Moxie on Telegram Encryption
twitter.com
twitter.com
The feature is hidden, and old "secret chats" stop working after a while without any indication that messages cannot be delivered anymore. To start a "secret chat" one must access it from a menu entry stashed away in users' profiles. And you can only start writing a secret message when the other side "comes online" for the first time after starting a "secret chat".
All discussions about the technical implementation of e2ee in Telegram aside, this makes e2ee a pain, which is why it is rarely used (by most) if not desparately needed.
Telegram's UI is pretty. I would use it as a replacement for WhatsApp, but it is not a replacement of Element, XMPP, Briar, Wire, Ricochet, and so forth.
Telegram is not an IM for secure communication where privacy matters. Do not use it as such.
[1] https://tsf.telegram.org/manuals/e2ee-simple#2-why-are-there...
I have seen so many people going through the horror of losing everything on WhatsApp whenever they switch phone platforms - the chat backups it creates are not transferable across Android and iOS for some reason and there is no way to recover your conversations at all in such a case. Telegram covers many things where its alternatives fall short, but privacy and security are not one of them.
You will get what you described without even needing a phone number and WITH E2EE
It never was closed source. They simply implemented a feature before uploading the code. Is there a rule to how how many commits need to be made in a time period? No.
> to integrate some cryptocurrency scams into it.
You clearly haven't read enough about why they chose to implement a payment system and why they chose to create their own. There are very good reasons they did both. Don't be salty because they didn't use the one you hold.
> why would I choose a messenger that requires a phone number over another that does not ?
Unless something has changed recently, telegram absolutely required my phone number. Signal is also working on replacing phone numbers with usernames.
> Mainly because the app is more stable and doesn't dictate its philosophy to the user. Proper e2e encryption has tradeoffs. Why shouldn't the user decide for which conversations he is willing to place convenience over security ?
One can't claim to be a secure encrypted chat app but then not enable it by default. It's completely fine to not have encryption, but it's not ok to mislead people into believing it's encrypted all the time.
> Why do you lose your history when you switch between android and ios ?
Mostly because signal doesn't store your messages. There is no central server that has all your info and chat history like telegram does. It makes this harder
The server-side code in the public repo was not updated between April 20, 2020 and April 6, 2021. The Signal Servers were updated in the meantime. The code that was running on those servers was not Open-Source.
>You clearly haven't read enough about why they chose to implement a payment system and why they chose to create their own.
I've read more than I ever wanted to read about this subject and I still find the arguments for why my privacy friendly messaging service would benefit from being co-mingled with a(soon to be heavily regulated) financial platform entirely unconvincing. Moreover setting aside the goals: the way they went about it, in total secrecy, does not engender trust.
>Unless something has changed recently, telegram absolutely required my phone number. Signal is also working on replacing phone numbers with usernames.
Signal has "been working" on this issue for an awfully long time. A Plethora of Matrix Clients have had this Feature from day 1.
>One can't claim to be a secure encrypted chat app but then not enable it by default.
enabling it (by default) and forcing the user to use this as the only option are completely distinct.
>There is no central server that has all your info and chat history like telegram does.
You seem to consider this to be a feature. To me the absence of an (optional) central server is a bug.
Any vendor that claims their product to be 'encrypted', plays this up in marketing and lets its users believe they are communicating confidentially, yet captures 99% of their communications -- it is not a bug, it is malicious.
>> Mostly because signal doesn't store your messages. There is no central server that has all your info and chat history like telegram does. It makes this harder
This can be solved by sharing keys between your two devices, or approving your device from another. Element does this. You do not lose history. In any case, this is a solved problem.
He is right in his technical concerns, but what I see is that Telegram is used in a different way around here. I and my friends don't use it for 1:1 chats. But for finding public chat groups on topics. For example I joined a public group where people mentioned drops of hard to get video cards. I got my Founder's Edition card for actual RRP because of that, instead of the inflated prices due to the shortages.
It's a bit similar in the way it's not a problem that IRC has no E2E encryption. The channels are meant to be public. Anyone can join them at any time.
I also use telegram for notifications because they're open to bots and you can even add images. So I have my own server notifications coming through there. Nothing sensitive in those. Signal in contrast does not allow any third party app on their network, moxie has said so many times.
I never use Telegram secret chats because they suck. Both parties need to be online at the same time and it can only be used on one device. But I don't view Telegram in the same way as Signal or Whatsapp. There's a place for both.
My real favourite is Matrix though. It does have good E2E encryption and also has good public channels (which don't need encryption). It's also decentralised, you can run your own homeserver with complete history right on your own system. It has bridges to other networks so you can reduce proprietary apps, and it welcomes third party apps. It's the best of all worlds IMO. Signal is still a walled garden even though it's a more private one.
They are separate from regular chats and not available in the official desktop app, but they are secure.
Signal with their “we trust Intel SGX to be single point of failure” kinda smells like a government honey pot.
Reviewing crypto is hard when you’re working with an organization that has good engineering practices and minimizes the possible risks. My early examination of Telegram crypto led me to the conclusion that Telegram was not an organization whose approach to crypto engineering is compatible with that standard, so it’s not worth the effort to try to vet their crypto when the company leaves so many weird question marks in their engineering approach. Meanwhile there are products with more professional crypto teams working hard to behave in ways that engender trust: I’d rather devote my limited effort to poking around over there.
I do recall Telegram building a very weird variant of Diffie-Hellman that effectively let the server modify the secret key (and thus conduct MITM attacks.) In fact they did this multiple times in different ways, either by accident or through malice. This happened a long time ago so it’s entirely possible that they’ve cleaned up their act, but it left a bad enough taste in my mouth that I’m afraid to poke around in their crypto and render any opinion. If I look at it and say “looks better now” I’m afraid I’d just be hurting people. Unless the company makes a real effort to bring their crypto engineering up to a higher standard, I won’t feel confident in any of it: there are too many non-standard bits of engineering where dragons might lurk.
It wouldn't matter if it was. I don't believe it is, but it wouldn't matter. Signals entire design is to NOT trust any server. Messages are encrypted on the device before it's ever sent to signals servers. This is verifiably proven since the code is all open source. Every signal message could be logged and it still wouldn't matter thanks to signals ratcheting algorithm.
> Signal with their “we trust Intel SGX to be single point of failure” kinda smells like a government honey pot.
Either you’re stupid or deliberately spreading lies.
I don't trust him, sorry.
So sayth my canary.