Why Isn’t Telegram End-to-End Encrypted by Default (2017)
1–10 of 151 posts
Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)
#2Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)
#3I think this is a key point to consider for Signal and the other "good" messengers - there's ways to do secure backups, it just needs to be implemented so well that you won't miss the convenience of Google Drive backups.
I tend to fall back on anecdotes a lot, but the first thing my relatives ask me when setting up a new phone is "will I have my texts" - people want to be able to look through the past 10 years of conversation and especially media with someone and WhatsApp makes this as easy as one click during setup.
Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)
#4Still avoiding the main point - e2e encryption does not prohibit syncing, backup etc for said data (without decryption)
Telegram is all about convenience, security is just bolt on. Everybody says they care about security, but hardly any TG user does it, because it is inconvenient. Install it on any any new device, confirm your phone number with an sms and whoops, all your chats and drunk and stoned pics are back.
Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)
#5> 1) Users don’t want to lose their entire message history when they lose/change their phones so apps of this kind never become massively popular. I think this is a key point to consider for Signal and the other "good" messengers - there's ways to do secure backups, it just needs to be implemented so well that you won't miss the convenience of Google Drive backups. I tend to fall back on anecdotes a lot, but the firs…
unless you switch platforms. then you lose it all
Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)
#6Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)
#7> 1) Users don’t want to lose their entire message history when they lose/change their phones so apps of this kind never become massively popular. I think this is a key point to consider for Signal and the other "good" messengers - there's ways to do secure backups, it just needs to be implemented so well that you won't miss the convenience of Google Drive backups. I tend to fall back on anecdotes a lot, but the firs…
> and WhatsApp makes this as easy as one click during setup. unless you switch platforms. then you lose it all
Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)
#8What matters is that:
- It doesn't do e2ee by default.
- It is not a properly documented protocol[0].
- It is not an open protocol.
- It has a history of extremely poor cryptography practices[1][2].
- It is not open source.
Thus, we should steer people away from it, and into acceptable solutions that meet these fundamental requirements.
Matrix, Signal and Tox come to mind; I have experience with all of these, and I can only recommend Matrix.
[0]: https://core.telegram.org/mtproto
Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)
#9Bait-and-switch topic in the opening paragraph. Insists that what people ask for, e2e chat, isn’t what they actually want or should want.
The majority of telegram users want convenient messaging, group chats, news channels and voice group calls. Think slack with a fast native app.
Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)
#10E2E on top of that, in my personal opinion, is a massive overkill for most cases and people.
Related read: https://homebrewserver.club/have-you-considered-the-alternat...
It is, however, different, when it comes to a server that I don't control in any form. In that scenario, it is rather useful, but I'm still a lot more worried about the unencrypted meta surrounding it. See email and PGP in this topic, which has always been a pain point for many.
Thoughts?