Earlier quoted context omitted.
Oh, I must have missed this. Please tell me how to enable secret chats for groups. And my desktop chats. Also I'd like to turn on the setting for defaulting to secret chats whenever I open a new one. Oh? I can't. Sounds like it's not there if I want it, after all. Good thing they didn't force it to me though /s
You can’t have secret chats for groups. For desktop secret chats you may use Unigram client (although it’s hard for me to justify a potentially non-mobile secret chat). The rest is trivial and isn’t that hard unless you contact hundreds of new people a day. In that case, I’d already thought of using ahk automation or a full-blown telethon bot.
Is Telegram really an encrypted messaging app?
381–390 of 609 posts
Re: Is Telegram really an encrypted messaging app?
#382Try the mud puddle test: log into your account on a new device using the password recovery flow. Can you see your old messages? If the answer is yes then law enforcement can too. https://www.forbes.com/sites/anthonykosner/2012/08/05/how-se...
Why not the "founder locked up" test? If the founder claims secure encryption, yet they are not in jail, that means there's no secure encryption because they negotiated their freedom in exchange for secret backdoors.
Re: Is Telegram really an encrypted messaging app?
#383In my opinion, Telegram is more of a social network than a messenger. There are many useful channels and in many countries, it plays an important role in sharing information. If we look at it from this point of view, e2ee does not seem very important. We should also not forget that, in the time when all social media (Reddit, X, Instagram etc.) close their APIs, Telegram is one of the only networks that still has a fr…
That's the dangerous part. It's a messaging app that took in the function of a social media platform. It did so without robust security features like end-to-end encryption yet it advertised itself as heavily encrypted. Like Green stated in his blog post, users expect that to mean only recipient can read what you say, i.e. end-to-end encryption. Telegram would be fine if it advertised itself as a public square of the…
Do you want to say that social networks must implement E2E? Personally I think it is a good idea, but existing social networks and dating apps do not implement it so Telegram is not obliged to do it as well.
As for promises of security, everybody misleads users. Take Apple. They advertise that cloud backups are encrypted, but what they don't like to mention is that by default they store the encryption keys in the same cloud, and even if the user opts into "advanced" encryption, the contact list and calendar are still not E2E encrypted under silly excuse (see the table at [1]). If you care about privacy and security you probably should never use iCloud in the first place because it is not fully E2E encrypted. Also note, that Apple doesn't even mention E2E in user interface and instead uses misleading terms like "standard encryption".
This is not fair. Apple doesn't do E2E cloud backups by default and nobody cares, phone companies do not encrypt anything, Cloudflare has disabled Encrypted Client Hello [2], but every time someone mentions Telegram, they are blamed for not having E2E chats by default. It looks like the bar is set different for Telegram compared to other companies.
[1] https://support.apple.com/en-us/102651
[2] https://developers.cloudflare.com/ssl/edge-certificates/ech/
Re: Is Telegram really an encrypted messaging app?
#384Re: Is Telegram really an encrypted messaging app?
#385Earlier quoted context omitted.
>You can have your phone compromised (especially when I know your phone number, Signal I’m looking at you) or be subject to other means of attacks, exposing everything. Knowing someone's phone number doesn't automatically let you compromise their device. This is such a ridiculous argument. >I would rather know that this app is not secure so I don’t share anything important, while keeping secure communication to other…
> Knowing someone's phone number doesn't automatically One way or another, phone numbers are like home addresses in the digital world. Once exposed, it’s just a matter of time and resources dedicated to that. Not to mention, sometimes it’s just needed to cross over the identity, that’s it. > This is a nirvana fallacy. It's essentially saying I didn’t say that. As I mentioned in the other comment to you, some or a lot…
Because that's the trade-off you make when you want high entropy unique usernames to prevent enumeration attacks. They become long and random. There's still a "phone number". It just looks something like 4sci35xrhp2d45gbm3qpta7ogfedonuw2mucmc36jxemucd7fmgzj3ad. You know that string and you can make a computer somewhere in the world accept some GET requests. Who knows if Flask, or whatever is part of the stack, has zero-click vulnerabilities.
And yes obviously I would recommend Signal to anyone who wants content privacy. Since Signal offers only narrow by-policy metadata privacy (unless you're on burner hardware), I'd ask them if they wanted metadata privacy, and if so, I'd point them to the direction of Cwtch https://cwtch.im/. I wouldn't recommend TFC unless endpoint compromise was part of their threat model. It's complicated and nuanced in the deep end of the pool.
Re: Is Telegram really an encrypted messaging app?
#386Earlier quoted context omitted.
Well of course, but this is a feature of Telegram. It's the only messaging app where messages are stored on the cloud. This of course has security implications, but also allows you to have a big number of chats without wasting your device memory like WhatsApp does, or having to delete old conversations, and allows you to access your chats from any device. By the way you can also set a password to log in from another…
> It's the only messaging app where messages are stored on the cloud Unreal. Please share how you came to this world view.
