5 ms·
The author of the parent comment specifically mentioned "change in privacy update" as the reason to switch. Until WhatsApp drops end-to-end encryption, there's
by ash 6y ago
The author of the parent comment specifically mentioned "change in privacy update" as the reason to switch. Until WhatsApp drops end-to-end encryption, there's not that much evil they can do. They can't read your messages. You don't need to trust WhatsApp (so far).
Telegram can have the best privacy policy, but they can always read your messages. You have to trust Telegram to do the right thing. (Except those few who opt in to use encrypted chats.)
- junippor 6y agoWhy is this such a big issue? When I use Telegram in the past (and I did for years) every chat I had was encrypted. Enabling isn't that complicated.
- EduardoBautista 6y agoEnabling E2E encryption in Telegram limits you to only the device that the chat was created in. WhatsApp and Signal allow you to use their desktop apps (not the best app but that isn't the point). This allows me to use a full sized keyboard when I have the need.
- rakoo 6y agoIt's not complicated, but it's still something you have to manually do (meaning many will never do it because they don't know it exists) and you lose a lot of features that seem to be the selling points of Telegram
- newscracker 6y agoWouldn’t you have to trust WhatsApp to do the right thing too, as far as end to end encryption is concerned? How would anyone know if the original Signal E2E is still around or changes have been made to it? WhatsApp already collects, stores and shares more metadata than Signal does. Are there any audit reports from trustworthy parties on WhatsApp behaving as expected on encryption? Or are we just relying on someone working on WhatsApp to become a whistleblower?
- ash 6y agoSure, WhatsApp can go rogue at any time. Signal app is obviously better. However, at least we have a possibility to find out if WhatsApp goes evil - decompilation, protocol analysis are still available. I wouldn't also discount fear of reputation losses if E2E vanishes from WhatsApp. Compared to maybe-evil-in-the-future WhatsApp, default Telegram is already evil, because they have access to all communication right now. What do (or will) they do with all that data? (Opt-in E2E - and only for 1-on-1 chats - is almost useless. Encryption should be the default.)
- newscracker 6y agoI think you missed my point, which is that WhatsApp is already rogue by way of metadata collection (which is as valuable as content), and that there’s no way anyone can claim with certainty that it’s not gobbling up more data on the server. Even Signal has stopped publishing its server source code for nearly a year, and if we are playing the game of what Telegram is doing with the data, we can say the same about Signal too on metadata (now that more information about groups and group memberships is stored on the servers).
- ash 6y agoWe don't need to play any games to point out that Telegram can see everything, including messages.
- AndriyKunitsyn 6y agoYou have to trust WhatsApp, because it is closed-source. Nothing stops them from planting a backdoor and enabling it specifically on your device, or from updating the E2E protocol to make it insecure. If your threat model includes WhatsApp/Telegram developers, you can't use WhatsApp but you can actually (carefully) use Telegram's E2E chats, because Telegram's client is an open-source app with reproducible builds. E2E in a closed-source app is useless, and all UX inconveniences of E2E are just "security theater".
- ash 6y agoClosed source WhatsApp is a problem. And a backdoor is possible. However, it's still detectable, albeit not easily. I'm sure researchers are closely looking at WhatsApp binaries. WhatsApp backdoor would be a scandal. Sure, open source WhatsApp would be better. However, we are comparing detectable potential backdoor with totally undetectable existing access to all non E2E chats on Telegram servers. Telegram developers can already see everything right now. (By the way, opt-in E2E encryption is almost useless. Encryption should be the default, and enabled for group chats too.) Between these two options WhatsApp situation is clearly better.
- AndriyKunitsyn 6y agoYour comment is based on two assumptions: - That backdoors are routinely detectable in closed-source applications. They are not just "not easily" detectable, they are impossible to detect without a good amount of luck, and even so, the knowledge about a new backdoor will come after years, after all of the damage was done. Numerous discovered RCEs in Windows, some of which laid there for more than a decade after being found, confirm this. - That there are incentives for security researchers to routinely disassemble WhatsApp binary and provide results of their inspection to the public, and not just report to employers or use the knowledge about a Facebook-authored backdoor to blackmail Facebook. There are none. If you discard these two assumptions, you can see that Telegram model is better because it gives users clear choice between passing data to Telegram (in exchange for chat sync) and using E2E, with strong guarantees of E2E that are backed by reproducible builds, not by trusting Facebook or "oh, but that would be a scandal". The "almost useless" E2E of Telegram (I don't see how it's almost useless, it's there, it's working, and it provides value for users) is better than the completely useless E2E of WhatsApp. (But yeah, group chats have no option of E2E in Telegram, that sucks.)