Telegram Web Apps for Bots
core.telegram.org
core.telegram.org
I recently examined a situation where confidential messages from high-ranking Moldovan officials were leaked through Telegram. Unlike WhatsApp and Signal, which offer end-to-end encryption by default, protecting your messages even in case of a SIM swap, Telegram does not offer the same level of security. A SIM swap or a breach in their system can lead to message leaks.
Despite advertising themselves as a "secure messaging" platform, Telegram lacks default end-to-end encryption, making it less secure than its competitors.
Read this excellent thread from Moxie https://twitter.com/moxie/status/1474067549574688768
https://www.wired.com/story/the-kremlin-has-entered-the-chat...
https://euromaidanpress.com/2023/04/07/russian-fsb-has-the-k...
https://pdmnews-ru.translate.goog/25704/?_x_tr_sl=auto&_x_tr...
You may or may not trust these sources, however, even just the fact that at one point Durov was extremely afraid of being found by FSB, Telegram being the only network not blocked in Russia, and general embrace of Telegram by Russian propagandists, speaks for itself.
Second, Telegram not being blocked is hardly an argument. Neither are Signal, WhatsApp or YouTube for example. Are all of these also controlled by the FSB? And the general embrace of z-propagandists is likely due the fact that Telegram is extremely popular all over post-Soviet space. As far as I know, pro-Ukrainian people use Telegram just as much, and just as much as a news source.
None of this is to say that Telegram is a good choice for a reasonably secure messenger or is trustworthy at all (and [1] lists some very convincing reasons for why it is not so). But "may be run by the feds" is a strong claim, and so far it is not supported by evidence.
[1] https://www.pwnallthethings.com/p/russia-is-spying-on-telegr...
This is not true. WhatsApp is still working. They banned facebook and instagram but not whatsapp. Viber, Signal, Threema, Wire still works, too. The only blocked currently, i think, is Line.
Not saying "trust telegram", but still.
All major intelligence agencies are probably neck deep in these activities.
Someone added two clients while I was asleep around new year.
I kicked them out and threw in a password and they tried again (unsuccessfully :) next night.
Meanwhile, way bigger leaks has happened from WhatsApp over the years.
If security is important to you, use something that is made for security, like Signal or Matrix, not "good enough call it secure" like Telegram or "how much data can we get away with stealing" like any Meta product.
Also Moxie is extremely biased.
https://www.wired.com/story/moldova-leaks-google-privacy-set...
1. SIM Swap is a physical device security issue, not something that telegram or any other app for that matter, is responsible for. Telegram already provides cloud password, comments like these wouldn't ever mention it.
2. Telegram using cloud encryption instead of E2EE by default does not make it less secure. In fact, it only makes it secure in a different way. Proponents of WhatsApp, kindly direct me towards an independent audit or research paper that confirms WhatsApp is using E2EE 100% of the time instead of 95% or even 5% of the time. The classic "but WhatsApp has E2EE" argument is as good as me saying that I'm the CEO of Google writing from an alt account. Telegram's encryption, both E2E and Cloud, have been audited by independent researchers. It doesn't take much to find out what's true and what's not.
3. Moxie's claims are extremely biased and misleading to the point that it almost seems like a propaganda against Telegram. I wouldn't want to hear someone who thinks Signal is too good to be on F-Droid and that any encryption aside from his own is the same as plain text.
If you want and need E2EE please God use some other messenger but why don't we stick to the topic of the feature announcement and save the hate, folks?
If you're a user of Signal, I support your choice to use Signal. Please support our choice to use Telegram.
This is proven by the fact that posts about WhatsApp, a closed source app from Facebook where you can never even confirm any of their security claims, gets a lot of praise compared to an open source app with a strong privacy and no-data-selling track record. Even here in the comments you can see people claiming about WhatsApp's E2EE when in reality they cannot prove it.
Telegram on the other hand has been audited multiple times by independent researchers and yet somehow, that's not enough. Apparently, symmetric encryption is considered plain-text these days and some closed source unverified implementation of E2EE as private and secure.
The world is a weird place.
Telegram is said to have been given authorities access to user data [1], despite the fact that they advertise the opposite. I guess that’s what happens when your app is not encrypted E2E by default.
Also, they have used their own encryption algorithm in the past (I don’t know now) instead of the well known and proven algorithms out there. Something highly criticized by experts, back then [2]
-[1] https://www.androidpolice.com/telegram-germany-user-data-sur... -[2] https://eprint.iacr.org/2015/1177
why not just look this info up before replying ?
