Telegram Became the Anti-Facebook
wired.com
wired.com
Ultimately, we need encrypted-by-default messaging based on public/private key pairs (obscured from the uninterested user, of course).
This is not a fundamental limitation but a default setting in order to preserve privacy. You can easily turn URL previews for a given E2EE room on by going to the room settings > General > scroll down to Other > URL Previews.
I'd probably even trust FB's unencrypted messenger content to be better protected than telegram.
They clearly have a loyal fan following though.
That said, this idea
> I'd probably even trust FB's unencrypted messenger content to be better protected than telegram.
is ridiculous.
With Facebook you know you will be datamined and the result sold to anyone who wants to buy..
With Telegram maybe Putin reads it, maybe not.
One of them is a threat to my family and friends, the other is not.
If you're using unencrypted messaging you should assume it's public. This is true of FB messenger and Telegram, but if I had to bet on what unencrypted content is more likely to be owned I'd bet on Telegram. This is mostly a bet on where the world's best security people are and the company culture.
Really though we shouldn't be relying on the benevolence of any of these company leaders, that's why people should use Signal or WhatsApp where the encryption means you don't have to (or Urbit where there is no central leader).
In short - you’re posting misinformation.
It also sounded like with Telegram there was some abuse of looking up or deleting other employees chats when threatened. The culture of the company doesn’t seem great.
All of this is kind of irrelevant though. The core issue is unencrypted chats.
My point is not that Durov sends data to Putin (I don't think he does).
My point is that there is a lot we don't know about Telegram.
When it comes to WhatsApp and all other Facebook properties we know a lot and much of what we know is ugly.
But yes, I should find a better way to phrase it.
I said it many times and I'll say it again: this can't possibly work in the real world, period. People are notoriously terrible with passwords already. So terrible in fact that VKontakte (I worked there, both with Pavel and after he was ousted) had, and still has, a department dedicated to account recovery. And those are passwords, short strings that you can actually remember. You can't possibly expect an average person to keep their private key (a file you can't store in your head) absolutely secret and never lose it at the same time.
In my world, the ability to recover your account if you lose everything is a hard requirement for any product that is meant to reach mass adoption.
The ability to revoke access is also a hard requirement. People share their credentials — it's a fact of life. In the usual setup, you can change your password and terminate sessions. But if your private key is your identity, you can't do shit to prevent someone who has gained access to it from impersonating you for the rest of eternity.
I don't think it matters as much for messenger attached to your phone number. Even if you lose all your conversations you still can be reached by the same identificator and most of your contracts are stored in phonebook anyway.
(outside of certain self-referential bubbles - like this site) no one cares anything about encryption, if in public chats I am anonymous and untraceable (example: no one can know my phone number and there are granular privacy settings) this is enough for 98% of people out here
"yes, encryption is useful if I want to send nudes to my partner or if I want to buy drugs but not while I'm asking mom for the sufflè recipe or I'm organizing a dinner with friends" this is what people think, and they are not completely wrong
I don't know however any groups that use signal as a replacement for any of the above, so do people have experience in migrating groups from those platform to signal?
-not being tied to a phone number
-having a desktop app which doesn't suck (sync issues, connection issues, lacking features, is basically a simple proxy for your phone, etc)
-allows me to use 3rd party apps
-having chat history synced across my apps and devices and backed up. History is immensely important
These days, Threema and Signal don't support the Matrix Protocol.
I wonder if Telegram would also be more closed if it was #1...
I think it does:
[1] https://techcrunch.com/2021/11/01/whatsapp-brings-its-busine...
[1] https://faq.whatsapp.com/general/whatsapp-business-api/getti...
Telegram is really weird and sketchy; the rants Durov posts on his channel against WhatsApp usually make no sense; and their claims of security are dubious. And TON was a disaster.
On the other hand. If I did any social organizing today, I would definitely use Telegram. Signal is fine, but nobody is using it and the UX is just worse. I don't trust Facebook to randomly not shut everything down because some outsourced content moderator in New Delhi had a bad sleep.
Durov might be sketchy and weird libertarian, but damn, his developers can deliver good and working product really fast. (And from what I understand, it's a really small team.) Credit where it's due.
I still think Telegram will plainly run out of money in a few years (you can use it to host unlimited amount of data and share it with unlimited number of people!! that is not sustainable), but well, I will use them before they do.