Re: Is Telegram really an encrypted messaging app?
#387Earlier quoted context omitted.
Not at all. Try searching 500/1000 sources (maximum number of conversations any free/premium user can be part of), each with potentially millions of messages, and providing the results in under a second.
AFAIK telegram dont have any super-advanced search features neither it instantly return you results for all these years. Also if you search less common terms it's usually take longer than less than second. And if you just run client on device without a lot of this history cached search wouldn't be anywhere as fast as you expect. So I pretty sure there no server-side magic there, but instead very good UX. Also I can t…
Re: Is Telegram really an encrypted messaging app?
#388Earlier quoted context omitted.
Signal also allows edits and deletions.
I haven't used Signal in a while, so I probably misremember some of what it supported. I just looked it up though and Signal's delete feature seems to leave a "This message was deleted" placeholder like what Facebook Messenger does, which looks a bit annoying to me ( https://support.signal.org/hc/en-us/articles/360050426432-De... ). Telegram just directly removes the message for everyone.
Re: Is Telegram really an encrypted messaging app?
#389Earlier quoted context omitted.
You seem to be living on this weird balance of having no threat model. This is what your post implies 1. Signal is bad and insecure because registering user account requires giving a phone number. 2. Matrix is better, it fixes this by registering with emails (although emails also have zero click vulnerabilities) 3. Telegram is better than Matrix, it's more usable (even though it also requires a phone number like Sign…
It isn’t about me picking a lane; I’m just stating things as they are. If you want a feature-rich chat and social app that has a user base too, but you don’t care much about security, go for Telegram. Although some might argue that chats aren’t encrypted, no one known has gotten in trouble because Telegram handed over their data. However, you should never rely on that and don’t trust any cloud-based service in genera…
The correct solution to sleeping with an axe struck on the roof above your bed isn't to not worry about it because axes coming loose on their own aren't a common occurrence. Telegram has no business in peoples' personal lives and it shouldn't be collecting that data.
Plus the risk of massive data breach is insane. I'm not sure if you know about the Finnish Vastaamo Psychotherapy hack, when thousands of patients' personal lives were published in the dark web https://en.wikipedia.org/wiki/Vastaamo_data_breach These victims are under constant extortion about that data getting spread even further. Now imagine that with close to one billion users. There is a LOT that people share on these platforms, how they unload to their close ones. Durov has no right to keep this amount of data sitting on some random server, especially given the authors' poor track record of security design.
>you should never rely on that and don’t trust any cloud-based service in general
This should be the take-away before the breach happens. But surely you agree Telegram is doing horrible job being transparent about its security, it's implying it's heavily encrypted, which laypeople assume means what end-to-end encrypted messaging provides.
>Recommending Signal might give a false sense of security.
Again, pick a lane. If you think zero click attacks of Signal are an issue but they magically disappear from Matrix clients, say so. They don't.
Decentralized system doesn't help with metadata. It's just spreading it to even more systems, every server people indiscriminately choose get a copy of groups' communication metadata, yay.
Your buddy self-hosts for you and your peers, now you have an individual with personal interest to take a peek at their peers' metadata. Not good.
There's very little a decentralized messaging platform offers other than baked-in resilience in case the company goes down. You can self-host the service.
But Signal is backed by Signal Foundation and really rich people like Brian Acton have helped it get the organization on a solid foundation. There's nothing that implies its going down.
From my PoV, I bin Element together with Signal, both provide content privacy, but no strong metadata privacy. For that you go with Cwtch, Briar, OnionShare, Ricochet Next.
Telegram is in the don't use for anything that isn't comparable to public Twitter, and since Telegram inevitably leads to misusing it, it's dangerous and bad tool. It was built to aggregate user data, and it will inevitably do that, because the masses generally don't prioritize privacy. Telegram monetizing user data is constantly one business decision away. And people using it are on borrowed time. We're not in disagreement about how it should be used, but people don't take that warning seriously, and when (not if, but when) shit hits the fan, it'll be like nothing anyone has ever seen before.
Re: Is Telegram really an encrypted messaging app?
#390Earlier quoted context omitted.
Well of course, but this is a feature of Telegram. It's the only messaging app where messages are stored on the cloud. This of course has security implications, but also allows you to have a big number of chats without wasting your device memory like WhatsApp does, or having to delete old conversations, and allows you to access your chats from any device. By the way you can also set a password to log in from another…
But that's literally the entire point of this article. That is, in this day and age, when people talk about "secure messaging apps" they are usually implying end-to-end encryption, which Telegram most certainly is not for the vast majority of usages.
Yet, Apple tries to create an image that iPhone is a "secure" device, but if you use iCloud, they can give your contact list to government any time they want.
Apple by default doesn't use E2E for cloud backups, and Telegram doesn't use E2E for chats by default. So Telegram has comparable level of security to that of the leaders of the industry.