It's no stretch of the imagination that this will replace many, if not most app ui's. For the time being there's still some programs that are much better off with a dedicated interface, but the future where the starting point for most day-to-day computer interactions is a unified natural language text input is very near.
It's striking to me how close this matches the depiction in the movie "Her".
Messenger apps like telegram do have an opportunity here, but I think the most likely way for this to play out is that apple and google will eventually make their assistants the front and center way of interacting with your phone and their won't be much that messenger apps can do about it, even if they are substantially faster at implementing this.
The reason for my doubt is that if you look around yourself; you will see a variety of amazing human computer and human machine interfaces, because no single interface has been universally suitable and more importantly the most or even reasonably efficient for all use cases. There is little reason to believe human language is an exception.
Switches, buttons, knobs, joysticks, motion sensors, and an array of other interfaces will persist until brain-computer interface is ubiquitous.
This is the essence of it; and it follows not just for "shouldn't be a computer" appliances but also software. People in tech tend of to forget about the array of hyper-specialist software that exists in the wild, from little point of sales to industrial machines.
I have little interest in talking to a coffee machine or automated transport ticket machine. Flat White. Day ticket. That would do, thanks.
But besides this I do see your point. Mechanical interaction with buttons, switches, dials and the like offer a great interface and they haven't been universally replaced by touch screens for a reason.
I was thinking more of the ubiquity of specialised phone apps. I checked my phone just now and I have apps for public transport (i.e. train tickets and routes), taxis/ubers, multiple apps for ordering food, fitness/workout tracking, todo apps, calendars, smart home control, weather, general search, news and lots more. I'd say that most uses of most of those apps would be more convenient through a single chat like interface.
Wasn't the Allo app supposed to do that?
(I'm still looking for a replacement for Google+.)
Now Google... put em in Gmail and Calendar webapps as a sidebar integration and a big-ass button on mobile
but no matter how good the api is if you must install something worse to talk to your friends.
IM applications are the new socialnetworks, and as such will be decided by network effect, everything else will be a consequence.
so, the best solution is the one that can be shoehorned into the whatever api quality the top IM application offers, which is not telegram
Exactly yesterday I thought that I got a spam message, it turns out that the sender is a SpaceX fan and a real interesting human, not the crypto-pushing bot that I had suspected at first when I read the greeting "hi".
Username in telegram is a public identifier that allow anyone to grant the permission to message you.
The other ways to grant this permission are
1. Add contact with phone number (can be disabled in privacy setting)
2. Have a message/forward message somewhere you can see, and the original sender is you. (Identity forward of forwarded message can be disabled in privacy setting)
3. Be in the same group with the target (chat admin can disable member listing)
Notice, this is a one time setup. A account only need to grant this once, and then he can message you at anytime.
I don't get that much spam in Telegram either, but this must be an exaggeration. My WhatsApp and Signal accounts get completely zero spam.
On the android client you find this option under privacy. Pretty sure it never hasn't been there
Did you set every option to 'Nobody' or 'My contacts only'?
The only way to do so is to have a username or phone number of recipient. Usernames are searchable if they are "Public Usernames". Phone number could be hidden from anyone.
I don't see how someone can contact somebody on the messenger yet without an ability to.. actually send a message. Sure, there could be an option to block everyone not in the contact list and use some other medium to relay the contact request[0] but most of the time this is useless for messenger.
But of course I have my POV skewed, because I prefer to use services defensively from the start so I had almost no unsolicited messages on Telegram, WhatsApp and Instagram.
[0] Hey, if you interested in $TOPIC contact me on Telegram, @username! But first send a couple of avian carriers with your phone number and username so I could add you to contacts first!
WhatsApp bots are overly simplistic. I'm not talking about specific implementations where bots only accept simple strings or just integer numbers (your typical city bot), I know that's not WhatsApp's fault.
It's just that WhatsApp bot capabilities have these 1.0 vibes. Bots that just chat and aren't rich anyhow like Telegram ones. WhatsApp bots don't come close, and WhatsApp users live in such Plato's Cave with it.
I just wish The West could come up with something like this, and at the same time not coming from your typical FAANG. That'd make me jump ship. Such a great product management.
Also, Zuckerberg is so deep in the privacy troubles with the Congress, that he cannot open WhatsApp Bot API freely like Telegram can. That hinders the development of bots in WhatsApp a lot.
