9 ms·
I understand Telegram's appeal because of its high quality apps and big feature list, but articles such as this one really should be more nuanced when pushing T
by mgw 8y ago
I understand Telegram's appeal because of its high quality apps and big feature list, but articles such as this one really should be more nuanced when pushing Telegram's marketing message of "We have true privacy and unlimited space for everyone.".
Their default mode is not end-to-end encrypted [1] and as such the product is less private than WhatsApp. Even tech-savvy users in my social circles are not aware of this and blindly recommend Telegram as the more private option.
When talking about privacy these articles should at least mention Signal. I hope they will use their recent funding [2] to polish their apps and increase the speed of innovation.
[1] https://telegram.org/faq#q-so-how-do-you-encrypt-data https://telegram.org/faq#q-so-how-do-you-encrypt-data
[2] https://signal.org/blog/signal-foundation/ https://signal.org/blog/signal-foundation/
- s_dev 8y ago>Secret chats are meant for people who want more secrecy than the average fella. All messages in secret chats use end-to-end encryption. Seems fair to me -- some people do want some archive of their conversations but the option to limit the storage duration of those conversations. Secret chat is a heavily promoted feature -- it's not some hidden mode just because it's not the deafult.
- dnate 8y agoThere is literally no downside to end-to-end encrypting text messages. So it should be default. It is just harder to implement technically.
- newscracker 8y agoThat's not a very good use of "literally", because searching through encrypted messages will certainly be slower, and on mobile devices, this will have a bigger impact on responsiveness and battery life. That is a big downside on mobile (not desktop). Create similar chats that are long (like tens of thousands of messages) on different apps and compare Telegram's search speed with others'.
- codedokode 8y agoKeeping a long history is almost always a bad idea because something you have written a year ago and have forgotten can be used against you. Keeping messages for just about a week is much better idea.
- skyyler 8y agoFor you. Some people like having records.
- mbesto 8y agoWhich is why we have other communication channels for that type of thing. Instant messaging should be ephemeral.
- mcculley 8y agoWhy should it matter which medium is used? I have some conversations I want to keep forever. Some I treat as ephemeral. This should be a per-conversation setting.
- davchana 8y agoNot always, I have my emails on Gmail since 2010 & WhatsApp chats since beginning and through multiple device changes.
- dvdgsng 8y agoReading old IRC or ICQ logs from 2001 can be quite fun though, brings back some memories.
- mruts 8y agoMine got me interviewed by the FBI. So there are some downsides :p
- 8y ago
- thecatspaw 8y agoThere is, you can only access them on the devices you sent them from or receive them from. If you add another client weeks down the line, you cannot access these messages anymore
- rickycook 8y agonot entirely true... you can pair a new device which shares the decryption key. hell, you could even do a p2p sync so the server stores nothing... there are plenty of options that get technically harder with each increment (perfect forward secrecy gives you some limitations), but you can absolutely backup and restore, or even live sync conversations between multiple devices even if it’s e2e
- derefr 8y ago> It is just harder to implement technically. To the point that the major players mostly fail at doing it well enough to achieve a good UX. WhatsApp doesn’t allow you to sync conversation history between devices, even though this is technically possible. It’s just hard, so they don’t do it. Instead, they require you to have a single device (e.g. your phone) acting as a secure conversation-history database, which other devices (e.g. your laptop) can then interact through WhatsApp “thin clients.” iMessage manages to sync conversation history between devices while also being E2E-encrypted, but it’s the exception (and also unavailable to non-Apple users.)
- r00fus 8y ago1) yes, harder/costlier to implement 2) maintaining security is an issue - losing security can cause outage or trust 3) patents are a thing.
- arendtio 8y agoJust to throw in another alternative: Some might know XMPP [1] for being the IETF standardized instant messaging protocol and Conversations [2] as one of the modern XMPP clients. Recently, the main author of Conversations created a new version of his app called 'Quicksy'. Quicksy is still an XMPP client but with the ease of use other messangers deliver. For example, you don't have to choose a provider. Yet you still have features like federation available. So a perfect solution to invite others to join the XMPP world. - https://play.google.com/store/apps/details?id=im.quicksy.client https://play.google.com/store/apps/details?id=im.quicksy.cli... - https://quicksy.im https://quicksy.im [1] https://en.wikipedia.org/wiki/XMPP https://en.wikipedia.org/wiki/XMPP [2] https://conversations.im https://conversations.im
- bovermyer 8y agoI just bought the Conversations app a couple days ago. It looks like, from the Quicksy.im site, that Quicksy is meant to eventually funnel users into Conversations. I'm a little confused by this path. What would make Quicksy users go to Conversations?
