Live data from Hacker News

Why Isn’t Telegram End-to-End Encrypted by Default (2017)

telegra.ph

11–20 of 151 posts

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#11
post #9
post #6

Bait-and-switch topic in the opening paragraph. Insists that what people ask for, e2e chat, isn’t what they actually want or should want.

And he is right. If you want e2e use signal, threema, or OTR/OMEMO. The majority of telegram users want convenient messaging, group chats, news channels and voice group calls. Think slack with a fast native app.

[deleted]

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#12
post #4

Still avoiding the main point - e2e encryption does not prohibit syncing, backup etc for said data (without decryption)

e2e does not prohibit it. But makes it hard or impossible even for an advanced user (i tried moving my whatsapp data from iphone to android once, not sure of the current status with signal). Telegram is all about convenience, security is just bolt on. Everybody says they care about security, but hardly any TG user does it, because it is inconvenient. Install it on any any new device, confirm your phone number with an…

If messaging clients like WhatsApp permitted a Keybase styled authentication of additional devices, then migration (so long as the original were available) wouldn't be difficult at all. And if they permitted backup to a user selected service (for instance, Google's for Android versus Apple's for iOS) then migration across OSes would become simplified for users.

But the WhatsApp iOS client backs up to iCloud, and the Android client backs up to Google, and this creates a blocking issue unless the user is willing to jump through hoops and use 3rd party tools.

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#13
Maybe I'm missing something, seems like any of these apps that might want local storage for some reason could store data in an encrypted format. A cloud backup would then be backing up and restoring encrypted data. Where the user holds the key in some form to unlock the data at the right time.

They bring up a good point that anyone with access to the message can leak it, no matter how tight you lock down your side. Something ephemeral seems best if you really want security.

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#14
post #4

Earlier quoted context omitted.

e2e does not prohibit it. But makes it hard or impossible even for an advanced user (i tried moving my whatsapp data from iphone to android once, not sure of the current status with signal). Telegram is all about convenience, security is just bolt on. Everybody says they care about security, but hardly any TG user does it, because it is inconvenient. Install it on any any new device, confirm your phone number with an…

If messaging clients like WhatsApp permitted a Keybase styled authentication of additional devices, then migration (so long as the original were available) wouldn't be difficult at all. And if they permitted backup to a user selected service (for instance, Google's for Android versus Apple's for iOS) then migration across OSes would become simplified for users. But the WhatsApp iOS client backs up to iCloud, and the…

Matrix actually does authenticate additional devices, and handle all that.

It's already out there, just a matter of adopting it.

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#15
post #7
post #5

Earlier quoted context omitted.

> and WhatsApp makes this as easy as one click during setup. unless you switch platforms. then you lose it all

Yes, this happened to me after iOS -> Android switch all messages was wiped, you cant load icloud backup on android

>you cant load icloud backup on android

for free

If you're willing to pay for an app, you can definitely do that.

https://www.syncios.com/icloud/how-to-recover-data-from-itun...

*I'm not advocating for this specific app, I've never used it and couldn't comment on how well it works, just an example*

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#16
Genuine question, and I'm certainly no expert in this - just a curious end-user, aren't the backups that WhatsApp creates and uploads to iCloud/GDrive kind of encrypted? As in, I can't simply download the backup file and access the messages and media?

My understanding is that in order to restore/access said messages and media, you would need the SIM/phone number that created the backup file and would have to register again with WhatsApp to receive a decryption key from WhatsApp servers. So doesn't this mean in effect that even though it's not super secure, the backup file stored on iCloud/GDrive is also protected from Apple and Google's prying eyes?

EDIT: For anyone interested, the backups are indeed encrypted. See: https://security.stackexchange.com/questions/136072/how-can-...

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#17
post #9
post #6

Bait-and-switch topic in the opening paragraph. Insists that what people ask for, e2e chat, isn’t what they actually want or should want.

And he is right. If you want e2e use signal, threema, or OTR/OMEMO. The majority of telegram users want convenient messaging, group chats, news channels and voice group calls. Think slack with a fast native app.

The only thing missing from signal among the things you listed is news, no?

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#18
post #9
post #6

Bait-and-switch topic in the opening paragraph. Insists that what people ask for, e2e chat, isn’t what they actually want or should want.

And he is right. If you want e2e use signal, threema, or OTR/OMEMO. The majority of telegram users want convenient messaging, group chats, news channels and voice group calls. Think slack with a fast native app.

Does wanting any of this automatically mean wanting e2e is wrong or invalid?

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#19
post #16

Genuine question, and I'm certainly no expert in this - just a curious end-user, aren't the backups that WhatsApp creates and uploads to iCloud/GDrive kind of encrypted? As in, I can't simply download the backup file and access the messages and media? My understanding is that in order to restore/access said messages and media, you would need the SIM/phone number that created the backup file and would have to register…

[deleted]

Re: Why Isn’t Telegram End-to-End Encrypted by Default (2017)

#20
post #8

The why doesn't matter. (the tl;dr is that they apparently never bothered to support some popular features within the context of e2ee, and believe people ultimately don't care about e2ee by default) What matters is that: - It doesn't do e2ee by default. - It is not a properly documented protocol[0]. - It is not an open protocol. - It has a history of extremely poor cryptography practices[1][2]. - It is not open sourc…

I've been exploring options with a friend, their requirements:

1) option for large groups (around 250) This drops Signal out which has a limit of 150 on groups: https://support.signal.org/hc/en-us/articles/360007319331-Gr...

2) e2e encrypted (because it sounds good, not because people actually understand what it is), including groups. This drops Telegram out: no e2e rooms.

3) handles sending photos, videos, and voice messages. More or less kills XMPP, unless people are on the latest-and-greatest version of Conversations and maybe ChatSecure.

4) the maintaining organisation needs to be reasonably big with decent privacy.

5) usable for completely non technical generic population - meaning Tox is out as well.

As much as I dislike to admit it, this leaves Matrix, and nothing else. My problem with Matrix is that it's so resource hungry - both the servers and the clients - is that it's silly. Yes, I know "optimization is coming" but even Dendrite eats 1.5GB memory easily with a single user joining a few, medium sized, federated rooms (yes, I've tried).

Footnote: Threema... no. There is no need for yet another competing open source thing, there are enough with Signal, Matrix, and XMPP.

Post reply on HN