. They frequently cooperate.
What I would really LOVE to see is just decentralized backends that can be accessed via a growing number of https gateways by a widget on any website, and used to sideload code that will run apps and update apps.
That will be an uncensorable app store (unless you censor all websites, or sniff all https packets and block ones that seem like they follow this protocol).
If only Apple/Google would allow us the ability to run our own notification servers…
That's not the same as a "wild west of free speech", though. I have no idea how well they do on the front of censorship, they're way too intransparent an organisation for that, but the USA also sees itself as such and it is not encrypted. Secure protocols and censorship are two separate things, even if one (in this day and age) helps the other.
What do you mean by that? When no new devices are introduced you only have to verify the fingerprint of each contact once (via QR code).
> Afaik it does not have any audit either
But you don't have to verify each contact once, but each session the contact uses
Here's my experience. I have three devices I use to connect to my XMPP server: phone (Conversations), PC and laptop (both gajim). Each one generates a keypair. I verified the public keys of PC and laptop by scanning a QR code using Conversations (phone). Conversations remembers all fingerprints as my own. Next time I meet a friend, they scan the QR code on my phone. They now have verified all three of my devices.
More recently, they've had egregious bugs such as images being sent to random contacts in your list, an absolutely inexcusable error.
Element and the Matrix protocol would disagree.
Anyway, no, this doesn’t reflect real usage.
the Matrix protocol is accessible to anyone understanding English and having access to the web.
It is even being worked on enabling P2P with Matrix, i.e. each client can spin up a local server that communicates with others (servers) via Bluetooth and other means of transports even if there is not a direct connection possible
see https://matrix.org/blog/2021/05/06/introducing-the-pinecone-...
Saying that it isn't is a bold claim to be backed up by proper arguments
> Signal is the most trusted app in authoritarian countries.
PS. Check the comment section of the tweet.
[1] https://twitter.com/signalapp/status/1293377583891980293?lan...
It looks to be like this particular telegram bot could have been a web site?
I am pretty sure the pressure will be given to the host and domain register.
Of course, such a block is easy to circumvent with a VPN, but if you need a VPN to access it then the service is essentially unavailable to non-techs, greatly reducing its effectiveness.
There is a website[0] and I don't know why they didn't just launch a similar web app. Running on Google's appspot.com, the website would probably be dealt with the same way the apps were dealt with. No big hosting company (Amazon, Google, OVH, you name it) wants to risk being banned from the Russian internet, after all. A TOR hidden service would probably survive attempts at censorship, but at that point the whole effort is probably not worth the effort because you're not reaching many people locking the information behind TOR.
But they can ask Apple and Google to ban it.
For instance the app could well function completely offline if it embedded the list of candidates it supports, it which case they'd have to block all requests to the Google Play Store which would be rather heavy handed and unpopular.
They have in the past blocked large swaths of AWS to block this app:
> Some users wish Telegram was 100% independent from everyone and could ignore Apple, Google and national laws of all countries. I also wish it was possible. But the reality we live in is different. I have warned the public many times of the danger that the Apple/Google duopoly poses for freedom of speech. And, as I wrote in August, the world is becoming more pro-censorship in general, with even democratic countries changing their definitions of free speech due to concerns of election interference from geopolitical rivals.
This is the main issue - BigTech have grown too big and have too much influence now on politics since the US decided to sub-contract intelligence gathering and surveillance to them (as Snowden revealed). The author is right that democratic countries are now increasingly becoming pro-censorship and have an anti-privacy attitude.
We should never support censorship or the erosion of privacy. Preservation of these two is essential for our democracy and freedom.
I was in the middle of an edit to add more commentary, and it failed. This hasn't ever happened to me on HN before.
Can a moderator explain what is going on or why I'm being targeted?
Edit button is completely gone on the above post. https://i.imgur.com/BnYuqx6.jpg
Right now it's 19 minutes old (and uneditable), yet I can still edit a different 27 minute old comment.
I crafted an edit URL for the post using its id, and I still can't edit it:
But I'm just guessing HN internals are p proprietary.
