Telegram is anything but secure; even Facebook is safer, says Signal founder
phonearena.com
phonearena.com
https://threej.in/article/Signal-founder-criticizes-Telegram...
What now? That's not "just as insecure", since Telegram can also "push any code they want to anyone they want to spy on," but they don't need to because your data is already plaintext on their servers.
Signal not being perfectly secure does not make it "just as insecure."
To tell people that there is no advantage to use Signal instead of much less secure alternatives because your Area 51 security requirements aren't met is actively harmful and bad advice.
Whether Signal or Telegram, you rely completely on trust in the central third party for security.
The choice of whether to use Signal or Telegram should depend on which of these organizations you trust the most (their leadership, their internal employees, and their security from external infiltration), NOT based on what technology they use in the client & server.
But you simply shouldn't use either because real security is all about not having to trust anyone like that.
And that's why technology matters, because security is not binary. Very concrete example, someone uses Facebook Messenger, the police get the hands on their phone, arrest them for some chat content. Signal cannot do that, and you can verify they cannot. That's a real use case that people in particular in countries with oppressive governments run into at this very moment.
This is technically correct but not in a way that matters. Signal pushes everyone to depend on Google to distribute the software. Through this system, it isn't even just Signal, but also Google and anyone who breaks into Google that can inject a compromised client.
You don't know that the client on the other side isn't getting its Signal app through Google.
More importantly -- even if you DO know the client on the other side -- the WHOLE POINT of Signal is this massive network effect where you don't need to coordinate with the other side.
If we're talking about the much smaller network-within-a-network of users who installed Signal from a non-Google source -- it's no longer compelling. Why bother with it? Less error-prone to get both sides to set something else up.
That doesn't make any sense at all. Being "serious about security" doesn't mean letting the perfect be the enemy of the good (which is what you're doing).
What other software has verifiable client builds and a server that stores as little information as Signal?
When the military issues secure communications devices, it makes damn sure that BOTH SIDES have a secure device.
What software would not be vulnerable to what you’re describing?
In case you don't trust Google I really suggest OpenSSH or WireGuard, to establish a secure tunnel; and then run IRC, Jabber, SIP, or mumble (as needed) over the tunnel.
I wouldn't take anything that Signal developers/founders say about their product or others' products security seriously.
Same thing with messaging online. Everyday nonsense can use whatever app you want, and if there's something you really don't want anyone else knowing you can use a different solution. I think the trade-off is worth it for most people.
Telegram is fancy, it is a great replacement for WhatsApp, but it cannot replace Element, Conversations/Gajim (XMPP), Briar, Ricochet, or Wire. Please avoid Telegram for actually "secure chats".
I recommend checking out https://secushare.org/comparison. I disagree with "Telegram can be among the least worse [for smartphones]" though. It is Briar. I have also used Briar on desktop, I wonder where that will go.
[1] https://tsf.telegram.org/manuals/e2ee-simple#2-why-are-there...