Earlier quoted context omitted.
Yes, and Telegram being open allows us to confirm with absolute certainty that it uses no E2EE by default. We don't have the WhatsApp source code, but we don't have to do a lot of reverse engineering to see that it uses this: https://github.com/signalapp/libsignal-protocol-c But yeah, you're right, it could be sending plaintext or deliberately leaking keys somewhere. Unless someone really reverses it we won't know it…
> Unless someone really reverses it we won't know it doesn't as surely as we know that Telegram doesn't use encryption at all. Telegram uses encryption by default, just not E2EE. You can criticise them for - using their own crypto - misleading advertising regarding the quality of said crypto ... and possibly more, but I still suggest we try to stick to the facts.
If just using encryption is good enough for you, then why not use Facebook Messanger, Google Hangouts or whatever they call it these days, or WeChat? You can verify their use of encryption with Wireshark.
You argue that Telegram is great because it's open source, but what difference does that really make when it's a centralized service and that centralized service has access to all the plaintext? So what if the client is open source? What does that actually help us verify in this case?