However, like you noticed, I do believe that some of my posts are targeted as part of the online marketing / "reputation management" that happens regularly all over the internet by BigTech. I am vocal about right to privacy, right to repair and need for government regulation of BigTech, and have noticed that if my posts on these subjects specifically mention Google, Apple, Microsoft or Amazon they are often downvoted (I once noticed a post go from 10 upvotes to 10 downvotes, in real-time, and that's when I realised what's happening).
(Anyway, HN doesn't like this kind of discussion as it doesn't add much value due to its speculative nature and it tends to distract us from the main topic.)
Occam's razor leads me to believe that it's organic behavior and not organized vote brigading. Perhaps employees or shareholders take opposition to negativity more frequently than not. Or maybe negative articles get posted on an internal company Slack and get extra attention.
I suppose they could hire a service that does the same as a form of brand management, but I'm more inclined to think that those in our profession have simply forgotten the importance of privacy and speech when they're being paid not to care.
More evidence of the problem plaguing our current era. These two companies simple should not be authorities above all local regulators.
Steve Jobs got us into this mess by trying to monopolize the iPhone processor (and only allowed the web to bootstrap his platform). Complete control can be strong armed by dictators, and our spineless capitalists will bend to their will.
The W3C needs to develop a standard for non-DOM, immediate mode painted, fully WASM apps that can access all of a device's hardware. Storage, cameras, network, GPS, multithreading, gyros, all of it. Native apps over web.
We need a web-based drive by app that we can run sandboxed and install without the Apple/Google duopoly, and the US, EU, and Asia need to mandate support.
Edit: downvoters, seriously, we need to talk. You're walking the evil line.
If you want, I'm sure you can cross-compile WASM into some kind of native application or even just leverage a WebView component to make your "app" an HTML page with just a <canvas>.
All of this is already possible today, and yet this problem still persists. Open access to your own hardware is important, but it doesn't solve political problems like these. Web applications can quickly be blocked by censors as China and Russia have shown. The technology arms race doesn't solve the political root cause of the problem.
They're also tightly controlled and taxed, which they shouldn't be.
Also I don't think that DOM presents any problem to security. It makes no sense to cut DOM or JS engine from your sandbox. You can use Canvas/WebGL/WebGPU to access GPU and draw anything in browser window. You can use WASM to have good speed. Tech is already there, you don't need W3C for it and DOM or JS is not really in the way. Storage, Cameras, GPS, Mulththreading, Gyros are available for web apps. Everything is already there.
Web apps miss notifications on Apple platform, home screen installation via API on Apple platform, better integration with OS on Apple platform (not sure about Android), but probably you want your password manager to be native app anyway.
I'm sure this voting app could've been a website, and I'm sure it was or could have been blocked in Russia.
Both of those clients blocked Smart Vote bot because my phone number is in Russia. At the same time all my non-Russian friends was able to freely use the bot all of the time.
The problem is that according to the recent federal law - campaigning ban does not apply in case when voting lasts for several days.
You can also find tons of other examples of Apple's influence making decisions about what large numbers of people can experience, often without even realizing it is Apple pulling the strings, whether it be content about drugs, guns, or the use of sweat shops in the manufacturing of smart phones (a category of app I find particularly egregious for Apple to be censoring as it is so self-serving).
The core problem is really that there is no alternative: if your app isn't allowed to be accepted by Apple, you simply don't get to address something like half of Americans with your product. Users generally don't own multiple phones and they can't take an extra trip to "visit" another phone for your product, so attempts to draw analogies to supermarkets or Walmart tend to be unhelpful.
It is more akin to a physical region of the country... imagine more as if all Apple users happened to live West of the Mississippi River or whatever and you weren't allowed to sell there because they had a monopoly, and for users to use your product they have to take on massive switching costs (of moving across the country).
This centralized bottleneck on software development and distribution then plays out in tons of ways, and tends to make Apple a patsy for local government interference. People like to claim "they have to follow local laws!"... but they didn't have to build a product that puts them in so much centralized control in the first place, as except for in the most authoritarian of regimes (such as North Korea) pretty much everywhere is ok with relatively open devices (such as computers or phones that support sideloading).
