4 ms·
I wouldn't go near Telegram if you paid me.
by gjmacd 8y ago
I wouldn't go near Telegram if you paid me.
- ascii_only 8y agoWhy?
- DCKing 8y agoTelegram - unless you deliberately take action and opt out of cross-device sync for individual chats - stores all your messages in plaintext on their server. If you want your chats secure, you will need to convince everybody you're chatting with to opt out of cross device sync. Good luck with that. This is in contrast to e.g. Wire, [a near-future release of] Riot.im / Matrix.org, and (AFAICT) Viber, which do end-to-end encryption by default and cross-device without compromises. The messaging providers don't know anything about your chats there. This is the way it should be. There are also complaints about Telegram's "weird" cryptography, although nobody's ever shown anything close to a practical attack yet, and definitely not for the current version of their custom MTProto protocol. The core problem is really in their insecure-by-default service offering.
- octosphere 8y ago> There are also complaints about Telegram's "weird" cryptography https://security.stackexchange.com/questions/18197/why-shouldnt-we-roll-our-own https://security.stackexchange.com/questions/18197/why-shoul...
- DCKing 8y agoTo be absolutely fair to Telegram, the accepted answer rightly says: > You can roll your own, but you probably will make a major security mistake if you are not an expert in security/cryptography or have had your scheme analyzed by multiple experts. Telegram has published the specification and multiple implementations of this protocol for over half a decade. Nobody has found this "major security mistake". One weakness was found in MTProto 1.0, that did not have practical adverse effects for message confidentiality, and which they fixed in the new version of MTProto. Despite them encountering a bunch of (well-deserved, mind you) cryptographic snubbery, nobody has shown the protocol to be breakable in any practical way. Although of course it's still true that rolling your own cryptography is a terrible idea, Telegram is not a great example to support that idea at this point. The perceived weakness of MTProto really is not Telegram's core problem. The fact that the discussion moves in that direction every time Telegram's security is mentioned is troublesome. First, it's a weak argument, because nobody has broken it in five years. Second, the cryptography circlejerk obscures the fact that Telegram has made far more stupid decisions in terms secure UX of that they also show no intention to backtrack on. Even if Telegram was using something akin to the Double Ratchet Algorithm (which they absolutely should), I still wouldn't touch an alternative messenger app that stores all my chats in plaintext.