Only big companies have direct WhatsApp API access and are able to re-sell it through tech partnerships (e.g.: You cannot call WhatsApp's API directly, you have to pay a company like Freshworks for its Freshchat product and then you can use WhatsApp's API indirectly through Freshchat API, walling the garden this much is just non-sense).
--
Full disclosure: I love Telegram far more than WhatsApp. I resent WhatsApp because I'm not able to quit it because of network effects. I also recently berated my phone carrier for offering WhatsApp for free, but not other messenger apps (which also violates my net neutrality rights).
Disclaimer: I know Telegram gets a lot of hate because of its Russian origins. Same hate TikTok gets for seemingly being CCP-controlled.
At least I managed to vent the steam off by setting an image that asks to write to me via Telegram instead as my avatar. You can find it here: https://gist.github.com/Self-Perfection/f470d5120f938221769d.... The image is in SVG format, so you can customize it to your liking.
For some reason it works for eastern people but barely for westerners. Every product made had more success with an additional web app. I always assumed it's because bots look all the same, it's hard to find scam indicators.
WeChat has had this for years (and other messengers in South Wast Asia).
I have no idea why in-chat apps were never successfully implemented in the "West". There were minimal attempts by bot Apple and Facebook to add apps to their chats, but at best it's "let's add stickers"
When I had to use it on my first visit to China, I couldn't possibly believe this is an app that people are actually using day to day. Slow, sluggish, graphical artifacts, NPEs.
Then I learned that the "Western" version is totally different, so I believe the real WeChat is a usable product and in par with whatsapp and telegram
Walled gardens and controlled ecosystems are horrible and concentrate power in the gatekeepers.
I hope the experience is kludgy and user unfriendly to the point that startups not contained in the straightjackets of other systems continue to win out.
"Back in the time" I would've used email for that, but if you don't run your own server, getting a free email address that doesn't either need a phone number verification, doesn't get banned for random reasons or doesn't stop working suddenly, because it decided it needed 2 factor authenticaion is practically impossible.
(btw, if anyone knows a service, that gives you a free email address (well, more than one) with smtp access, no phone number or any other verification and doesn't ban accounts after a few automated messages, please tell.. I don't care about getting marked as spam, I can whitelist it on my side)
One thing I like about chat is the different mindset and granularity. I can have a bot post a message to a channel for normal messages and then tag me, thus giving me a notification, for urgent matters. Email is more like digital mail, I don't want to have to check it often (I disable email notifications).
The same can't be said about the third-party client protocol, which is a perfect example of NIH syndrome. Where the bot API is bog standard JSON over HTTPS, the client API has its own encryption protocol, its own connection protocol, its own serialization standard and its own schema language. Everything is reasonably well documented, but some of the documentation (particularly for the schema/serialization part) is somewhat hard to understand if you're not a mathematician and/or well-versed in statically-typed functional languages like Haskell and the associated theory. Some parts, voice and video calls in particular aren't documented at all. Where every other part of the API has a precisely defined schema, this one just expects a binary blob of unspecified contents. There's a tgcalls library (written in C++) that implements this protocol, but its Github repository doesn't contain the needed build scripts nor any information on what other libraries it relies on (and it definitely relies on at least WebRTC and probably some others.)
Just build a webapp.
Allowing third-party JavaScript execution on the client is a bold move. They better have both user- and admin-accessible way to disable this.
It's more like end-to-Google-to-end. If you choose to decline this default, your conversation partners probably haven't.
Signal had a catastrophic bug that would send random images in your camera roll to random contacts. If you want your private photos sent to your family members, use Signal I guess.
Does it? I have criticized WhatsApp a lot, but this was new to me.
(I don't follow WhatsApp development any more but back in the day they used to do things like sending data actually unencrypted - not just not e2e-encrypted - over port 443, and storing unencrypted backups on Google Drive, but encryption keys was/is new to me if it is correct.)
This is a lie[1]. If you don't enable backups yourself, you loose your messages. You can enable E2E encryption for your backups.
WhatsApp is vastly superior to Telegram in terms of E2E encryption. Telegram can read users messages on their servers and they are not even trying to tell their users to enable E2E.
[1] https://www.tomsguide.com/news/whatsapp-encrypted-backups
Regardless, chances are your contacts have enabled the Google backdoor if you haven't.
>WhatsApp is vastly superior to Telegram in terms of E2E encryption
That's why CVE-2020-1910 enabled attackers to steal your entire message history with a single image message. Has Telegram had similar catastrophic E2E exploits? Nope.
>Telegram can read users messages on their servers
Google has your WhatsApp "E2E" private key by default -- meaning it is NOT end-to-end encrypted. Telegram's E2E Secret Chats have no such backdoor.
