> purported security failures> people are looking to block it instead of silently explore its flaws
This is not a good heuristic for determining if security failures are "purported."
In point of fact, Telegram is widely lampooned by every self-respecting professional cryptographer who has written about it. There's nothing "purported" about Telegram's security failures - they are empirically demonstrable, and have been exposed through multiple cryptanalytic reviews.[1][2]
Frankly, I don't think I've ever seen anyone defend Telegram here on HN who actually has professional crypto experience (whether academia or industry), or any other similar proxy for credibility in the field. The popular contention is that (poor, harmless) Telegram is plagued by a persistent astroturfing campaign perpetrated by the likes of Moxie Marlinspike and Thomas Ptacek in order to elevate Signal's status. That's:
1) not true, in my opinion (though to be fair at least one of those people is obviously biased); and
2) irrelevant, because we have the benefit of empirical rigor to instruct our opinions of secure messaging systems. We don't need to rely on infosec ideologues on HN or Twitter.
Telegram is very much like climate change. There is a widespread consensus among the informed (read: academic and professional cryptographers) that Telegram's security failures exist, and that these failures are empirically demonstrable. At the same time, there is a controversy led almost entirely by the uninformed (read: non-cryptographers) that denies Telegram's security failures and undermines attempts at demonstrating them through accusations of shilling or misdirection.
To put it very succinctly: there are no valid arguments that Telegram has an optimal security model from the perspective of cryptanalysis and cryptographic design best practices.
____________________________________________________________
1. https://www.alexrad.me/discourse/a-264-attack-on-telegram-an...
2. https://cs.au.dk/~jakjak/master-thesis.pdf