I feel that this is a pretty good summary of what's going on: https://youtu.be/39rBzRd4M0k and explains how the encryption works etc.
I feel that this is a pretty good summary of what's going on: https://youtu.be/39rBzRd4M0k and explains how the encryption works etc.
Saying telegram is based in Russia is like saying the pirate bay is based in Sweden. Used to be true, but not so much anymore.
Regardless, I think it's totally reasonable to be concerned about having shared symmetric cryptography keys stored on servers in Russia while claiming your app is 'secure'/end to end encrypted (not sure if they're claiming the latter anymore or if that was even official claims to begin with vs internet BS), and is especially relevant for Ukranians or Russians politically opposed to Putin.
[0] https://www.facebook.com/help/messenger-app/1084673321594605
What makes you feel that? Never seen that channel before, and the self-description of "High-intensity code tutorials and tech news to help you ship your app faster" doesn't really inspire much confidence when it comes to talking about more nuanced topics.
For example, Telegram isn't based in Russia, and I don't think it ever was. So if that's one of the takeaways from that video, it seems pretty misinformed even about the basics.
Also, there are issues with Telegram's E2EE mode, besides it being disabled by default. More than enough reason not to use it.
They can eavedrop by simply adding a device to a conversation and nobody will notice. Your device will gladly send them decryption keys and provide them with a copy of the message nicely.
The simple bad scenario I have in mind is when you're initiating a new chat and the mitm it from the start. Or they could do it halfway through, which would notify you that the other end's key changed, but that message is non-threatening enough and happens enough for random other reasons that most people would probably ignore it.
Edit: Meant to say, the web client needs to somehow be authorized by the phone, not that it takes the privkey exactly. Probably gets a new key that the phone stores, so the phone is still the "master" device. I wouldn't expect the phone client to happily send the chat history to a new device it didn't authorize locally.
i'm happy to know more about that topic if you've got some documentation.
Maybe there's some key derivation mechanism so the new pubkey is self-evidently owned by the first one, never heard of one though.
https://tsf.telegram.org/manuals/e2ee-simple
My own distrust for Telegram aside, I like how these pages seem to be written by an engineer and not a PR person.
Message secrecy does rely on being able to authenticate the recipient's public key.
They are using Telegram for PR, same as Twitter or Instagram. It doesn't matter if the posts get decrypted by Russia – they are anyways meant to be public.
This is not an empty accusation, there's been several stories which could not be explained by anything else than FSB having access to Telegram. That said, however, it's only FSB. There hasn't been a single suspicious act like that on behalf of Russian police, so we can assume that this access is only used in exceptional cases. So, unless you believe that Russian intelligence is targeting you personally, you're safe.
Could you share which "100% confirmed" stories this is about? Haven't really come across that before
If your device is compromised, all bets are off.
Example: FSB once leaked Navalny's emails. He used gmail. And no one suspects Google of conspiring with FSB.
As of 2024, Russia-the-state has no problems with either Pavel Durov or Telegram. That's suspicious to say the least.
They only tried to ban it in 2018 and gave up in 2020 after failing to do so without cutting off access to other Internet services. The last time they blocked access to it was quite recently, on 21 August, after the Ukrainian incursion into Kursk oblast.
https://understandingwar.org/backgrounder/russian-offensive-...
And so? Durov happens to be the founder of VK...