They just cannot be sustainable long term. There is literally no restriction size-wise on data you can save on their servers. For free. And they have basically no income. They have some new ad program with basically no tracking (which is good for users, sure, but nobody will pay that much for that). They get 0 commissions from payment (and I never heard anyone using their payment thing). TON went nowhere.
It also seems like files that are not downloaded by many people for a while get moved to slow servers and downloading these is really really really slow. If you have a few GB and want an additional online backup sure you could abuse it for that but realistically the potential to abuse it is low as it simply makes no sense as a could storage + they simply delete accounts from people who abuse the network. "Spam" is very lose defined and if you spam upload/download I'm sure they consider that to be spam and delete your account. Kinda pointless "backup" if you can lose access the moment you use the backup.
>And they have basically no income.
How would you know? They launched ads in public channels.
>TON went nowhere.
TON exists and seems functional just doesn't have anything to do with Telegram anymore due to the SEC.
You’re repeating weird, but working with both bot api and tg api weekly or so (tg api through a wrapper, but I’ve read about lower level calls and used these in gramjs) I can’t see what do you mean by that.
[1]: https://words.filippo.io/dispatches/telegram-ecdh/ [2]: https://crypto.stackexchange.com/questions/31418/signal-vs-t...
it is on https://Github.com/SignalApp
and i’ve got my own variant of Signal server and client running. and runs on not only mobile but Linux too.
If you don't need/want that it is clearly superior, but if you do...
Sure, Telegram team used more human resources elsewhere while WA and Signal where doing their E2EE magic, but once they where done - what stopped them from investing into everything else?
The most salient of these is that, if you lose your keys, you may never be able to recover your data.
That stuff confuses every non IT person.
Not caring about it, allows for a more simple UI and UX to provide a easy way for person A to message B. Where B can be a group of thousands of people.
(a really secure way of posting a message to a big group would be way more complicated, even signal makes compromises)
- Hash the password client-side
- Send the hash to the server. The server treats it as a password, and gives you your blob of encrypted data
- Decrypt the data client-side using the original password
Also, downloading blob to client side and decoding it locally can hardly be done fast enough for user to consider it 'instantly'.
That's a different, further goalpost - we were talking about E2E encryption, weren't we? I.e. the server should not need to decrypt your data to provide it.
Obviously if you want to be able to recover your history from storage with just a password, that does mean the password is the only protection over that history, tautology. So storing your history should be optional, if you're seriously worried about brute-force attacks on data encrypted at rest (indeed, even WhatsApp makes it optional to have a backup of your data!).
In any case, that doesn't compromise future secrecy - i.e. gaining access to the history still doesn't give you access to future messages.
> Also, downloading blob to client side and decoding it locally can hardly be done fast enough for user to consider it 'instantly'.
Off the top of my head, it doesn't have to be a single blob for all your data. You could split the blob into tiny equal-sized chunks, and then have a separate encrypted index file which stores the information of which chunks hold which chats (plus just enough metadata, e.g. chat titles and last messages, to display your homepage properly). The index file is the only one downloaded on first login, then when you want to open a chat it moves the corresponding chunks to the top of the download list.
Exactly, and what is described is not e2ee at all.
> End-to-end encryption (E2EE) is a system of communication where only the communicating users can read the messages. [..] End-to-end encryption is intended to prevent data being read or secretly modified, other than by the true sender and recipient(s). The messages are encrypted by the sender but the third party does not have a means to decrypt them, and stores them encrypted. The recipients retrieve the encrypted data and decrypt it themselves.
Which requirement do you believe is failed by such a system?
This is reasonable, but it's not describing any weakness of encrypted backups. It merely points out that "E2E" isn't the right term to use when there are not two E[nds], but rather only one client and their files.
However, our conversation was about storing chat history. There are two parties to the conversation in that case.
The key property of E2E is that only those parties can read those messages, and nobody else, in particular not the agents running the server. That property is not affected by the existence of backups, as long as those backups are client-side encrypted, because third parties cannot access them.
Therefore, it is possible to have both cloud-stored chat histories and true E2EE. QED.
Please, enlighten me how exactly Element/Matrix practically do that. Thank you in advance.
