4 ms·
> “If you have WhatsApp on your phone and your battery’s low and your phone goes dead, suddenly you can’t get access to your messages. It’s over. It’s not cross
by slasaus 11y ago
> “If you have WhatsApp on your phone and your battery’s low and your phone goes dead, suddenly you can’t get access to your messages. It’s over. It’s not cross device. It doesn’t have cross-device sync. You can’t send documents or big media. There are lots of limitations in the group chats, in your communication. It’s not private. So I’m not sure I was a big fan of WhatsApp about three years ago, and I’m not sure I am now,” he said.
Unfortunately, E2E encrypted chat doesn't work when using these multi-device features, and so most contacts of mine don't use the privacy or security features of Telegram.
- izacus 11y agoHow doesn't it work? Having a shared passphrase would work just fine - and it wouldn't even be more complex UX wise. Not being able to receive WhatsApp messages on two devices is one of the major annoyances with having browser tethered to the phone being the second in line. Especially when you have flakey wifi on the phone it gets really unbearable.
- superuser2 11y agoIt can; Apple's approach is to distribute lists of public keys instead of single ones. The seem to have the same threat profile: Apple can be compelled to silently add a public key to the keybag; Telegram can probably be compelled to silently replace a public key with an MITMed version.
- slasaus 11y agoYou're right and I believe WhisperSystems is doing something similar (or was at least working on it last year when I spoke with one of the developers). I vaguely remember them claiming that group chat is about the same as multi-device, cryptography-wise. I specifically meant Telegrams E2E implementation. Apart from other problems with it [1] the fact that it's not on by default, as others have stated, makes that most people (especially non-technical users) don't use it. [1] https://github.com/zhukov/webogram/issues/126#issuecomment-127982342 https://github.com/zhukov/webogram/issues/126#issuecomment-1...
- StavrosK 11y agoIt does work, Silent Circle does it, for example. It's much more complicated and thus much more prone to failure and complicated UX, but it does work. In the trivial case, you share the key between all devices. This loses you a bunch of security, but it demonstrates trivially that it works. You can also just encrypt the message once per device, which increases your data volume, but is a good compromise otherwise.