Earlier quoted context omitted.
Read this: https://fortune.com/crypto/2024/06/27/telegram-dark-net-blac... Telegram channels are public, unencrypted web shops for all kinds of illegal goods. I guess the French government alleges that Durov is not doing enough to stop these activities on his platform. It doesn't necessarily have anything to do with encryption.
It indirectly has a lot to do with encryption, in that if Telegram was actually encrypted, they'd probably have no grounds on holding him in the first place. (At least at the moment, in most countries) it's not illegal to not ship a backdoor in your end-to-end-encrypted software upon government request, but in most it is illegal to not share data you're holding in a form accessible to you when you receive a warrant f…
Is Telegram really an encrypted messaging app?
131–140 of 609 posts
Re: Is Telegram really an encrypted messaging app?
#132Of course for Telegram is much more convenient to not have end2end encryption. Given that they store everything on their servers, it means years of chat history that probably weights Gb for each user, contrary to what WhatsApp/Signal do, of course if 10 million people send eachother the same meme it's stupid to have 10 million copies of the same images on their servers just because it is end2end encrypted. They probably have a store where they index each media with its hash and avoid to have multiple copies, that is fine. This is the reason Telegram can offer you to have all your messages, including medias that can be up to 1Gb each, stored on a cloud for free.
As I user I prefer Telegram just because it's the only app that works perfectly synchronized among multiple devices (Android, Linux, macOS) with good quality native clients, without wasting space on my phone for data.
By the way, end2end encryption it's not that safe as they claim. Sure, the conversation can not be intercepted, however:
- you can put a backdoor on endpoints, that is compromise the user phone (something they do)
- you can make a MITM attack on the server (don't know if they do that, but technically possible)
- you can access the data that is backed up on other platforms (i.e. WhatsApp makes by default backups on Google Drive or Apple iCloud, trough which you can access all the conversations in clear text).
Re: Is Telegram really an encrypted messaging app?
#133Earlier quoted context omitted.
[flagged]
What do web3 and crypto moneys have anything to do with the discussion? Decentralized protocols have existed for a very long time. Email have existed since the 70s. Telephone is also arguably decentralized and have existed for even longer.
Government split Ma Bell into multiple smaller pieces, but they still operated as a cartel and kept prices high. They had centralized telephone switchboard operators etc.
It is only when authors of decentralized file-sharing networks like Kazaa (who built them to get around yet another government-enforced centralized regime of Intellectual Property, RIAA, MPAA etc.) went clean did we get Skype, and other Voice over IP consumer products. And seemingly overnight, the prices dropped to zero and we got packed-switched networks over dumb hubs, that anyone can run.
That's the key. We need to relegate these centralized platforms (X, Meta, etc.) into glorified hubs running nodes and earning some crypto, akin to IPFS nodes earning filecoin, or BitTorrent nodes earning BTT, etc.
Everything centralized gets enshittified
Clay Shirky gave a talk abot this in 2005: https://www.ted.com/talks/clay_shirky_institutions_vs_collab...
And Cory Doctorow recently: https://doctorow.medium.com/https-pluralistic-net-2024-04-04...
Re: Is Telegram really an encrypted messaging app?
#134Earlier quoted context omitted.
Is there a nice solution for multiparty (n >= 3) end-to-end encryption?
MLS scales best for large n, but WhatsApp/Signal or Matrix do pretty well for < 1k people
Re: Is Telegram really an encrypted messaging app?
#135Earlier quoted context omitted.
You can coherently argue that encryption doesn't matter, but you can't reasonably argue that Telegram is a serious encrypted messaging app (it's not an encrypted messaging app at all for group chats), which is the point of the article. The general attitude among practitioners in the field is: if you have to reason about how the operator will handle legal threats, you shouldn't bother reasoning about the messenger at…
> if you have to reason about how the operator will handle legal threats, you shouldn't bother reasoning about the messenger at all. That's true. You need to run your own platform people. XMPP is plenty simple, plenty powerful, and plenty safe -- and even your metadata is in your control. Just self host. There's no excuse in 2024. Wake up people! Why should the arrest of someone else affect YOU?
I'm someone who's been on the business end of a subpoena for a platform I ran, and narcing on my friends under threat of being held in contempt is perhaps the worst feeling I'm doomed to live with.
"XMPP is ..." not the solution I'd recommend, even with something like OMEMO. Is it on by default? Can you force it to be turned on? The answer to both of those is, as it turns out, "no," which makes it less than useful. (This is notwithstanding several other issues OMEMO has.)
Re: Is Telegram really an encrypted messaging app?
#136Earlier quoted context omitted.
I think a high definition photo taken on a recent phone takes up an awful lot more device memory than a "big number of chats"
Yeah, but Whatsapp chats tend to be full of those... and videos.
Re: Is Telegram really an encrypted messaging app?
#137Earlier quoted context omitted.
You can coherently argue that encryption doesn't matter, but you can't reasonably argue that Telegram is a serious encrypted messaging app (it's not an encrypted messaging app at all for group chats), which is the point of the article. The general attitude among practitioners in the field is: if you have to reason about how the operator will handle legal threats, you shouldn't bother reasoning about the messenger at…
> if you have to reason about how the operator will handle legal threats, you shouldn't bother reasoning about the messenger at all. That's true. You need to run your own platform people. XMPP is plenty simple, plenty powerful, and plenty safe -- and even your metadata is in your control. Just self host. There's no excuse in 2024. Wake up people! Why should the arrest of someone else affect YOU?
Gung-ho evangelists rarely convert like a reasonable take on the subject does
Re: Is Telegram really an encrypted messaging app?
#138Earlier quoted context omitted.
> Obviously if your phone is compromised your e2ee chat is not safe. Pretty much, a lot of people think that seeing E2EE means everything is safe, which I believe gives a false sense of security. You can have your phone compromised (especially when I know your phone number, Signal I’m looking at you) or be subject to other means of attacks, exposing everything. I would rather know that this app is not secure so I don…
Stealing someone's phone number wouldn't give you any Signal data, as all the messages have perfect forward secrecy, though, right? And all contacts would see an alert that your security number had changed. Not completely foolproof, and I would like Signal to use something other than phone numbers for accounts, but it's pretty good.
Re: Is Telegram really an encrypted messaging app?
#139Earlier quoted context omitted.
> Obviously if your phone is compromised your e2ee chat is not safe. Pretty much, a lot of people think that seeing E2EE means everything is safe, which I believe gives a false sense of security. You can have your phone compromised (especially when I know your phone number, Signal I’m looking at you) or be subject to other means of attacks, exposing everything. I would rather know that this app is not secure so I don…
Not only that. If they want to intercept e2e chats it's possible with a MITM attack, that if you control the server it's not a difficult thing to do. Of course the users if they check the keys they see they are different, but practically no one does that. And I think WhatsApp probably does it, otherwise why the authorities never complied that WhatsApp did not let them see the conversations?
Rule of thumb: never trust anything Facebook. I’m sure sending your messages through mail is more secure and private than WhatsApp these days.
Re: Is Telegram really an encrypted messaging app?
#140> One of the biggest privacy problems in messaging is the availability of loads of meta-data — essentially data about who uses the service, who they talk to, and when they do that talking. […] the same problem exists with virtually every other social media network and private messenger. Is this true for Signal too? I thought it wasn’t.
It is, because you cannot use Signal without giving them your mobile phone number, and from that point onward they (and anyone they might be sharing data with) know the who/what/when, and more. My gut feeling, notwithstanding any apologist and their weak arguments, is that the design choice is exactly about the who/what/when because it's mandatory despite being entirely unnecessary from a technical perspective.