When you login, you provide that password, and Element can use that to decrypt the keys and use these to decrypt the messages stored in the cloud
Alternatively, you can solely rely on syncing keys between verified devices.
Only you as a recipient can decrypt the messages, because they are sent e2ee to you.
And this stays true if you use the backup, as only you know that password.
Regarding the security theater, the backups encrypted with your password are far more vulnerable to being compromised than any of the popular e2e encryption protocols.
But then again, most users do not need real security, they are fine with a warm comforting feeling of safety, provided by a sincere promise that everything is really safe, as demonstrated by Telegram users.
> Regarding the security theater, the backups encrypted with your password are far more vulnerable to being compromised than any of the popular e2e encryption protocols.
How, so? Are you aiming weak passwords? (One is provided for you ("security key"), however you can opt into a custom one that is not directly used for encryption ("security passphrase"))? Or are you referring to PFS, which isn't a property of all popular e2e protocols either, and "far" would be quite a stretch.
How does all that disprove that Element uses true e2ee?
What is "it" that in your opinion should reduce the users privacy?
> I don't know what else to argue about here.
I don't know what you are arguing about right now. What I know, is that I have disproven your original thesis (visible messages right after login through a password is not possible with e2ee) by explaining how it works and providing an example that has put that concept into practice.
If you feel there is anything to discuss, or if you have any further questions, don't hesitate to respond though.
I'll add link that adds technical Implementation details, in case you are interested: https://matrix.org/docs/guides/implementing-more-advanced-e-...
https://www.whatsapp.com/security/WhatsApp_Security_Encrypte...
Overall, the concept seems to be the same: use a secret, only known to the client to secure data stored at a untrusted location.
The major differences include:
- closed vs open source (it's easy to validate the mechanism in the implementation whereas you pretty much need to trust WhatsApp that they don't leak the key)
- WhatsApp uses a third party provider for storing the data whereas with Matrix your Homeserver is responsible for messaging and the backup
- only the main app can access the backup whereas with Matrix any of your clients can independently read and write to the backup (because there is no main client)
- WhatsApp stores everything in the backup, a Matrix client only the keys, because the messages are stored somewhere else
This wikipedia entry? So client-side encrypted backups are not called end-to-end encrypted, because the backup service is not a messenger?
Hmm? How so? Surely this depends on the strength of your password.
> Break one key, and all messages will be accessible to an attacker.
How do you propose breaking that one key, though? The attacker also needs to somehow acquire access to the key backup and to the encrypted messages, so it's a multi-step process.
The encryption protocol does rotate message keys. In fact it uses the same cryptographic primitives as Signal, that is the double ratchet algorithm.
I think you're conflating the message encryption protocol with cold storage, which is the purpose the key backup serves. It's completely typical for backups to be encrypted with a single symmetric key.
Finally, the key backup is completely optional and can be disabled.
Then, how do you break the key?
Brute force? If you break one key that way, it's likely you could break equally secure keys as well.
Access to the device? Well then you have access to everything anyways
I get that people like its UX, but if you're sacrificing security for UX then basically anything becomes fine?
The police can only make you talk if they know who to make talk in the first place.
Reading your messages tells them who to interrogate, where to find them, who else is involved, etc.
Encryption is important especially in such countries.
The police need to crack the encryption protocol (not impossible, telegram use non-standard crypto), or somehow gain access to telegram's server farm.
>Reading your messages tells them who to interrogate, where to find them, who else is involved, etc.
Why read my messages if they can start from me? Or that other guy who posted something on twitter? Or any other place? Or talked to someone.
I'm not saying encryption is unimportant. I'm saying that it really only matters as long as all parties involved keep their business secure in the first place.
Not to mention that they police don't really work with that kind of precision here.
If you can choose secure communication vs. insecure communication you're better off choosing secure. You're right of course this doesn't protect you 100%, but it's a lot better than not having secure communication.
Does that mean even with Signal your friend could be compelled to unlock their phone and reveal the comms? Sure. It's still better to have that be the requirement than access to all comms by default. It requires more specific and high effort targeting. It makes it harder to just query keywords generally to find people. It's the better default state.
If you want to exchange your private keys, you better not do it using any chat platform.
What countries do you people live in that needs such hiding from the police/state?
In my country they bought Pegasus and what can I do about it? If they want to trace me they can do it.
