And Telegram has been so far the most reliable, feature full and easy to use chat app I have had to use.
And if you are a developer and your software is used in any decent scale, you are unlikely to be the exception.
And in an Apples-to-Apples comparison, WhatsApp fared far worse than Telegram on privacy, and not to mention its parent company.
The only benefit I can think of WhatsApp has is claiming to be encrypted by default. So I dont need to press an extra button. I just have to take their word for it.
I'd like to see that comparison. Considering that WhatsApp is end-to-end encrypted, and Telegram persistently stores almost all of their users' messages on their backend in a way that lets them read them, I find that very hard to believe.
> So I dont need to press an extra button.
Nobody presses an extra button, especially not one that opts you out of multi-device support.
I don't think it's reasonable to expect them to actually be e2e encrypted.
Espacially since Zuckerberg has many years of poor track record for privacy, and made the famous quote "they trust me the dumb fucks"
Russian can't affect my life as much as my gov.
For contacts: I have no expectations of any contact privacy on WhatsApp. It's known and documented [1] that they upload your entire phone book for contact matching. Private set intersection would be better, but I don't see anything sneaky going on.
Audio, video, cameras: What are you referring to?
> What makes the true believers so sure their WhatsApp chats are really E2E encrypted and FB cant decrypt them and isnt scanning at the edge?
The amount of scrutiny they're under from security researchers worldwide, and the fact that many governments are currently throwing a fit about not being able to gain access to the data either.
2016 Audio: they listened to what you did through your microphone until they got caught
https://www.nbc4i.com/news/spying-secrets-is-facebook-eavesd...
2019: Facebook caught activating camera without permission, to spy on you
https://www.pcmag.com/news/facebook-app-caught-activating-ph...
2020: Facebook a year later still secretly using your camera to spy on you, this time through Instagram
https://news.ycombinator.com/item?id=24514433
This is the company you are now trusting with the mere claim that WhatsApp is end-to-end secured.
2018: Facebook, not satisfied with getting its own users’ data only, bought and hijacked a VPN app in order to — wait for it — bypass encryption that millions of people trusted for ALL SITES ON THE INTERNET in order to analyze traffic and be able to get the dirt on its competitors!
https://arstechnica.com/tech-policy/2018/08/facebook-violate...
Now about WhatsApp…
Oh yeah… it’s already sending a lot of telemetry to Facebook:
https://www.wired.com/story/whatsapp-instagram-facebook-data...
And has been since 2016:
https://www.wired.com/story/whatsapp-facebook-data-share-not...
Oh, but at least the content of your messages is not analyzed by FB? Well, as far as we know that might be true, but if the other user flags your convo, it is in fact sent to Facebook:
https://www.propublica.org/article/how-facebook-undermines-p...
But wait, there’s more. Sometimes the mask slips due to People You May Know, which is the carefully guarded mix of “secret” algorithms that has helped Facebook aggressively grow beyond 100 million people:
https://medium.com/hackernoon/facebook-is-reading-my-encrypt...
https://gizmodo.com/people-you-may-know-a-controversial-face...
Mark Z knows what’s up:
https://www.theguardian.com/technology/2016/jun/22/mark-zuck...
https://amp.theguardian.com/technology/2018/apr/17/facebook-...
Telegram has NEVER tried to do any of these types of things.
So, given a choice, would I trust Zuck and co, or a guy who literally had to flee Russia because at great personal cost he had refused disclose the identities of the Maidan protestors, and losing his company to their Mail.ru conglomerate?
https://www.forbes.com/profile/pavel-durov/
https://www.quora.com/Why-was-Pavel-Durov-so-careless-in-his...
https://www.cnn.com/2016/02/23/europe/pavel-durov-telegram-e...
The answer is: neither (although Pavel Durov is like 1000x more trustworthy in my opinion).
https://itc.ua/en/news/durov-boasts-that-telegram-employs-ab...
I prefer open source software
https://community.intercoin.app/t/web3-moxie-signal-telegram...
And here’s why:
https://community.qbix.com/t/the-global-war-on-end-to-end-en...
- list the problems
- link to sources
- backup the source instead they happen
We forget too easily, and PR works wonders. I used to have such a list for Microsoft, but:
- I have to pull it of every time we talk about the new MS, because people think they are good guys now. They already forgot.
- People don't think it could have been that bad.
- I have to rewrite the list, I can't link to it. Or expand it. And I have to justify its existence and credibility because MS PR is so strong now.
- The links are disappearing from the web, so my previous proofs are fading away, slowly being replaced by references everywhere singing MS praises and stating how a saint Gates is.
The powerful are rewriting history, literally.
karmicarchive.com is available, just saying.
The Signal one somebody has posted in the adjacent thread was definitely real and horrible though: https://news.ycombinator.com/item?id=27950763
The fact that at least two heavily-used messengers got one of the most essential things in instant messaging wrong is nightmare fuel I didn't need to have in my life :(
IT is just a series of security breaches.
> is nightmare fuel I didn't need to have in my life :(
It's a weird reaction. All software have always been like that as far as I remember.
xz: A sophisticated supply chain attack. These are known, scary, and we don't have great ways to prevent them yet.
Apparently half of all popular instant messengers at some point making the same kind of trivial but catastrophic off-by-one error: Not rocket science to prevent. I was hoping at least high-stakes apps would have better QA.
> is nightmare fuel I didn't need to have in my life :(
User sends message via client. Client fumbles the recipient id. Message ends up at the wrong recipient.
Examples: incorrect recipient ID attached to contact in list where users selects recipient. Buggy selection of multiple targets in the selection UI due to incorrect touch event handling. Incorrect deletion of previously selected and then deselected recipient from recipient array of multitarget message. Or if working low level even a good old off by one error and reading out of bounds data for the recipient list (though that one hopefully should trigger a faulty send request due to other stuff no longer matching). There is endless examples.
The server can't really safeguard against the client providing a legitimate send request even though the user intended to send it to another recipient.
Yeah, I don't know how they manage to get bugs like that, but it's happened