Apple has thereby made an active choice to build a product that is bad for democracy around the world (including here in the west!) in no small part because it makes them a ton more money than one that they would have less centralized control over (and thereby manage to charge their extreme overheads on all use cases for)... this profits before people approach should be familiar, as it is also similar to the playbook used by Big Oil and Big Tobacco.
And, as we see in situations like this, maybe that Google merely allows sideloading isn't sufficient, given how they actively discourage it with functionality barriers (alternative stores not supporting automatic updates), discouraging messaging (telling users that side loading is dangerous), complex activation paths (sometimes requiring switches in hidden developer-only settings panels), and even stronghanding users back into their happy path (such as with their anti-virus-like tool that tends to flag alternative stores as if some kind virus).
We need to stop allowing this sort of behavior. If a company is doing something that puts them in a situation where they are making decisions to support authoritarian regimes, we should not only be morally judging them--and of course this includes everyone who works at these companies on these products: you don't get some moral pass for "merely" being a foot soldier if you have the skills to take on another job--but maybe putting in place laws that prevent our companies from tolerating these kinds of decisions.
And again: this is not to say that "you are asking Apple to violate the laws of Russia" or "you are requiring Apple to not sell to Russia"... the laws in Russia or China or wherever we tend to be talking about when these issues come up do not make it illegal to sell a device that lets users install this software: Apple, and in a different (though I do think lesser, if only for being more indirect) way Google, have gone out of their way to build a product that puts them in that position.
(To the extent to which anyone finds any of these thoughts interesting, I gave a talk at Mozilla Privacy Lab back four years ago on "That's How You Get a Dystopia", citing numerous examples of how centralized systems lead directly to the problem of gatekeepers either themselves becoming corrupt over time or being forced to corrupt themselves to satisfy external pressures, with numerous concrete examples--every slide is a citation--across the entire industry. The saddest part is that it feels like I am constantly writing down new examples of the issue I could use to make this long talk even longer, as this is a never-ending problem.)
That's a good point, actually. If a company wants to claim that they are on the side of users and democracy, it needs to include in its threat modelling the possibility of "Are we the baddies?".
It feels like that's part of their business model. Apple (and Google) can have more business if they follow the dictates of dictators. Dictators can "buy" suppression of free speech from Apple/Google.
As this "puritanism" is an interest of mine, can you point me to some of that interesting stuff you had in mind, please?
From what I've found so far, I disagree with this interpretation. It's as if saying that publishing a list of people with their stances on a particular policy is the same as campaigning for them. It's not.
By this metric, a website like isidewith is campaigning, https://www.isidewith.com/, as are voting guides that help voters pick out candidates who back action on Climate Change, https://voteclimatepac.org/voters-guide/, or who are pro/anti-2A, https://www.nrapvf.org/grades/ / https://gunsensevoter.org/ . Are these campaigning as well?
Admittedly, the application differed from isidewith by focusing on a single issue - anti-totalitarianism, it did not do anything different that voteclimatepac, the NRA-PVF, Gun Sense Voter etc don't do. It was meant to match voters with candidates who already offer their preferred position - anti-totalitarianism. I don't see how this is campaigning.
Further, the app wasn't affiliated with most of the people it was recommending. While it was designed by Navalny, it recommended people across multiple parties. This fact weakens the argument even further.
Here is the app for you to judge for yourself, https://votesmart.appspot.com/ English translation: https://votesmart-appspot-com.translate.goog/?_x_tr_sl=auto&...
As you will see, it doesn't advocate for a party or a candidate, but across parties and candidates based on a single issue - anti-totalitarianism.
-
While Telegram has taken a stand against the Russian govt. in the past, I do not believe that past action is necessarily predictive of future results in this regard. Given that the new Kremlin, in particular, is famous for bringing its opposition under their thumbs and turning them into controlled opposition.