Edit: but even so, they could verify a phone number by SMS, no need to make anyone install an app.
You toss out another statement in "TON was a disaster" without explanation. If you're going to make really big statements like this, please go into detail otherwise you're just shooting from the hip.
TON was a disaster because the SEC got involved. TON, as a technical solution to decentralizing Telegram, was a great idea and I'm sad Telegram was forced into a position of paying for all that infrastructure another way, with ads (opt-in, non-tracking, and only in one-to-many channels but still, ads).
People keep insisting that electron is chosen for productivity yet telegram delivers more features with more efficiency in C++/QtWidgets (for the desktop) with a smaller team than so many electron stuff
Fun fact, their Android code [0] (haven't seen iOS) is unmaintainable mess and on the surface just looks like a complete disaster. I find it baffling how Telegram Android not only hasn't fallen to bits requiring a full rewrite, but has continued to deliver brilliant UX and features.
0. https://raw.githubusercontent.com/DrKLO/Telegram/master/TMes...
Oh yes, definitely. Whenever I read them it feels strange, understanding the technical context of Telegram. He never mentions that WhatsApp is actually end-to-end encrypted. He does continue to talk about 'encryption', though. It's very very misleading. It just seems to be bashing WhatsApp without talking about Telegram's shortcomings too. He obviously isn't going to be non-partisan but it would be nice if he would be a little more honest.
If you only need the one channel and you need to manage a 100+ people, Telegram is by far the best tool. For "communities" Discord is a bit better, since you can split stuff to multiple channels. Anyone with basic knowledge of the internet can also install bots on both to manage dozens of different things.
Signal on the other hand is SUPER SECURE (although you will be giving your phone number to everyone), but no bots and no real ways to manage hundreds of possibly unruly people on a single channel.
Even better than Element? In my experience it does well with hundreds of people as well. And it allows to group channels as well, or use bots
And you can use E2EE everywhere you think you want it
I've been on IRC since its inception in the 90's and I've used ircII and BitchX etc. I'm no stranger to janky clients for communication tools.
Element is still in its death by a thousand cuts phase. There's nothing hugely wrong with it, but everything is a bit wonky. Just enough to be consistently annoying enough for me not to bother.
Summary: Matrix mostly good, Element bad. They should just copy Discord's UX 1:1, change the colour theme and work from there.
If you're managing a 100+ user channel, encryption matters fuck-all unless your invitation process is 100% airtight and every user has all their devices encrypted and locked up at all times.
Data will leak anyway so E2EE won't bring any real advantages.
Any leakage of secret knowledge shared only through these groups could be detected as treason by one of the participants in that channel. Having several channels with fewer and fewer members, closer to the party's leadership, is a typical configuration to maintain control of the most secret information.
FYI they recently got an ad platform https://promote.telegram.org/
And then they will start selling all the personal data they gathered in all these years. They have all the data, except for the tiny amount that passed through secret chats (but they also have the metadata for these, tied to accounts and all the non-secret stuff).
The kind of data Signal can't sell even if Moxie turns evil, simply because Signal does not have it.
I don't see how Telegram is any different to say, Signal. It may have better apps, UX, features and more which that alone makes it a compelling competitor but its optional E2EE support is quite damning.
The great thing about regulations is that it stops such suspicious projects like TON dead in their tracks. After the ICO madness in 2017, unregistered ICOs have become illegal and TON fell in that category.
But who knows, maybe when the terrorists, extremists, scammers and fraudsters realise that Telegram is not E2EE by default or layman terms 'not secure', perhaps they would run to Signal and chat amongst themselves about using a private untraceable cryptocurrency like MobileCoin to fund and plan their operations. [0] [1].
[0] https://www.theverge.com/22249391/signal-app-abuse-messaging...
[1] https://foreignpolicy.com/2021/03/13/telegram-signal-apps-ri...
You have answered your own question there. Humans naturally chose paths that they find convenient, not necessarily safest or otherwise "better" paths.
The UX is great. The Telegram clients are quite nice to use. They're open-source, too. Well, 'open-source' as in they dump a huge diff into the source tree now and again, and they never interact with outside developers submitting Feature Requests and Issues.
Don't, unless it's for a BBQ or friendly partying.
[1] https://www.wired.com/story/brazil-hacker-bolsonaro-car-wash...
