Live data from Hacker News

Why Isn’t Telegram End-to-End Encrypted by Default (2017)

telegra.ph

1–10 of 151 posts

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#3
> 1) Users don’t want to lose their entire message history when they lose/change their phones so apps of this kind never become massively popular.

I think this is a key point to consider for Signal and the other "good" messengers - there's ways to do secure backups, it just needs to be implemented so well that you won't miss the convenience of Google Drive backups.

I tend to fall back on anecdotes a lot, but the first thing my relatives ask me when setting up a new phone is "will I have my texts" - people want to be able to look through the past 10 years of conversation and especially media with someone and WhatsApp makes this as easy as one click during setup.

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#4

Still avoiding the main point - e2e encryption does not prohibit syncing, backup etc for said data (without decryption)

e2e does not prohibit it. But makes it hard or impossible even for an advanced user (i tried moving my whatsapp data from iphone to android once, not sure of the current status with signal).

Telegram is all about convenience, security is just bolt on. Everybody says they care about security, but hardly any TG user does it, because it is inconvenient. Install it on any any new device, confirm your phone number with an sms and whoops, all your chats and drunk and stoned pics are back.

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#5
post #3

> 1) Users don’t want to lose their entire message history when they lose/change their phones so apps of this kind never become massively popular. I think this is a key point to consider for Signal and the other "good" messengers - there's ways to do secure backups, it just needs to be implemented so well that you won't miss the convenience of Google Drive backups. I tend to fall back on anecdotes a lot, but the firs…

> and WhatsApp makes this as easy as one click during setup.

unless you switch platforms. then you lose it all

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#7
post #5
post #3

> 1) Users don’t want to lose their entire message history when they lose/change their phones so apps of this kind never become massively popular. I think this is a key point to consider for Signal and the other "good" messengers - there's ways to do secure backups, it just needs to be implemented so well that you won't miss the convenience of Google Drive backups. I tend to fall back on anecdotes a lot, but the firs…

> and WhatsApp makes this as easy as one click during setup. unless you switch platforms. then you lose it all

Yes, this happened to me after iOS -> Android switch all messages was wiped, you cant load icloud backup on android

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#8
The why doesn't matter. (the tl;dr is that they apparently never bothered to support some popular features within the context of e2ee, and believe people ultimately don't care about e2ee by default)

What matters is that:

- It doesn't do e2ee by default.

- It is not a properly documented protocol[0].

- It is not an open protocol.

- It has a history of extremely poor cryptography practices[1][2].

- It is not open source.

Thus, we should steer people away from it, and into acceptable solutions that meet these fundamental requirements.

Matrix, Signal and Tox come to mind; I have experience with all of these, and I can only recommend Matrix.

[0]: https://core.telegram.org/mtproto

[1]: https://news.ycombinator.com/item?id=25726068

[2]: https://news.ycombinator.com/item?id=25641399

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#9
post #6

Bait-and-switch topic in the opening paragraph. Insists that what people ask for, e2e chat, isn’t what they actually want or should want.

And he is right. If you want e2e use signal, threema, or OTR/OMEMO.

The majority of telegram users want convenient messaging, group chats, news channels and voice group calls. Think slack with a fast native app.

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#10
E2E chat is an interesting topic. Say I'm using XMPP, my own server, talking to a federated one, all over TLS, including S2S.

E2E on top of that, in my personal opinion, is a massive overkill for most cases and people.

Related read: https://homebrewserver.club/have-you-considered-the-alternat...

It is, however, different, when it comes to a server that I don't control in any form. In that scenario, it is rather useful, but I'm still a lot more worried about the unencrypted meta surrounding it. See email and PGP in this topic, which has always been a pain point for many.

Thoughts?

Post reply on HN