They are referring to in-transit message over Internet as virtually indecipherable: Nothing a court warrant can't get directly from their servers.
Moxie also "rolled his own crypto". "Rolling your own crypto" is typically used disparagingly by those who claim moral or intellectual superiority over the competition. The Signal Protocol was rolled by someone, yes? The version of MTProto that had vulnerabilities discovered was deprecated many years ago.
This is where the privacy promise falls apart. From a user's perspective on-disk encryption makes no difference, because there is no real enhancement of privacy for them. If a third party holds the key, they hold the key. If you put something into the hotel safe, the hotel could still steal it from you. As far as I can tell, most TG users are not aware or do not care, but for those who are not aware, but actually do care, this should be made much more clear.
> Moxie also "rolled his own crypto"
Besides Moxie being a bit dubious himself, the more interesting question is: was there something that was already verified by many people that could have been used instead?
Use another messenger if you like but e2ee encryption is not some moral imperative that must be done. There are always trade-offs. I appreciate Telegram for the purposes I use it for. If I want e2ee, I turn on a Secret Chat.
I just think that Telegram tries to position itself as some kind of subversive and secure messenger (successfully so), which it isn't and I find that dubious. I can see that many people prefer it for its user experience, which is fair, but people should not be lured by a false sense of security.
> e2ee encryption is not some moral imperative that must be done.
It is not a moral imperative, but a protection against many evils, that most people probably would benefit from if used consistently. I've got low tolerance for trying to artificially limit e2ee though.
The way he is attacking this alternative Signal client and rules out interoperability:
https://github.com/LibreSignal/LibreSignal/issues/37#issueco...
Signal was a word before he decided to turn it into a brand.
The signal server source code repo was not updated for a year. Communication intransparent.
https://www.androidpolice.com/2021/04/06/it-looks-like-signa...
I am not even against crypto integration, but I found the choice of MobileCoin odd. Instead of integrating an existing privacy coin or working with the community, he decided to integrate MOB and to be one of their "advisors":
https://techcrunch.com/2018/04/24/mobilecoin-moxie-marlinspi...
Most people think of “private” as between the conversation parties, not everyone in the conversation, the company, and any government with leverage on them.
Encryption at rest prevents from some intrusion attacks but does absolutely nothing against a warrant if the government has leverage.
I did not claim that.
When I wrote:
> Telegram disguises itself as encrypted chat app
I meant exactly that.
(Just to clarify: I like Telegram. I just don't like Durov very much and the way he positions Telegram as the superior messenger in every way, even though it obviously isn't when it comes to encryption in particular.)
What I was expecting from Telegram (although it doesn't look like they plan to do this) is synced, E2E encrypted cloud chats. So any new device I add has access to all the previous message history, and is independent of all other devices.
Don't worry, you're safe from hackers, deep state, and foreign nation-state from eavesdropping on ya over the net through their awesomely robust and intensely-touted advertised EE2E capability.