[2] https://www.reuters.com/article/us-iran-cyber-telegram-exclu...
[3] https://www.haaretz.com/israel-news/tech-news/.premium-exclu...
C'mon, it's not even E2E. It's as good as Facebook Messenger when it comes to security.
Telegram server side is open source?
I tried to connect it to a tor email local postfix, still wip.
And of course, at the conclusion of the article, the author shudders of the thought that there could be a communication platform not censored by the government. The horror!
I'd actually pay a monthly subscription for the value Telegram has given over the years. The pace of development is unmatched by any other platform. I know Telegram chats are not end-to-end encrypted by default. Pavel Durov has explained, and I'm sure it's somewhere on Telegram's site too, that a big reason for not doing E2EE is enabling fast search (on the server). And it shows: Telegram has the best search among chat platforms and is even better than search on social network platforms with more features like Facebook. Maybe they have ulterior motives and/or aren't technically able to provide E2EE for all chats. So far, it hasn't had widespread scandals (other than TON) like Facebook/Meta has had.
This is not to claim that Telegram doesn't have design flaws or drawbacks. But no other platform can catch up to its UX and features for at least a few more years, and that gap seems to be widening as time passes. If any platform were capable of doing so, it would've happened already.
Among Telegram's many features (if you use Telegram, check how many of these you know about):
* Phone number hidden from others? Check.
* Username that can be given to anyone or published anywhere for others to contact? Check.
* Multiple accounts on one app? Check. (the official Telegram clients allow up to three accounts)
* Fast and reliable (comparatively) message delivery? Check.
* Client applications for multiple platforms? Check.
* Messages (the default, non-E2EE ones) sync across all clients? Check.
* Send large files? Check.
* Prevent phone number enumeration by others (who randomly add numbers to their contacts list)? Check.
* Granular privacy settings? Check.
* Search messages by text, by person, by date? Check. Global search? Check.
* Use a calendar view to check activity/messages? Check.
* Edit messages after sending? Check.
* Delete messages after sending? Check.
* Message reply threads? Check.
* User mentions and quick navigation to mentions? Check.
* Scheduled messages? Check.
* Audio messages? Check. Video messages? Check.
* Voice chats (like clubhouse)? Check.
* Polls? Check.
* Chat exports? Check.
* Media editor? Check.
* Built-in video player with playback speed adjustment and fast forward/rewind? Check.
* Edit photos after sending? Check.
* Forward messages with fine control over whether it shows as a forward and whether the caption should be included? Check.
* Pin messages? Check. Multiple pinned messages? Check.
* Broadcast channels (one to many)? Check.
* Bots? Check.
* Themes and stickers? Check.
* Message folders? Check.
* Interactive emoji? Check.
* Message read receipts (by user) for small groups? Check.
* Spoiler formatting? Check.
* Reactions? Check.
P.S.: I do not work for and nor am I in any way associated with Telegram, except as an end user.
Facebook suffers biggest one-day fall in history as shares plunge over 26%
More than $230bn wiped off the value of Meta making stock market history.
Most concerning was a never-before-seen drop in Facebook’s daily user numbers.
https://www.telegraph.co.uk/technology/2022/02/03/almost-200...
Anyway, I think facebook is too big to fail.
1. Everyone I know uses it in plain-text, very few dare to (gasp) initiate secret chats (and they tend to lose chat histories every now and then).
2. At one point it had been banned by Russian authorities with a demand to disclose the E2E encryption keys. The ban was quietly lifted with a single report I could find vaguely mentioning some cooperation promises by Telegram’s leadership. What is happening beneath the curtain is anyone’s guess.
3. Last time I checked, the company that runs the servers has undisclosed structure and is liable to be manipulated by whichever entity that gains a hold of them (not even through legal mechanisms, but through direct or indirect fear for personal safety).
4. According to what I heard from friends, solvency/debt issues from the failed ICO attempt made them desperate for money.
It’s not a safe private messenger, period. Even Telegram’s own advocates are switching from their old stance “Telegram is secure” to “Telegram is just best for messaging, who cares about e2e or privacy anyway” (which, incidentally, I don’t know if true in Android land, but at least on iOS Apple Messages has way superior stickers, built-in apps, etc. for those who don’t care that much about privacy).
My favourite one from Wired is when they critically examined Project Xanadu leader and its history.
