No. Most people can't do that (because not everyone is a software developer).
Good luck trying to convince the general population that “the UX is bad but theoretically anyone can improve it” is better than what you get out of the box with other messengers.
Just do the change yourself. Help those people close to you to install Element alongside whatever they are using now. Even if just because they are using to talk with you, it's better than nothing.
You don't get to migrate things that are on huge network effects in one go. But we can help the growth of one network organically until it reaches critical mass.
I am not asking them to delete the other app, I am not asking them to join a religion. I am just asking them (and helping if necessary) to install an app and set up an account on my server.
I don't use either so I don't really care. I just don't expect a consumer service with subpar UI to win market share solely on technical merits.
That makes sense for unfunded projects because most developers are not good designers, and designers don't have a culture of contributing to open source, but for a project that pays (some of) its developers, it's their choice how much to pay developers vs designers vs managers, and they are responsible for the way in which they allocate their limited resources.
I recently had to move my open source project's chat from Gitter to Discord, not because we like Discord or "don't care about open source" but because everyone is so damn tired of Gitter's terrible UX that it became the overriding concern.
Matrix bought Gitter two years ago, and I kept waiting, hoping that they would improve it, but they did literally nothing to it except connect it to Matrix within a couple months – and even that doesn't work well, with Matrix users still unable to respond in threads.
I assume there is a good reason for that. I'm not here to judge, only to point out that this "good reason", whether it's lack of funding or priorities or whatever – won't change anytime soon, so I won't be holding my breath anymore.
We spelt out the good reason in the original blog post: https://matrix.org/blog/2020/09/30/welcoming-gitter-to-matri...
> However: in the medium/long term, it’s simply not going to be efficient for the combined Element/Gitter team to split our efforts maintaining two high-profile Matrix clients. Our plan is instead to merge Gitter’s features into Element (or next generations of Element) itself and then - if and only if Element has achieved parity with Gitter based on the above list - we expect to upgrade the deployment on gitter.im to a Gitter-customised version of Element. The inevitable side-effect is that we’ll be adding new features to Element rather than Gitter going forwards.
We’re almost at the point of being able to switch Gitter over to being a branded Element.
Apparently, that has not been a priority in many years.
Matrix/Element is so far behind usability/features that it's really only used by people that favor decentralization/openess at the expense of actual users.
Also, being based in the UAE doesn't inspire confidence on the privacy and security front... Nor the fact they promised to release yearly transparency reports and then never did so... Or the fact Der Spiegel claims they have evidence of Telegram handing over user chats to authorities despite the fact telegrams FAQ claims they have never done so...
> Also, being based in the UAE doesn't inspire confidence on the privacy and security front...
Well the 5 eyes do not inspire confidence either, and that's where whatsapp is based.
And Apple has plans to automatically inform law enforcement from device scans. At least telegram client is open source so that is unlikely to happen on the client side directly.
You also lose talking to more than 1 person at the same time.
Also AFAIK Telegram has access to the plain text data from stickers so when they are downloaded by a person on a secret chat, everybody with server access can also figure a bit of the context of the conversation.
And everyone from all companies to which Telegram will sell the data once they figure that there is a good money to be made from it.
If they have the plain text data they can do whatever they want with it.
It uses a homebrew encryption scheme and does not have E2E encryption (yes, you can enable E2E for individual chats, but nobody uses it because it breaks most features).
Not to mention the weird corporate structure, lack of transparency, failed crypto token launch, dishonest marketing...
Please stop with that. At some point every encryption scheme was "homebrew" (or rather, new). MTProto 1.0 had flaws, which were addressed in 2.0. The latter has been independently formally verified to be secure[0].
> Telegram is the least secure.
Against who? What is your threat model? Such absolutist blanket statements are useless by design.
> of all the major messengers
Which are Messenger, Whatsapp, and SMS/RCS around here. Signal shows up from time to time, and Matrix doesn't even register above statistical noise so I won't count them as "major" (Signal, being, in a stroke of optimism, at best a challenger)
Of these, SMS/RCS is a total clusterfuck, and the remainder is owned by Meta. Yes, Meta is high on my list of adversaries, and given their track record should probably be for anyone out there caring about their privacy. No, WhatsApp's E2E is not to be trusted[1][2].
So is Telegram the least secure of major messengers? definitely not.
Is Telegram perfect security, certainly not either, because that doesn't exist[6], but their E2E is solid, even without E2E, extra steps are taken to thwart certain adversaries[3][4], they have reproducible builds for their client binary builds[5], and as can be observed so far their actions are veering on the complete opposite side of Meta's.
Is Telegram an opportunity to convince non-{privacy,security}-minded random joes and janes to jump out of a bunch of terrible chat platform for a better (or less worse if you want) chat platform? I'd say probably. I mean, it really really looks like they're trying hard to get the job done.