- arendtio 8y agoWell, I think this is more like a newcomer vs. power user scenario. If you are new to XMPP, Quicksy gives you a decent messenger without requiring you to know how everything works. After a while though, you might learn that you can host your own server or use your own domain and want to do that. At that point, however, you would have to switch to Conversations as Quicksy allows only Accounts on Quicksy servers (AFAIK). Actually, I don't think the primary reason for Quicksy is to increase the sales of the Conversations app. I think it is more about to get more people in contact with the XMPP ecosystem, without asking them to pay for an app like Conversations up front. After all, the ones who are doing XMPP nowadays are fighting for the cause and not for the cash.
- bovermyer 8y agoGotcha. Thanks for the clarification.
- tapoxi 8y agoI love Signal, but it has issues. It _feels_ slow. I've had messages appear out of order, I've had the desktop app suddenly stop sending messages while simultaneously spamming my contacts (https://i.imgur.com/QDR22xl.png https://i.imgur.com/QDR22xl.png). I don't love that they refuse any discussion about federation. They don't implement fun features that my friends or family want to use. It's secure, but it seems like a niche product targeting those who really care about security and aren't able to use iMessage.
- newscracker 8y ago> When talking about privacy these articles should at least mention Signal. I hope they will use their recent funding [2] to polish their apps and increase the speed of innovation. I keep repeating this often, but Signal is not a user friendly platform for average users. It is good for ephemeral chats and conversations that one wouldn't care about later. Signal actively blocks chats from being backed up (and restored) on iOS. So if you switch to a new device, you'd have to start afresh without any chat histories and also join all the groups once again. The fact that this issue was opened a long time ago on GitHub and responded to by saying it's a security issue to allow backups shows what audience Signal is focusing on (investigative journalists, dissidents and activists who use burner devices and don't need any traces of chats to linger around). Telegram, on the other hand (even with the not-end-to-end-encrypted default), makes for easy moves between devices (supporting chat syncing across OSes and devices) and to newer devices, with every chat showing information shared as links, photos, etc., and very easy to get back to. Of course, since the chats are not stored encrypted on its servers, search is also blazingly fast. One deficiency with Telegram is that the end-to-end encrypted chats ("secret chats") are tied to phones and can't be initiated from other devices or seen from other devices. Those also don't carry over to a new device. There is no technical reason for this, because Wire (which in my opinion is a better alternative to Signal and easier to sell others on) handles end-to-end encryption with syncing across devices.
- ardy42 8y ago> Signal actively blocks chats from being backed up (and restored) on iOS. I don't think that's true. Signal's backups require you to copy a file from your old phone to your new phone's storage. It's possible on Android to mount your phone's filesystem on a PC. IIRC, Apple is the one that doesn't make that easy on iOS, not Signal.
- newscracker 8y agoWhat I said (specifically about iOS) is true and has been so since 2015 (or earlier). See [1] and [2] that I linked in another comment here and check on backups explicitly being denied on iOS. This has nothing to do with Apple, and everything to do with the Signal team not willing to make it user friendly (for this case). [1]: https://github.com/signalapp/Signal-iOS/wiki/FAQ https://github.com/signalapp/Signal-iOS/wiki/FAQ [2]: https://github.com/signalapp/Signal-iOS/issues/905 https://github.com/signalapp/Signal-iOS/issues/905
- kadendogthing 8y agoAnd they rolled their own encryption. It's a false sense of security.
- jhoechtl 8y agoSignal all the way down. It's the only viable solution we have now on a compromise level between security, usability and user base.
- AsyncAwait 8y agoor Wire if you don't want to use your phone number
- deleted 8y ago[deleted]
- acct1771 8y agowww.riot.im
- kpcyrd 8y agoThey also aggressively reject certain phone numbers.
- kerng 8y agoAgree, that the arguable best option Signal should be at least be mentioned. Also, unlikely at that if Telegram had an drastic increase in users that it would be similar for Signal.
- lloeki 8y ago> and as such the product is less private than WhatsApp Given that 1. it's owned by FB and 2. FB's plan is to move towards FB/Messenger/WhatsApp/Instagram grand messaging unification (in spite of them promising they would not) we can reasonably assume they won't keep E2E for long (because chat in the browser). Also, it's FB. Even if it's E2E, FB control the apps at both 'E's and I would not trust them with anything privacy related.