It's from 1995 but people still keep linking to it whenever Xanadu is mentioned.
the E2E feature is... there... who cares about it, just load it up for one specific conversation and move on.
"Telegram is Russian Spying"
"Telegram has extremely weak crypto"
"Telegram is used by pedophiles"
"Telegram is used by far-right terrorists"
.... Use Signal!
sigh
The amount of times people bash on telegram is becoming painful.
But lets take a logical argument; NSA has made it's mission in backdooring basically everything.
We know from the Snowden revalations that their technical capability in 2008 (he only exposed info on things that were already old, his intent was to show illegal surveillance not capability remember) was such that they had some kind of access to every conceivable device on the planet and the majority of communication that went through the US.
I don't think their technical capability got significantly worse in that time. So, if Telegrams private crypto code is backdoored or weak: well, NSA have it. No doubt should remain in anyones mind about that.
Telegram is hosted on Google Cloud, which is under the juristiction of USA. Google cloud claims to not have access to client data, but I think it's not outside the realm of possibility that something could exist between the TLS terminators and the telegram communication relays.
Maybe I'm wrong here entirely, but two things cannot be true at the same time:
1) Telegram is weak, NSA has access
2) Telegram is strong, NSA does not have acces
If telegram was strong: NSA would do everything in it's power to push users to more controlled platforms.
If telegram was weak: Jan 6th and Jihadi terrorists wouldn't use it.
Addendum: all of these same complaints (save: weak crypto) can be used against Signal.
---
I don't think this is a good justification for not using telegram, you wont be labelled alt-right or a terrorist or a pedophile.
These same arguments come out time and time again about Tor too. It's pitiful, honestly.
Even if you make the argument that telegram CAN be encrypted (only in 1-1 chats) what ultimately matters is how people actually use it, and that is probably in an unencrypted manner.
I've heard criticisms about Telegram's MTProto encryption on HN, but in my usage of Telegram nobody has ever turned on the secret chats mode enabling it anyway. Anyone privacy-conscious asks me to use Signal, Matrix, or even Threema.
I have heard compliments about Telegram sticker packs though, if the other apps want more users they could consider making "cute stickers" :)
You joke, but Telegram's clients have been innovating for years. Way ahead of the rest. Its packed with features and yet never feels bloated or slow. Frankly, its amazing.
The Telegram client/feature set is great, and I hope Signal and competitors will improve their clients to match.
Many of Signal's sticker packs were ported from Telegram:
https://core.telegram.org/stickers#importing-stickers-from-o...
In light of that, importing stickers from Telegram to other apps is fair game. Telegram's very brief terms of service* do not forbid users from using Telegram stickers outside of Telegram.
Also, some of these stickers are recycled memes from social media and pop culture, which usually qualify for fair use when used for messaging.
https://tlgrm.eu/stickers/MrBat https://tlgrm.eu/stickers/BattyBat https://tlgrm.eu/stickers/FangBat
Source? Back when Russia was playing IP whack-a-mole, they were using at least AWS, Google and Azure.
https://www.bbc.com/news/technology-43797176
Not that this really affects the thrust of your argument, since all 3 are US entities, but it seems unlikely that there's a single place you could tap for access to everything.
Frankly I wasn't aware they were on all three, I was just on google cloud and got affected by these whack-a-mole shenanigans, and assumed it was exclusive.
This is entirely my bad for not checking my assumptions and I apologise.
The Jan 6 dudes ("terrorists" and/or otherwise) put their ugly mugs all over Facebook, Twitter, Parler, and the public Internet. I wouldn't exactly take opsec advice from that lot.
I remember 9/11 from outside USA. It "broke" the normal way people lived their life. Jan 6 on the other hand did nothing, no one cared. Only US propaganda media made a huge deal out of it. And they keep talking about the 768 (an more) people who have been charged as if they where charged for terrorism or something. Most of them simply got charged for entering a restricted building. Comparing this to a terrorist attack that took the life of 3000 people and injured at least 6000 other is grotesque and disgusting.
9/11 may have been devastating in many ways, but Jan 6 was an attack at the very structure of the American democracy. They tried to install a leader of the country who wasn't actually the one elected by the majority. If they succeeded, it would be a major blow to American credibility and founding story of a "democratic nation by the people, for the people".
