5 ms·
I really like Telegram and these features but I don’t use it because they don’t have end2end encryption as default. Also you can’t create a secret group chat th
by blue_box 6y ago
I really like Telegram and these features but I don’t use it because they don’t have end2end encryption as default. Also you can’t create a secret group chat that you can start from your phone and continue from your Mac.
- darthrupert 6y agoI think it would make it slightly more difficult for them to profit from the chats.
- TheChaplain 6y agoJust out of curiosity, what kind of discussion do you have that require e2e? Myself I use TG extensively with friends, family, girlfriend and I think I've used secret chats once when the gf wanted to send a naughty photo. It's not that I don't have anything to hide, it's just I choose what to say according to the environment and I feel the features of telegram far outweigh the con of not having e2e at all times.
- randomhodler84 6y agoOh no. No. “You have nothing to share.” E2e by default or GTFO. This isn’t about your secrets. It’s about making your regular discourse indistinguishable from secrets. There is no con to e2e, and many cons for snake oil/plaintext.
- parhamn 6y ago> There is no con to e2e, and many cons for snake oil/plaintext. Is this true? From anecdata every e2e encrypted platform I used is much lower quality than the alternatives (iMessage, Signal, etc). Things like multi-device sync don’t work that well. Is this really just a coincidence? Telegram claims they can’t provide the same quality chat (and snappy cross platform crispness is really their competitive advantage) with e2e. Is this just a fake limitation?
- newscracker 6y agoTechnically, E2E increases the complexity of the applications and servers, but it shouldn't really affect quality of chats or messages. One area where this will be a problem is in search. Telegram claims that is can search chats faster because those are on its servers, and anecdotally, I have seen Telegram's search being better and faster than the other platforms I use or have tried (they have to search only on the local device, which then has an impact on battery life for phones and tablets). The other bigger drawback with E2E is that the servers of those platforms don't store the chats permanently (they store it for about 30 days or so to deliver the messages to devices when they come online, depending on the platform). So syncing chat history across devices gets affected by this choice (it could still be done, but the complexity and speed of syncing grows a lot). Wire does E2E for all chats and syncs all chats across devices. But it too doesn't sync chat history on newer linked devices. It also took the (what I consider as inferior) choice of using Electron for its desktop apps, which makes it quite sluggish.
- kitkat_new 6y ago> he other bigger drawback with E2E is that the servers of those platforms don't store the chats permanently (they store it for about 30 days or so to deliver the messages to devices when they come online, depending on the platform). Not true: Matrix is fine with storing messages permanently
- xorcist 6y ago> There is no con to e2e, No multi device support. No transcoding for video. No shared history for group chats. Scaling get progressively harder with increasing participants.
- rakoo 6y ago> No multi device support. That's an issue with your client and protocol, not with e2e > No shared history for group chats. Same > Scaling get progressively harder with increasing participants. Same > No transcoding for video. Now that's a more palpable issue. Also no size reduction of photos which is probably more used as a media.
- vetinari 6y ago> That's an issue with your client and protocol, not with e2e That's issue with distributing the keys among multiple parties. > No shared history for group chats. > Same Exactly. What's e2e good for, if you give keys to the entity that does the archiving?
- rakoo 6y agoIf you have 2 devices, one device can send messages to the other, all e2e encrypted. It's the same for group chats: if you are part of a chat, any participant can send you the history of the chat. All those issues are protocol-related. E2E only stipulates that the message can't be read between the two ends, it doesn't say you can't send a technical message for making a better UX.
- est31 6y agoDoesn't even have to send the full history of the chat, it can only send you the encryption key while the history is stored on the server.
- rakoo 6y agoIndeed, and you can go even further: with e2ee there is no need for central server beyond dumb distribution of opaque blobs. So the history can be exchanged by the whole network and the encryption keys shared recipient by recipient on a need-to-know basis. That's what bitmessage is doing, for example
- AnyTimeTraveler 6y agoActually, there are many cons to e2e, especially with bigger groups. I've read a lot about Signal's and Matrix's development and there are many problems that don't exist when sending data over a simple SSL connectiom to a server. For example: You have a group with 100 Members, do you encrtpy each message you send 99 times for each recipient? Not likely. So you use a send key that everyone else can decrypt. But then what if the group changes? Does everyone has to replace their send-keys, because the party that left can still decrypt all those messages otherwise. That means you have to do n-1 key exchanges whenever a party leaves or joins. Otherwise it wouldn't be secure anymore. There are some clever ideas about key exchanges, but so far the messengers that implement them are not widely used and since there is no profit in it, no one is in a hurry to compete.
