Live data from Hacker News

Is Telegram really an encrypted messaging app?

blog.cryptographyengineering.com

281–290 of 609 posts

Re: Is Telegram really an encrypted messaging app?

#281

It's not e2e encrypted, so what? It's something the majority of users does not need, and that doesn't increase security that much given their downsides. Of course for Telegram is much more convenient to not have end2end encryption. Given that they store everything on their servers, it means years of chat history that probably weights Gb for each user, contrary to what WhatsApp/Signal do, of course if 10 million peopl…

>It's not e2e encrypted, so what? It's something the majority of users does not need, and that doesn't increase security that much given their downsides.

Privacy is a human right. Everyone needs it. And Telegram advertises itself as an encrypted messenger. For every non-expert, that means end-to-end encryption. Only me and recipient can read the message. Users expect Telegram to be more secure than WhatsApp. Telegram claims its more secure than WhatsApp, and Telegram has attacked WhatsApp over its security. WhatsApp is always end-to-end encrypted, Telegram is not. So don't go putting words into peoples mouths.

>Given that they store everything on their servers, it means years of chat history that probably weights Gb for each user

It could be stored there with client-side encryption, Telegram doesn't need to have access to that data. Also who says chats that are ephemeral in nature need to be forever accessible. I save what I need from Signal or Telegram.

>This is the reason Telegram can offer you to have all your messages, including medias that can be up to 1Gb each, stored on a cloud for free.

It's not free. It comes with the price of your human right to privacy. You should get a job at Facebook with this marketing pitch.

>As I user I prefer Telegram just because it's the only app that works perfectly synchronized among multiple devices

It doesn't sync secret chats at all with multiple devices, not even desktop. Signal does.

>good quality native clients

Your script is seven years old https://signal.org/blog/standalone-signal-desktop/

>You can put a backdoor on endpoints, that is compromise the user phone (something they do)

Nirvana fallacy. Why is Telegram offering secret chats if all endpoints are compromised? If they're not always compromised, then it should offer end-to-end encryption for everything, always. Like Signal, Whatsapp, Wire, Threema, iMessage, Cwtch, Briar, Element, Session...

>you can make a MITM attack on the server

Which is why every messaging app worth its salt offers safety numbers https://support.signal.org/hc/en-us/articles/360007060632-Wh...

Even telegram has them, although their initial implementation of babby's first QR-code was a joke. How do you compare over the phone shades of a color matrix?

https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcSUnBRB...

>you can access the data that is backed up on other platform

Oh, that would be horrible. Good thing Telegram doesn't have its data backed up in cloud, no wait, sorry, it does. ~Everything you ever do with the app is permanently stored in an ecosystem built by the Mark Zuckerberg of Russia, and his PhD in geometry bro Nikolai.

Shill harder.

Re: Is Telegram really an encrypted messaging app?

#282
post #16

If telegrams encryption is so bad why is Pavel Durov under arrest? The arrest cites that he was not cooperating with authorities to crack down on various drug illegal activities on telegram. None of the other social networks have their ceos arrested. Is it simply that telegram is the only one without backdoors for five eyes? It seems to me the secret chat feature actually works too well?

I'd suggest waiting for more details from French officials, they have already said that they'll address it tomorrow. So far claims from the media sound like Durov's being prosecuted due to very little moderation on the platform, not because of E2EE. Even so, most messages sent on Telegram are plaintext, they're encrypted only in transport layer, but Telegram's servers see them in full. Secret chats (the only E2EE cha…

> So far claims from the media sound like Durov's being prosecuted due to very little moderation on the platform, not because of E2EE.

But that's why it's good. With all the mainstream media censoring stuff, telegram was a (good for the people) exception.

On the other hand, that's probably why they arrested him.

Re: Is Telegram really an encrypted messaging app?

#283

I am amazed at the low quality comments here. Encryption really doesn’t matter as much as the trust of the app here. Any malicious app author can 100% secure encrypt everything in wire and yet leak 100% of your data to some state actor. Anything you type into the chat box is only encrypted by the app after you type and probably storing it in the clear in some local SQLite db. It gives them a whole bunch of options to…

Telegram basically have "trust me bro" security.

Even worse than Apple. They at least have some e2ee options.

Re: Is Telegram really an encrypted messaging app?

#284

Telegram is not Signal, it is a waaay better Discord

Still not indexable, referencable, or freely readable

It's a walled-garden system which is fine for private chats between groups of friends, but Discord is increasingly being used as a place to report bugs and share information. Telegram furthermore requires signing up with a phone number which Discord did not (now, often, you need to for participating when an admin of a community aka gild aka misnomer "server" turned on that requirement)

https://xkcd.com/979/ This comic will not be understood by gamers growing up today... (Except in many cases someone posted a solution or nudged DenverCoder9 in the right direction at least; with Discord, Slack, or Telegram you'd simply never find the thread in a search engine to begin with.)