[0]: https://github.com/miculan/telegram-mtproto2-verification
[1]: https://twitter.com/Shiftreduce/status/1347546599384346624
[2]: Meta controls the Es in this "E2E", and I won't trust that, ever.
[3]: https://telegram.org/faq#q-do-you-process-data-requests
[4]: https://security.stackexchange.com/questions/238562/how-does...
For example, if you travel internationally with a different SIM card, iMessage doesn’t allow your main phone number to be used for iMessage any more.
Another terrible “feature” is that to have a complete history of your chats, you need to back up to iCloud. Even for plaintext messages. And uploading photos will quickly blow through your iCloud storage.
Telegram, on the other hand, maintains your complete searchable message history including media for free, and when your phone number changes, it just asks “hey did your phone number change?” You press no, and the experience is completely identical.
Whereas when your phone number goes away on iMessage, you’ll have to fiddle around with settings to get something else working, your contacts will be fucked, and people will have issues sending you messages, etc.
In telegram, the model is that my messages are associated with me. In iMessage, the model is that my messages are associated with my device and SIM card. I think the latter model is boneheaded for a personal messaging app. Which means that iMessage is fundamentally problematic.
Sorry for my iMessage rant, but I do love telegram :)
Indeed, it is. I did not mention it because it's Apple ecosystem only, leaving a lot of people out. It appears to do many things very right, some lacking, and a few "wrong".
AIUI, with Messages backups in iCloud disabled, each device has its own key. Each message sent gets E2E encrypted with the key to each destination device and sent once for each device. So if the recipient has three devices, that's three encryptions and three messages sent. (That's how I recall someone describing it back in the day, I'm not sure today and I can't find the source of that anymore)
> Another terrible “feature” is that to have a complete history of your chats, you need to back up to iCloud.
The above means that a newly added device doesn't get access to the message history. This actually implements perfect forward secrecy! An attacker who manages to convince someone in some way to add a new device would a) be name to decrypt any old message intercepted and b) only be able to see new messages.
In that setup the only thing really lacking is being able to jointly check a contact (sender or recipient) key via a secondary channel and maybe TOFU it and displaying a warning when a contact key is added, changed, or revoked. You do get a warning for new devices added to your account but it could also apply to already added devices who unexpectedly get a new key.
Enabling backups in iCloud breaks perfect forward secrecy somewhat since the goal is being able to obtain the whole history, so an attacker managing to enroll a new device would presumably get the history. That said I also hear that this iCloud backup isn't zero-trust encrypted (technically it could be, think borg backup) but I'm really not sure about that.
> And uploading photos will quickly blow through your iCloud storage.
Not just that, it seems to do an absolutely terrible job at clearing the local cache, eating space like crazy and with no easy option to clear it: the settings app storage section is hopeless in that regard, Telegram's way of handling that manually plus the automated ones are muuuch more clear.
> For example, if you travel internationally with a different SIM card, iMessage doesn’t allow your main phone number to be used for iMessage any more.
I did not witness that when swapping SIM cards with new numbers: Messages popped up a dialog or something asking "keep using +XXXXXX" || "use +YYYYYY". I seem to recall I could even have both numbers for some time (IIRC there was a 2 week - or was it one month? - delay before a number is forcefully dropped out if you don't pop the SIM with that number back in). It was annoying the hell out of me as it was a short-lived number that was temporarily assigned while my real number was transferred between operators. My mistake though for tapping the wrong answer, but admittedly something there could use some improvement.
That was with local numbers though, the international story might be different? I would not expect that though as it would be truly an awful experience for international travelers that swap SIMs on non-multiSIM (eSIM+tray) iPhones.
And finally there's trust... it's completely closed and very hard to audit, but then again Apple owns the OS and hardware, so one could audit the app all they want, they have a much more potent vector for exfiltration.
[0] https://www.whatsapp.com/security/WhatsApp-Security-Whitepap...
That said, WhatsApp using the E2E Signal protocol is immaterial if they exfilter the locally stored private keys out to their servers, which is what the redaction of that line in the whitepaper we both linked (you directly, me via that Twitter link highlighting the diff) alludes to:
> At no time does the WhatsApp server has access to any of the client's private key.
Unless one checks every update of the client's code and the matching published reproducible binary output one can't be sure that keys (or any other data for that matter, since it has full access to anything decrypted) are not exfiltrated.
Now, that line deletion could be a subtle canary because law enforcement/state actor, or that could be Meta being nefarious following the cofounders departure, or anything in between. Either way I find it a worrisome signal that this specific line has been removed.
They don't do that.
Biggest issue with WA is the backup mechanism. You can encrypt it with a passphrase nowadays but AFAIK that's off by default, rendering E2E moot if either party backs it up to their Google Drive.
Seems legit, I see no reason whatsoever not to trust them completely at their word. No company has ever lied to anyone before after all.
factual statement is made by said company
doesn't elaborate
gigachad.jpg
Telegram is great for other no privacy related stuff as bots, channels and groups.