6 ms·
Strange to see people switch from end-to-end encrypted WhatsApp to non-encrypted (by default) Telegram. What do I miss?
by ash 6y ago
Strange to see people switch from end-to-end encrypted WhatsApp to non-encrypted (by default) Telegram. What do I miss?
- junippor 6y agoObviously you're missing that there's more factors to a person's choice than default encryption.
- ash 6y agoThe author of the parent comment specifically mentioned "change in privacy update" as the reason to switch. Until WhatsApp drops end-to-end encryption, there's not that much evil they can do. They can't read your messages. You don't need to trust WhatsApp (so far). Telegram can have the best privacy policy, but they can always read your messages. You have to trust Telegram to do the right thing. (Except those few who opt in to use encrypted chats.)
- junippor 6y agoWhy is this such a big issue? When I use Telegram in the past (and I did for years) every chat I had was encrypted. Enabling isn't that complicated.
- EduardoBautista 6y agoEnabling E2E encryption in Telegram limits you to only the device that the chat was created in. WhatsApp and Signal allow you to use their desktop apps (not the best app but that isn't the point). This allows me to use a full sized keyboard when I have the need.
- rakoo 6y agoIt's not complicated, but it's still something you have to manually do (meaning many will never do it because they don't know it exists) and you lose a lot of features that seem to be the selling points of Telegram
- newscracker 6y agoWouldn’t you have to trust WhatsApp to do the right thing too, as far as end to end encryption is concerned? How would anyone know if the original Signal E2E is still around or changes have been made to it? WhatsApp already collects, stores and shares more metadata than Signal does. Are there any audit reports from trustworthy parties on WhatsApp behaving as expected on encryption? Or are we just relying on someone working on WhatsApp to become a whistleblower?
- ash 6y agoSure, WhatsApp can go rogue at any time. Signal app is obviously better. However, at least we have a possibility to find out if WhatsApp goes evil - decompilation, protocol analysis are still available. I wouldn't also discount fear of reputation losses if E2E vanishes from WhatsApp. Compared to maybe-evil-in-the-future WhatsApp, default Telegram is already evil, because they have access to all communication right now. What do (or will) they do with all that data? (Opt-in E2E - and only for 1-on-1 chats - is almost useless. Encryption should be the default.)
- newscracker 6y agoI think you missed my point, which is that WhatsApp is already rogue by way of metadata collection (which is as valuable as content), and that there’s no way anyone can claim with certainty that it’s not gobbling up more data on the server. Even Signal has stopped publishing its server source code for nearly a year, and if we are playing the game of what Telegram is doing with the data, we can say the same about Signal too on metadata (now that more information about groups and group memberships is stored on the servers).
- ash 6y agoWe don't need to play any games to point out that Telegram can see everything, including messages.
- AndriyKunitsyn 6y agoYou have to trust WhatsApp, because it is closed-source. Nothing stops them from planting a backdoor and enabling it specifically on your device, or from updating the E2E protocol to make it insecure. If your threat model includes WhatsApp/Telegram developers, you can't use WhatsApp but you can actually (carefully) use Telegram's E2E chats, because Telegram's client is an open-source app with reproducible builds. E2E in a closed-source app is useless, and all UX inconveniences of E2E are just "security theater".
- ash 6y agoClosed source WhatsApp is a problem. And a backdoor is possible. However, it's still detectable, albeit not easily. I'm sure researchers are closely looking at WhatsApp binaries. WhatsApp backdoor would be a scandal. Sure, open source WhatsApp would be better. However, we are comparing detectable potential backdoor with totally undetectable existing access to all non E2E chats on Telegram servers. Telegram developers can already see everything right now. (By the way, opt-in E2E encryption is almost useless. Encryption should be the default, and enabled for group chats too.) Between these two options WhatsApp situation is clearly better.
- AndriyKunitsyn 6y agoYour comment is based on two assumptions: - That backdoors are routinely detectable in closed-source applications. They are not just "not easily" detectable, they are impossible to detect without a good amount of luck, and even so, the knowledge about a new backdoor will come after years, after all of the damage was done. Numerous discovered RCEs in Windows, some of which laid there for more than a decade after being found, confirm this. - That there are incentives for security researchers to routinely disassemble WhatsApp binary and provide results of their inspection to the public, and not just report to employers or use the knowledge about a Facebook-authored backdoor to blackmail Facebook. There are none. If you discard these two assumptions, you can see that Telegram model is better because it gives users clear choice between passing data to Telegram (in exchange for chat sync) and using E2E, with strong guarantees of E2E that are backed by reproducible builds, not by trusting Facebook or "oh, but that would be a scandal". The "almost useless" E2E of Telegram (I don't see how it's almost useless, it's there, it's working, and it provides value for users) is better than the completely useless E2E of WhatsApp. (But yeah, group chats have no option of E2E in Telegram, that sucks.)
- vikbytes 6y agoPresumably the fact that Facebook owns WhatsApp and continues to erode all the "protections" users of WhatsApp initially had from the invasive tentacles of Facebook into their data on WhatsApp.
- EduardoBautista 6y agoApart from the fact that they have access to your contacts, I haven't felt that the E2E encryption of WhatsApp has been in danger of being eroded. I do use Signal when possible, but I find WhatsApp to be secure enough for my day to day messaging with friends and family. I can't say the same about Telegram since it does not have E2E encryption on by default on all messages.
- barbazoo 6y agoFor many it was the prospect of metadata being sent to WA's big brother Facebook. Personally I don't want anything to do with the FB ecosystem so I deleted my WA account. I didn't have anything against WA per se, I really like the app , just the connection to FB is unacceptable.
- bryan_w 6y agoBut if telegram sells to FB or someone worse, you will be in a worse position as now they will not only have your metadata, but also the full text of your messages. It doesn't make since to move away from one company for privacy reasons onto another company with even worse privacy.
- barbazoo 6y agoThat's right. I don't think I said otherwise.
- skinkestek 6y ago1. why do everyone insist E2E-encryption is necessary for IM but not for email and letters ( the alternatives)? Because that is mostly what I use Telegram for. 2. I could have a hard time choosing between Signal and Telegram some days. With WhatsApp I know Facebook will do metadata analysis on my contacts and my conversations (possible even with E2E-encryption). They'll also upload some or all my messages unencrypted to Google if I or any of my contacts enable backups. Does that explain it?
- ash 6y agoE2E encryption is necessary for all communication. Email is unfortunately not encrypted, but it doesn't explain why would you choose non-E22 tech when there are perfectly good E2E alternatives. E2E is an insurance against: * bugs * rogue employee * server vulnerabilities * acquisitions (imagine Telegram being acquired by Facebook) As for metadata analysis, I still fail to understand how is it comparable to Telegram having access to all messages.