Uhm what? It's 2023 and they still don't do e2e encryption by default. Building a chat application without e2ee is orders of magnitude easier than with. And let's not talk about MTProto…
The app is full of tiny annoyances like this. For sending photos there are some editing/cropping tools - a fun and somewhat useful innovation, but while the crop handles work from the corners of an image they don't work properly from the sides. I was a busy evangelist for the product in its early days, now I hate using it.
To be clear, Signal now allows secure backups to the cloud. If you don't use a strong password, and much as the public won't, it's not perfect but they maximize the security. (And you can always choose to not use the backup.)
https://signal.org/blog/secure-value-recovery/
(It's also relevant to the OP.)
No, it doesn’t, at least on iOS. There is no backup option on iOS. The only way to retain information when using a new device is to have the old device close by and transfer it by running Signal on both of them. Anyone who loses their device or does not have it with them when getting and setting up a new device will lose all the messages from the older/previous device.
- Apple implemented iMessage E2EE sync across devices back in 2011. But be careful not to save your chat keys in iCloud backups (local backups are fine), unless you enable E2EE for iCloud backups as well, which is an option rolled out in 2023.
- WhatsApp appears to have rolled out a form of E2EE device sync in 2023 as well. WhatsApp Web complicates the question of how secure is the E2EE though.
Telegram just stores everything on their servers in Dubai, in the clear.
Really? Why do I need to provide a phone number in order to register for the username test?
(In fact, I do still expect public phone numbers to be the "default", i.e. encouraged, experience, because of its viral properties. This is also fine by me, as I want Signal to be used by as many people as possible.)
Do you have a recommendation on how they would prevent fraud and abuse w/o using a phone number while also maintaining the same level of low friction?
I once worked for a company that happened to find itself in possession of a nearly complete social graph of one of the rich countries. The goal of the project was a different one, that graph was a kind of side effect. The graph was never actually used, but the company did have it.
Producing the graph was neither difficult nor expensive. I believe the complete project cost only a little over €1M.
If you want to gather data like that, you can do it without any expensive intelligence operations or attacks. You can spend a million on writing a desirable free smartphone app that needs contact permissions and another few hundred thousand on promoting the app, then sit back while the data is uploaded to your servers. To me that appraoch sounds a lot simpler and cheaper than breaking into Signal, Intel/SGX or a DC hoster.
I suggest that attacking anyone to get their contact data isn't really desirable.
While I share your concerns about Intel SGX, your statement is not exactly true: SGX is only meant as an additional measure to secure insecure PINs.
Now making it into an actually viable business is very hard (I'm not sure we ever managed it), but the hard parts aren't the technical side of implementing a chat app.
That is, when you power of a Telegram server.
Ten per cent more difficult, OK. But ten thousand per cent?
Telegram openly does not have e2e by default.
What it also didn't have that I think Signal at some point had was:
- a bug that sent photos(?) to persons without you asking
- a rather nasty vulnerability that let people send you a message and pwn your desktop environment
For some reason a large subset of HN is like E2E or nothing. But I remind folks that except in very particular cases, all email is available to one email provider or the other.
Same goes for banking etc. But for some reason according to HN my postcard level communication with my family demands I use a system with a tenth of the usability of Telegram.
I used Telegram in E2EE mode with someone initially, but later we decided the multi-device sync and web chat were so much more useful to us, it trumped the desirability of E2EE and we switched.
Those features together would be better of course.