Earlier quoted context omitted.
Secure systems are all alike; every insecure system is insecure in its own way. A messenger that has E2E encryption might not be secure, but a messenger that doesn't have E2E encryption is definitely insecure. Not caring about your messages being read, or being willing to trust the operator of the service, is fine, but in that case I struggle to see why you'd pick Telegram, given that their whole selling point was ab…
> A messenger that has E2E encryption might not be secure, but a messenger that doesn't have E2E encryption is definitely insecure. It is secure for my purposes. Throwing away threat models and the meaning of secure and encrypted just to be able to define something that competes for attention as "not secure" and "not encrypted" (from other threads) isn't very high level, it is basic framing. edit: > Not caring about…
It's basic, but it's valid. I was responding to all your "It doesn't matter if it is E2E-encrypted if xyz" points, which are faulty logic; if whether it's E2E-encrypted matters in your threat model, then whether it's E2E-encrypted still matters in your threat model even if other aspects of the system are secure.
> Remember, when Telegram came around WhatsApp was un-encrypted. Not point-to-point encrypted, just encoded. You didn't need to know or crack a key, you just needed toknow the protocol.
Citation? I don't remember it happening that way at all; Telegram marketed themselves by attacking WhatsApp on a couple of minor vulnerabilities in side features like video handling (which was legitimate in some ways, but extremely hypocritical given the bigger weaknesses in Telegram's own implementation). If message text was readable that would have been a much bigger deal.