I must reiterate that this is a baseless claim because no one can see WhatsApp's source code and going by the track record of Facebook as a company, I'd rather choose to reject this statement than accept it as a possibility.
Decompiling and inspecting mobile apps is relatively simple, so if there were any issues with the WhatsApp client, they would likely have been uncovered already.
As for Telegram, its messages are stored in plain text on their servers, and it doesn't offer default end-to-end encryption. This means that if Russian secret services were to gain access to Telegram's backend, they could easily read all the messages.
Therefore, when using Telegram, it's important to be aware that its administrators have the ability to read all of your messages.
Backend is never verifiable. It's a moot point. Signal's backend is open source yet they always release the sources late. Their servers were running entirely different code for a year and they even injected some cryptocurrency related features which weren't reflected in the source code.
Backend is always unverifiable, open source or not.
> Decompiling and inspecting mobile apps is relatively simple
Not so much when WhatsApp obfuscates binaries on purpose.
On top of that, the T&C clearly forbid you from doing it.
> As for Telegram, its messages are stored in plain text on their servers
Absolutely false. Telegram's cloud encryption algorithm has already been audited by independent researchers.
Calling symmetric encryption as "plain text", is disingenuous.
> This means that if Russian secret services were to gain access to Telegram's backend, they could easily read all the messages.
I guess Russia's telegram ban doesn't matter then? Nor Durov's fight with the Russian government. He actually moved to another country to stop the Russian government from having access to the servers.
It's totally fine to understand your security context and the security your messaging medium provides but it's not good to misrepresent facts and use terms that mislead people.
Even with Telegram's encryption, messages can be compromised through a straightforward SIM swap. This means that their encryption is essentially irrelevant since messages can be read without needing an encryption key from the client.
I recommend checking out Moxie Marlinspike's Twitter thread on this topic for further insight. You can find the link I previously shared in another thread.
Actually there is. The backend transferring information is the sole point of failure. While the message content might be secure, nothing other than that ever is. In fact, an E2EE app could send unencrypted messages in the payload or the private keys and you still wouldn't be able to do anything about it.
This is why I question WhatsApp's effectiveness in the first place.
> Even with Telegram's encryption, messages can be compromised through a straightforward SIM swap
2FA - Cloud Passwords have existed for a long time. Most people fail to mention it when mentioning SIM swap, which is a physical device security issue, a responsibility of the user.
> I recommend checking out Moxie Marlinspike's Twitter thread on this topic for further insight.
I'm sorry but I consider that misinformation at worst and propaganda at best.
He thinks that any encryption that's not his, is 'plain-text'. On top of that, he's very much the reason why Signal was never released on F-Droid. He's got some weird biases against other tech that he can go to any lengths to defend it.
Not only are his Twitter threads loaded with bias but the language he chooses to use, I'd consider that plain misinformation. He does not have any authority to claim things he can't prove.
Why? First time I can remember top critical comment has gotten encrypted/e2e-encrypted correct :-)
> Signal is cooler
Clearly you haven't tried using Signal on multiple devices. It's terrible currently. Telegram / WhatsApp / etc work great on multiple devices.
Because all the really security focused apps insist on per-device private keys, so everything has to be re-encrypted by everyone per the other users' device. This mitigates key leakage problems to some extent, but also makes the UX as awful as you describe.
I don't understand why nobody (to my knowledge) has yet gone the middle route of having a private key per user. Sure, it's a bit less secure, but it's surely better than users preferring to use un(e2e)encrypted options instead?!
That's what Telegram actually does with their cloud encryption.
Well, you can buy a number (+888) on fragment and use one instead of your own.
Why?
Because countries insist on linking phone numbers to individuals.
Why do I think this is borderline ridiculous?
Because the phone system is still so open that any scammer can appear to call from any number, or even temporarily hijack reception of messages and calls.
No I can't.
I just looked and all of the "ending soon" auctions have prices of $150 and up. With several of them at $4,000 and more. I know nothing about Fragment but I can only assume there's some kind of money laundering or other illegal activity involved to justify those prices.
Those are nice looking ones. Some people spent great amounts of money to buy a nice phone number or a car plate (at least in Russia or Armenia for example).
A car plate\registration number like M888MM 777 will cost you 10M rubles ~122k USD.
Costs like $0.2
Because it's primarily a chat app, just like Signal or WhatsApp.
They're more open than the alternatives but they still function with the old app-first philosophy.