> Signal is cooler
Clearly you haven't tried using Signal on multiple devices. It's terrible currently. Telegram / WhatsApp / etc work great on multiple devices.
Because all the really security focused apps insist on per-device private keys, so everything has to be re-encrypted by everyone per the other users' device. This mitigates key leakage problems to some extent, but also makes the UX as awful as you describe.
I don't understand why nobody (to my knowledge) has yet gone the middle route of having a private key per user. Sure, it's a bit less secure, but it's surely better than users preferring to use un(e2e)encrypted options instead?!
That's what Telegram actually does with their cloud encryption.
It's more like end-to-Google-to-end. If you choose to decline this default, your conversation partners probably haven't.
Signal had a catastrophic bug that would send random images in your camera roll to random contacts. If you want your private photos sent to your family members, use Signal I guess.
Does it? I have criticized WhatsApp a lot, but this was new to me.
(I don't follow WhatsApp development any more but back in the day they used to do things like sending data actually unencrypted - not just not e2e-encrypted - over port 443, and storing unencrypted backups on Google Drive, but encryption keys was/is new to me if it is correct.)
This is a lie[1]. If you don't enable backups yourself, you loose your messages. You can enable E2E encryption for your backups.
WhatsApp is vastly superior to Telegram in terms of E2E encryption. Telegram can read users messages on their servers and they are not even trying to tell their users to enable E2E.
[1] https://www.tomsguide.com/news/whatsapp-encrypted-backups
I must reiterate that this is a baseless claim because no one can see WhatsApp's source code and going by the track record of Facebook as a company, I'd rather choose to reject this statement than accept it as a possibility.
Decompiling and inspecting mobile apps is relatively simple, so if there were any issues with the WhatsApp client, they would likely have been uncovered already.
As for Telegram, its messages are stored in plain text on their servers, and it doesn't offer default end-to-end encryption. This means that if Russian secret services were to gain access to Telegram's backend, they could easily read all the messages.
Therefore, when using Telegram, it's important to be aware that its administrators have the ability to read all of your messages.
Backend is never verifiable. It's a moot point. Signal's backend is open source yet they always release the sources late. Their servers were running entirely different code for a year and they even injected some cryptocurrency related features which weren't reflected in the source code.
Backend is always unverifiable, open source or not.
> Decompiling and inspecting mobile apps is relatively simple
Not so much when WhatsApp obfuscates binaries on purpose.
On top of that, the T&C clearly forbid you from doing it.
> As for Telegram, its messages are stored in plain text on their servers
Absolutely false. Telegram's cloud encryption algorithm has already been audited by independent researchers.
Calling symmetric encryption as "plain text", is disingenuous.
> This means that if Russian secret services were to gain access to Telegram's backend, they could easily read all the messages.
I guess Russia's telegram ban doesn't matter then? Nor Durov's fight with the Russian government. He actually moved to another country to stop the Russian government from having access to the servers.
It's totally fine to understand your security context and the security your messaging medium provides but it's not good to misrepresent facts and use terms that mislead people.
Even with Telegram's encryption, messages can be compromised through a straightforward SIM swap. This means that their encryption is essentially irrelevant since messages can be read without needing an encryption key from the client.
I recommend checking out Moxie Marlinspike's Twitter thread on this topic for further insight. You can find the link I previously shared in another thread.
Actually there is. The backend transferring information is the sole point of failure. While the message content might be secure, nothing other than that ever is. In fact, an E2EE app could send unencrypted messages in the payload or the private keys and you still wouldn't be able to do anything about it.
This is why I question WhatsApp's effectiveness in the first place.
> Even with Telegram's encryption, messages can be compromised through a straightforward SIM swap
2FA - Cloud Passwords have existed for a long time. Most people fail to mention it when mentioning SIM swap, which is a physical device security issue, a responsibility of the user.
> I recommend checking out Moxie Marlinspike's Twitter thread on this topic for further insight.
I'm sorry but I consider that misinformation at worst and propaganda at best.
He thinks that any encryption that's not his, is 'plain-text'. On top of that, he's very much the reason why Signal was never released on F-Droid. He's got some weird biases against other tech that he can go to any lengths to defend it.
Not only are his Twitter threads loaded with bias but the language he chooses to use, I'd consider that plain misinformation. He does not have any authority to claim things he can't prove.
Regardless, chances are your contacts have enabled the Google backdoor if you haven't.
>WhatsApp is vastly superior to Telegram in terms of E2E encryption
That's why CVE-2020-1910 enabled attackers to steal your entire message history with a single image message. Has Telegram had similar catastrophic E2E exploits? Nope.
>Telegram can read users messages on their servers
Google has your WhatsApp "E2E" private key by default -- meaning it is NOT end-to-end encrypted. Telegram's E2E Secret Chats have no such backdoor.
Why? First time I can remember top critical comment has gotten encrypted/e2e-encrypted correct :-)
Well, you can buy a number (+888) on fragment and use one instead of your own.
Why?
Because countries insist on linking phone numbers to individuals.
Why do I think this is borderline ridiculous?
Because the phone system is still so open that any scammer can appear to call from any number, or even temporarily hijack reception of messages and calls.
I just looked and all of the "ending soon" auctions have prices of $150 and up. With several of them at $4,000 and more. I know nothing about Fragment but I can only assume there's some kind of money laundering or other illegal activity involved to justify those prices.
Those are nice looking ones. Some people spent great amounts of money to buy a nice phone number or a car plate (at least in Russia or Armenia for example).
A car plate\registration number like M888MM 777 will cost you 10M rubles ~122k USD.
No I can't.
Costs like $0.2
Because it's primarily a chat app, just like Signal or WhatsApp.
They're more open than the alternatives but they still function with the old app-first philosophy.