You gotta be kidding me and/or yourself. Do you really believable that?
This was a rather normal protest march which escalated to a riot where a small fraction of the people probably 100-200 resorted to various forms of violence mostly against property and to an extend against police. No question this is bad. But a coup? Really? Installing a leader, lol what?
Reality check: If an heavy armed group would have stormed the capitols and killed everyone inside that would not have installed a leader and that would be an actual terrorist act. Still there is no logical path how that would/could have changed whos the next president.
There is no evidence that any group of people went there with this goal (to violently install a leader). The vast majority was just there to protest and didn't do anything wrong. From the 700+ people charged the majority was just foolish and entered the building/property after police gave up or where overpowered by the actual violent people. There are plenty videos from inside the capitol where people just walk around. These videos were used to charge them but given the fact that they just walk around they basically are trespassing and cant be charged for much. Most of the 700+ charges are non-violent.
One person died because she was shot by the police some others died do to medial reasons. Some injuries and property damage as you would expect from a riot. Calling this a coup is absurd. America would be the last place where people start a coup unarmed.
I would advice you to watch some of the live streams from that day and/or read some foreign news articles about it and make sure you know about all the debunked misinformation tied to the riot. From X people who got killed to a police officer being murdered to bombs it really had it all and most old articles you find about it still are not corrected.
We don’t even need to resort to conspiracy theories — all Germany would have to do to ban Telegram is make Apple take it out of its app store. And it is coming close to that. Telegram’s Durov also openly said that they respect countries’ laws and censor certain people because to be kicked out of the app stores in that country is worse.
What is the decentralized alternative? It takes a lot of work and immunity from the profit motive, to build a viable alternative.
Moxie is famously skeptical of decentralization, but it is essential — not just for privacy, but more broadly — for user empowerment and control. If you want to know what the decentralized solutions look like, lease read my answer to Moxie
https://community.intercoin.org/t/web3-moxie-signal-telegram...
Telegram didn't have e2e encryption for a long time and its chats are still not e2e encrypted by default. Also, I would hardly call Durov an anarchist.
Matrix
That's reaching deep... seriously?
https://theanarchistlibrary.org/category/author/moxie-marlin...
Durov seems to be more of a right libertarian type. Whether this qualifies as "anarchist" or not depends on who you ask.
We know they had access to every centralised provider's servers (including Google and any other company you care to name). We also know that they couldn't break post-DES cryptosystems when properly used - indeed NSA employees expressed considerable frustration about the fact that they couldn't break PGP-encrypted emails or chats and had to resort to metadata analysis, social engineering, hacking individual users and so on.
> 1) Telegram is weak, NSA has access
> 2) Telegram is strong, NSA does not have acces
It's not a binary. Most attacks on cryptosystems reduce the amount of work it takes to break in rather than making it completely free. And even if the NSA theoretically has access, that doesn't mean they can predict an attack or will share that data with every contry/agency/company. We know the NSA was reading all unencrypted emails up until at least 2012 or so, yet there was plenty of crime committed and discussed over email during that period.
(I'm no fan of Signal or the way it's marketed, quite the opposite, but I trust Telegram far less)
NSA is not a law enforcement agency; they don’t care about crime.
Pretty sure the intelligence people have a policy to maintain their ability to see their shit rather than blowing their load.
In fact there's probably an evolutionary aspect to the jihadi thing.
Most people I know would rather use Signal now.
What power does the NSA have to influence those choices? When has it happened? Do you have evidence of it?
I think that was probably around the same time more and more of the web moved from HTTP to HTTPS. Even webmail was accessed over plaintext for a long time, so I guess a lot of signal got worse while legal access got not only better but "integrated".
Better and E2E crypto is the main argument for Signal though.
This is a significant difference between those two. You can't just ignore it if you build up such a case.
It's the same reason why you don't want to measure someones kindness by comparing it with Adolf Hitler. "Oh I have such good neighbor, he is the completely opposite of Adolf Hitler", it just don't compare very well.
You must have missed this piece [1]:
> The app was in fact secretly built by the FBI, and designed to allow law enforcement to tune into conversations between about 9,000 users scattered around Earth.
[1] https://www.theregister.com/2021/06/08/operation_ironside_an...
> accounts do get closed for automated/arbitrary reasons
can happen on any of big platforms