> With a flourish he sponsored lavish arts festivals for the most provocative modern artists in Moscow, then supported Orthodox fundamentalists, dressed all in black and carrying crosses, who in turn attacked the modern-art exhibitions. The Kremlin’s idea is to own all forms of political discourse, to not let any independent movements develop outside of its walls. Its Moscow can feel like an oligarchy in the morning and a democracy in the afternoon, a monarchy for dinner and a totalitarian state by bedtime.
https://www.theatlantic.com/international/archive/2014/11/hi...
This assertion may seem conspiratorial. And it is. Though not guaranteed, it is well within the realm of possibility that the state leader bred by the KGB found ways to turn the screws on M. Durov to keep his hold on power. Given that he kills regularly for it. Should we consider it unlikely that he's willing to coerce others for it?
I guess I'd want to let them know, but how..
They have two options:
1. Find a way around relying on Apple and Google's blessings
2. Make it technically impossible for themselves to ban someone like this again
The same rules apply to any other app on the stores. No technical solution (encryption or whatever) would make this go away.
So you can't sell a web browser that can access illegal copyright infringing adult content?
I think they should remove all browsers then.
Also everyone knows that browsers are excluded form most of these store rules because reasons. Browsers dont have to pay a fee for ads shown either for obvious reasons.
BTW you can use web.telegram.org to circumvent apple blocked content on telegram because this runs in a browser they dont have to comply with app store rules (for now). And you can use F-Droids Telegram Fork or the APK form telegram.org to circumvent googles blocked content.
In case of a bot that is turned off however this does not help because its turned off at the backed.
That's not completely true. The bots are basically like web servers.
Please don't start a "telegram is not encrypted by default" shitstorm like in every other comment section about anything related to Telegram.
Probably ends up at the nsa though. But I care more about not being a product of Google.
Its weak point were the backups. They were encrypted but the key was with WhatsApp and the data with Google or Apple. All a friendly secret government request away. Of course you can turn off backups but you don't know whether everyone in your group does.
However they have recently started to shore this up too. You can now choose to keep the key yourself. Of course you still don't know whether everyone in your chat group does this.. But even the alternative password method is much safer than before. According to FB it's stored in a HSM. Yes, we have to take their word for it. But if you use the numeric key only you will have it (and thus no way to recover the data which is a normal consequence of good encryption)
WhatsApp still leaks data for sure. Like all your contacts (even non WhatsApp users), and all your metadata, like when you're talking to whom.
But the content is pretty safe there IMO. Surprisingly so for Facebook. I don't like using it very much either but I'm Europe we simply don't have a choice. I limit its access to my contacts and photos by running it inside a 'work profile' on Android.
Messenger is a different story of course.
For closed (invite only) group chats and 1:1 chats I think it should be encrypted by default though. Like WA and Signal. There's the secret chats of course but they only work on one device and not on group chats. Of course key management is hard in those cases but the others have worked around this very well.
I agree that encryption issue doesn't really have any bearing on this bot ban though. This thing wasn't really about surveillance. But the best way to make this appear in the comments is Telegram fixing it :)
Edit: FWIW I really like Telegram because they're open to integration with other networks (eg Matrix) and that they actually allow and embrace bots. But it would be so much better if they did have E2E.
I hope that their implementation will stay as it is. I'm all for implementing better security for ordinary chats, but they should keep secret chats feature as a restricted high-security channel.
And if a security feature has so many drawbacks that nobody uses it, you end up with less security. I'd rather have a flawed E2E implementation than one that is not used at all. For example I recently sent passwords to our Makerspace users in secret chats but half of them didn't see them because they were either on another device or they weren't online (also seems to be a requirement for secret chats). So many of them asked to 'stop being difficult' and send them in a normal chat. This is what I mean. And those people are mostly geeks. If they give up on it, what will normal people do?
If it's not seamless enough, only us crypto geeks will use it and the rest will roll their eyes. It has to work for grandma just as easy as it does for us. And Signal and WhatsApp do really pull that off.
I agree that backups were WhatsApp's weak spot but they are making some good modifications that allow users to store the key themselves.
It would help if the key management could be checked though.. I totally agree with you there. Right now it's not transparent enough, even for those of us who know what they're doing it's not really possible to check with WhatsApp. Signal is another story as it's open source.