To anyone who wants to complain about Telegram not encrypting chats by default and using "homebrew crypto" I'd like to say that it's XMPP we're discussing here. Telegram offers marginally better security than XMPP over TLS. The "homebrew crypto" is still not broken in 10 years and not for the lack of trying.
I think you should compare apples to apples, that is, end-to-end encrypted XMPP using OTR/OMEMO/PGP. However, I agree that many XMPP clients were UX disaster when using E2E.
Yeah, and the private keys are shared with Roskompozor.
https://techcrunch.com/2023/10/19/telegram-is-still-leaking-...
Your IP address is public. Stop treating it like a secret.
And no, your IP should not be made public in any modern chat app, that's ridiculous. The fact that Discord protects your IP from leaks is at least half of the reason it's so successful.
Peer-to-peer communication reveals people's IP addresses to each other, what a sensational revelation! By the way, water is wet.
All voice can be E2E thru servers, like Signal does.
If you’re using it to communicate to a hostile party who would love to unmask you, then very not so much. Personally I’m not in the second category but I’m sure some are.
Since this thread is about XMPP, Telegram's security is effectively the same as XMPP over TLS, maybe a bit better because there isn't a trusted third party (the CA).
> All voice can be E2E thru servers, like Signal does.
I know that. In fact, I built the first VoIP implementation for Telegram, libtgvoip, myself from scratch. Relay servers add delay, can run out of capacity, and cost money in bandwidth. Of course relays are still used if a P2P connection can not be established (libtgvoip always started the call through the relays and only switched to P2P if pings went through and RTT was lower, that took at least several seconds before enough statistics was gathered).
To be honest, Telegram using homemade crypto instead of relying on standard approaches like CA certs turned out to be good solution in the end. Apps should stop trusting CA and should hardcode public certificates instead.
Regardless, using open and verified cryptographic primitives is a best practice for a reason. As are audits. The likelihood any company can start from scratch and produce a flawless solution is a number approaching zero.
I'd feel much more comfortable with something using Signal protocol. Ideally built from independently audited source.
It requires phone number.
I'd say these are security issues
so does Telegram
> requires a primary Android or iOS devices
so does Telegram