Telegram just stores everything on their servers in Dubai, in the clear.
Really? Why do I need to provide a phone number in order to register for the username test?
Do you have a recommendation on how they would prevent fraud and abuse w/o using a phone number while also maintaining the same level of low friction?
(In fact, I do still expect public phone numbers to be the "default", i.e. encouraged, experience, because of its viral properties. This is also fine by me, as I want Signal to be used by as many people as possible.)
While I share your concerns about Intel SGX, your statement is not exactly true: SGX is only meant as an additional measure to secure insecure PINs.
I once worked for a company that happened to find itself in possession of a nearly complete social graph of one of the rich countries. The goal of the project was a different one, that graph was a kind of side effect. The graph was never actually used, but the company did have it.
Producing the graph was neither difficult nor expensive. I believe the complete project cost only a little over €1M.
If you want to gather data like that, you can do it without any expensive intelligence operations or attacks. You can spend a million on writing a desirable free smartphone app that needs contact permissions and another few hundred thousand on promoting the app, then sit back while the data is uploaded to your servers. To me that appraoch sounds a lot simpler and cheaper than breaking into Signal, Intel/SGX or a DC hoster.
I suggest that attacking anyone to get their contact data isn't really desirable.
Now making it into an actually viable business is very hard (I'm not sure we ever managed it), but the hard parts aren't the technical side of implementing a chat app.
That is, when you power of a Telegram server.
Ten per cent more difficult, OK. But ten thousand per cent?