"These backups are not e2e-encrypted and get decrypted whenever(...)"
Are they or are they not encrypted?
21–30 of 151 posts
"These backups are not e2e-encrypted and get decrypted whenever(...)"
Are they or are they not encrypted?
The why doesn't matter. (the tl;dr is that they apparently never bothered to support some popular features within the context of e2ee, and believe people ultimately don't care about e2ee by default) What matters is that: - It doesn't do e2ee by default. - It is not a properly documented protocol[0]. - It is not an open protocol. - It has a history of extremely poor cryptography practices[1][2]. - It is not open sourc…
I've been exploring options with a friend, their requirements: 1) option for large groups (around 250) This drops Signal out which has a limit of 150 on groups: https://support.signal.org/hc/en-us/articles/360007319331-Gr... 2) e2e encrypted (because it sounds good, not because people actually understand what it is), including groups. This drops Telegram out: no e2e rooms. 3) handles sending photos, videos, and voice…
When you get into groups with hundreds of members I think Slack and Discord are probably the dominant chat apps there.
Earlier quoted context omitted.
I've been exploring options with a friend, their requirements: 1) option for large groups (around 250) This drops Signal out which has a limit of 150 on groups: https://support.signal.org/hc/en-us/articles/360007319331-Gr... 2) e2e encrypted (because it sounds good, not because people actually understand what it is), including groups. This drops Telegram out: no e2e rooms. 3) handles sending photos, videos, and voice…
I'm all for end-to-end encryption, but if you have 250 people in the chat I'm not sure it'll be very effective. It only takes one of those people to leak the messages. When you get into groups with hundreds of members I think Slack and Discord are probably the dominant chat apps there.
The why doesn't matter. (the tl;dr is that they apparently never bothered to support some popular features within the context of e2ee, and believe people ultimately don't care about e2ee by default) What matters is that: - It doesn't do e2ee by default. - It is not a properly documented protocol[0]. - It is not an open protocol. - It has a history of extremely poor cryptography practices[1][2]. - It is not open sourc…
I've been exploring options with a friend, their requirements: 1) option for large groups (around 250) This drops Signal out which has a limit of 150 on groups: https://support.signal.org/hc/en-us/articles/360007319331-Gr... 2) e2e encrypted (because it sounds good, not because people actually understand what it is), including groups. This drops Telegram out: no e2e rooms. 3) handles sending photos, videos, and voice…
As you haven't mentioned it: Supporting e2ee isn't enough. It must be the default, else the non-technically inclined will often end up not using e2ee.
>As much as I dislike to admit it, this leaves Matrix, and nothing else.
I'm in the same position. Never been a fan, but I have to support it, because that's really the only option, even if bloated.
I also tried running a server (synapse) with similar results. I have hopes for dendrite, but they've just been dampened by your report.
Fortunately, the client side is far more important, and there's some options there. Particularly, the web-based hydrogen is massively less resource-hungry than the web-based element, and nearly there featureset-wise.
>XMPP
I didn't even list that one, because e2ee is not the default, and support was added way too late in the protocol's trajectory.
>Signal
I mentioned it, but I'm actually not about to use it. The reason is that accounts are tied to phone lines. That's a non-starter for me.
I can get the reasons behind not doing e2e encryption by default to reach more audience (msgs history, lack of resources on start, special backups)
What I cannot get is why Durov is blaming FB/WhatsApp that much, it seems to be the main competitor. As for me the story with WhatsApp is clear, it's Facebook and if you like being Zucked - go with it. But why so much hate on it?
On the other hand, every time Signal pops up the only answer I see: 'because it does only e2e well which is only one feature of Telegram' - wrong, Signal does secure messaging and messager has to do its job well, that's it. You need a media platform - go for Telegram/WhatsApp/Facebook, you need a messager - use Signal/Wire/etc
Does anyone else feels this bias towards WhatsApp? I cannot blame WhatsApp for being WhatsApp, that's how FB makes money
Bait-and-switch topic in the opening paragraph. Insists that what people ask for, e2e chat, isn’t what they actually want or should want.
And he is right. If you want e2e use signal, threema, or OTR/OMEMO. The majority of telegram users want convenient messaging, group chats, news channels and voice group calls. Think slack with a fast native app.
I love getting glimpses of how other people use certain apps. I can't imagine _wanting_ news in my messaging app - that's what my news app is for! Very valuable reminder that our own perspective is not always widespread.
Earlier quoted context omitted.
I'm all for end-to-end encryption, but if you have 250 people in the chat I'm not sure it'll be very effective. It only takes one of those people to leak the messages. When you get into groups with hundreds of members I think Slack and Discord are probably the dominant chat apps there.
Indeed. But ever since Whatsapp started advertising e2e, people want it.
Earlier quoted context omitted.
I've been exploring options with a friend, their requirements: 1) option for large groups (around 250) This drops Signal out which has a limit of 150 on groups: https://support.signal.org/hc/en-us/articles/360007319331-Gr... 2) e2e encrypted (because it sounds good, not because people actually understand what it is), including groups. This drops Telegram out: no e2e rooms. 3) handles sending photos, videos, and voice…
I'm all for end-to-end encryption, but if you have 250 people in the chat I'm not sure it'll be very effective. It only takes one of those people to leak the messages. When you get into groups with hundreds of members I think Slack and Discord are probably the dominant chat apps there.
As far as old messages goes, Matrix rooms do not allow new participants to see old history, unless explicitly enabled.
>if you have 250 people in the chat I'm not sure it'll be very effective. It only takes one of those people to leak the messages.
Ultimately, the system is only good when the members of a room deliberately leaking messages is the primary concern; It means the system is working as intended, thus privacy is a matter of trust on the conversation members, as it is away from keyboard.
The why doesn't matter. (the tl;dr is that they apparently never bothered to support some popular features within the context of e2ee, and believe people ultimately don't care about e2ee by default) What matters is that: - It doesn't do e2ee by default. - It is not a properly documented protocol[0]. - It is not an open protocol. - It has a history of extremely poor cryptography practices[1][2]. - It is not open sourc…
When creating a 1 to 1 chat, it's one of the default buttons. In Android, you click a {pencil} icon, then "new chat" (encrypted in transit and at rest like your bank website) or "new secret chat" (end to end encrypted)
> - It is not an open protocol.
The protocol is fully open source and audited. https://telegram.org/apps scroll down to source code.
> - It is not open source.
As above https://telegram.org/apps . The client apps are fully open source and reproducible.
> - It has a history of extremely poor cryptography practices.
People pointed out the security issues in MTProto v1, and they were all addressed in MTProto v2 over 3 years ago.
You may be recalling some FUD spread by the author of what eventually became Signal, but none of what you said above is factual.
Earlier quoted context omitted.
I've been exploring options with a friend, their requirements: 1) option for large groups (around 250) This drops Signal out which has a limit of 150 on groups: https://support.signal.org/hc/en-us/articles/360007319331-Gr... 2) e2e encrypted (because it sounds good, not because people actually understand what it is), including groups. This drops Telegram out: no e2e rooms. 3) handles sending photos, videos, and voice…
>2) e2e encrypted As you haven't mentioned it: Supporting e2ee isn't enough. It must be the default, else the non-technically inclined will often end up not using e2ee. >As much as I dislike to admit it, this leaves Matrix, and nothing else. I'm in the same position. Never been a fan, but I have to support it, because that's really the only option, even if bloated. I also tried running a server (synapse) with similar…
That is not a thing with XMPP. The very essence of it is adding things in, and OMEMO is quite good.