Its not like its a significant difference honestly. I know people beat the E2EE drum and they definitely should: but that only makes sense if the clients are disconnected from the transport. IE: ensuring that collusion between them is less possible.
Though storing things on the server is something telegram then has to secure on your behalf, it does provide a tangible UX improvement.
Telegram supports open source and third party clients, so if you wanted the benefits of E2EE with a popular chat network then that's a better way to go. Custom clients on the telegram network.
It is best is to use something like Element/Matrix though, for sure. But if you're trading UX for convenience then materially the difference really is a lot smaller than you imply.
By switching their optional E2E encryption from their weird proprietary thing to the Signal protocol, Telegram could at least display some goodwill – but only making that the default would show that they actually care about their users privacy.
I'd be happy if it was available on desktop clients as well :D
The desktop client requiring me to constantly have the mobile with me defeats the purpose.
Still... It's an excellent product. Default e2ee, notifications on partner key changes. The main thing I'd like from it would be an option to block me from sending messages until I reauthenticate the partner, or a colour coded system like threema that serves as a reminder that without authc you really don't know who you're chatting with.
We already had that with OTP over ICQ/MSN/AIM etc. in the early 2000s. I could use it with about all of 3 other people.
And why stop there? You can always message base64-encoded PGP messages back and forth. Problem solved!
Except that defaults matter.
Also, both iMessage and WhatsApp support encrypted cloud backups.
On Telegram, I can be in rando messaging groups of people and have a username rather than a hard-to-change, legacy voice traffic routing number that's widely used for tracking.
The only improvement is if they could get rid of the requirement that you use a phone number to sign up for these services, which is a regression from AIM, MSN, ICQ, IRC and Jabber/XMPP.
That would only lead to one thing: absurd amounts of spam.
And as far as I know, Telegram still requires a phone number (or some crypto nonsense) as a primary identifier and for signups. They just allow you to hide that from your contacts.
A bunch of people I know who play video games are on Telegram. I'm pointing out that I can talk to them without sharing my phone number which I can't do on WhatsApp/Signal.
Not being stalked by weirdos is a higher priority for a lot of people than anything involving spooky Edward Snowden stuff involving the NSA, FSB, GCHQ, Mossad and Five Eyes etc.
Also matrix spaces is more elegant than telegram folders.
Depends on the threat model. If you're being in opposition to Western governments, you can be relatively sure that Telegram will stick the finger to them and not cooperate beyond occasionally shutting down public channels that promote violent terrorism and thus garner media attention.
Who has the keys? What exactly is encrypted? 1-2-1 chats? Group chats? Attachments? Are metadata handed over? Dear Autumn12 don't just read the marketing material.
In a real example: Apple's Cloud has a copy of most users' data as (by f...g default) when you activate an iphone it enables them all. I remember the case with that terrorist (was it the Boston Marathon guy?) that Apple wouldn't hack the device but they handed everything they had on their cloud to FBI.
I don't know what you want to say with your example, but there are dozens of examples where telegram did not give out data even thought they likely should have. It's definitely a more private choice to apple or meta
Yes, but not by default, and it’s weird/custom and not properly peer-reviewed.
> somewhat better than meta AND the whole US government having access to my data
How do you know that that is the case for WhatsApp?