Re: Is Telegram really an encrypted messaging app?

#285
post #65

> One of the biggest privacy problems in messaging is the availability of loads of meta-data — essentially data about who uses the service, who they talk to, and when they do that talking. […] the same problem exists with virtually every other social media network and private messenger. Is this true for Signal too? I thought it wasn’t.

> Is this true for Signal too? I thought it wasn’t. It is, because you cannot use Signal without giving them your mobile phone number, and from that point onward they (and anyone they might be sharing data with) know the who/what/when, and more. My gut feeling, notwithstanding any apologist and their weak arguments, is that the design choice is exactly about the who/what/when because it's mandatory despite being enti…

How does it follow that Signal knowing a phone number means they know who the identity that phone number represents is communicating with?

Re: Is Telegram really an encrypted messaging app?

#286
This is actually great blogpost since too many people tend to believe that Telegram is somehow more secure and private then alternatives on market.

Also it's not like Telegram dont have censorship. During last 3-4 years there was many cases where Durov blocked bots and channels that belong to protests and opposition in Russia, marked them as "fake" or just plain removed with no trace.

So it's just another case where some rich guy try to sell his own platform as some "freedom of speech" one even though it's just censored to his liking.

Re: Is Telegram really an encrypted messaging app?

#287

Earlier quoted context omitted.

> It's the only messaging app where messages are stored on the cloud. Besides Slack and Discord and Teams and whatever the heck Google has these days and iMessage and... I think you mean it's the only messaging app that purports to have a focus on security where messages are stored in the cloud, which is true, but also sus. There's a reason why none of the others are doing it that way, and Telegram isn't really claim…

Matrix also keeps your message on the server. Except you can run your own server. And the messages are end to end encrypted. And you can keep a proper backup of the keys. Granted it can be clunky at times, but the properties are there and decentralised end to end encrypted messaging is quite and incredible thing. (Yes, Matrix nerds, it's not messaging per se it's really state replication, I know :))

As you alluded to, Matrix has really horrible UX. Telegram is meant to be easy for the many to use: finding content in chats or even globally across public channels for example is intuitive and snappy because their server does the heavy lifting. That's a huge sell for many, myself included.

Re: Is Telegram really an encrypted messaging app?

#288
post #258

If telegrams encryption is so bad why is Pavel Durov under arrest? The arrest cites that he was not cooperating with authorities to crack down on various drug illegal activities on telegram. None of the other social networks have their ceos arrested. Is it simply that telegram is the only one without backdoors for five eyes? It seems to me the secret chat feature actually works too well?

I can give you some insight into why EU law enforcement and politicians dislike telegram. It’s not because they can’t snoop on you, it’s because Telegram fails to comply with moderation requests for channels where illegal content is shared. We had a nice scandal of sorts here in Denmark where a bunch of young men shared pictures of young women without consent. If you’re old enough to remember those old “rate this gir…

The problem is that it never ends at protecting Danish women or kids, or "fighting terrorism".

Re: Is Telegram really an encrypted messaging app?

#289

I am amazed at the low quality comments here. Encryption really doesn’t matter as much as the trust of the app here. Any malicious app author can 100% secure encrypt everything in wire and yet leak 100% of your data to some state actor. Anything you type into the chat box is only encrypted by the app after you type and probably storing it in the clear in some local SQLite db. It gives them a whole bunch of options to…

> malicious app author can 100% secure encrypt everything in wire and yet leak 100% of your data

Um, surely you understand the difference between piping random-looking bytes uselessly to whoever and having a readable copy of all data readily available to whoever hacks the system or applies for a sysadmin role? Or are you making the assumption that people use a closed-source client and the server can push malicious code?

> Even if the app source code is published as you don’t know if they backdoored it before they submitted to App Store.

Doesn't work if you have third parties also working with the system or forking the code to work with it. It gets noticed. Your concept of "e2ee can be 100% leaked anyway" only works if you don't know what code you're running. You need to trust the community in general to uncover issues you've overlooked (in the code or build process) but that's not the same as not having encryption at all. You can't audit the servers but you can audit the client code.

Re: Is Telegram really an encrypted messaging app?

#290

Reads like a hit piece on Telegram from a crypto expert who couldn't be bothered to explain in more than one paragraph why the app he is calling not an encrypted app (according to how he personally thinks everyone refers to when talking about encryption) actually uses some encryption technology that he's not exactly sure of but suspects is insecure.

TLDR: 99.95% of messages on Telegram stored as plain text on their servers and only encrypted between client and telegram server. End-to-end encryption only working for 1on1 chats, not available half of their clients and have terrible UX.
Post reply on HN