- sarakayakomzin 6y ago> Just out of curiosity, what kind of discussion do you have that require e2e? Where as your conversations couldn't possibly be made illegal by your government in the future?
- rakoo 6y agoThere are two kinds of things someone may want to hide: legal stuff and illegal stuff. It's a real shame that governments have succeeded in conflating the two and forcing us to take a position that is not the one we really have. Truly a brilliant move. Of course you have something to hide, it's called privacy. There is absolutely no reason your private life should be public by default, so why accept it ?
- TheChaplain 6y agoI fully understand. Privacy is important to me, but it's not a binary state. What I talk about to my friends, girlfriends and family are all on different "privacy levels". If the chats with my friends were disclosed, I'd probably be made a laughing stock at most but it's no big deal. My family ones would probably be most boring, and the ones with my girlfriend could be material for a soap opera, and embarrassing. But it's not the end of the world if someone at Telegram can read them of if they were disclosed by some hacker group. My point is that it is an amazing chat app and have way too many benefits for me to not use it, but I _am_ fully aware that there are a chance what I write can be read by someone else, and therefore I take care what I write about. Oh, and thank you for keeping the discourse on a respectful level. :)
- dschuessler 6y ago> If the chats with my friends were disclosed, I'd probably be made a laughing stock at most but it's no big deal. That’s a privilege many people don’t have. Think about sexual preferences, controversial opinions or health problems that can be disadvantageous in their career or when obtaining insurance. Or that aren’t problematic now but might be in the political climate in 20 years. You could argue that people worrying about this still have the choice to use an E2E encrypted messenger. After all different needs are served by different products. But if this behavior becomes the norm, people who hide possibly disadvantageous information can be identified simply by their messenger use, partially defying the purpose of hiding their information in the first place. I consider this a very strong argument for privacy as the default regardless of particular people's lack of a need for privacy. EDIT: Removed remarks that could be misunderstood as snark.
- TedShiller 6y agoCan you send me a zip archive of all your chats? It would be fun for me to read and ok with you since you have nothing to hide. You can contact me here. If you don’t send me your chats then I assume you want privacy after all.
- TedShiller 6y agoStill waiting
- heyoni 6y agoMe too. It shouldn’t take this long! Ps: hard drive image clones should also do the trick.
- samat 6y agoNot op, but what would you give him in return? Sending some random purist on the internet my personal texts is one thing. Sending it to the company promising secure communication, company which delivers the best convenience messaging UX in the whole fucking world without any ads... Well, if you can’t see the difference...
- samat 6y agoDon’t get me wrong, I love complete e2e! I am choosing iMessage with complete e2e every time I can, but iMessage is iOS only and telegram is many years ahead in user convenience even from it. You might as well continue pushing for pgp for secure email. User convenience is not optional.
- kitkat_new 6y agoyou conflate iMessage with what is possible with e2ee
- gbh444g 6y agoI think the argument here is that without e2ee, the chats are available to whoever pays enough (e.g. advertisers). So in return he will get some ads and sms spam.
- proactivesvcs 6y agoAbout the weather. Cute manitee gifs. Politics. Jokes. Rants. About life, the universe and everything.
- Krasnol 6y agoI don't know how one can't be aware that Telegram is pretty well known for it's illegal content 2021.
- newscracker 6y agoActually, you can't start a secret group chat at all in Telegram. It supports secret chats only for chats between two people, and that's where it's tied to the devices used for initiating the chat.
- vetinari 6y agoSecret chat with multiple devices or with group has the key distribution problem - what's good to receive the message, if you cannot read it? When there are exactly two devices, you avoid that problem. That's why it is not on by default and why it doesn't work for groups. Most users favor convenience over strict e2e.
- kitkat_new 6y ago> Secret chat with multiple devices or with group has the key distribution problem which is solvable Signal and Matrix have two distinct approaches to this
- vetinari 6y agoSure, it is. But it has its own problem. Signal, for example, copies the received messages into per-device queues that belong to the same identity. The problem for the user is that the user has no visibility into what is really assigned to his identity and where copies of his messages are routed encrypted by which keys; it could be used to implement anything between CALEA to Prism access. I'm not familiar with the Matrix approach, so I won't comment on it.