8 ms·
>whereas Telegram users typically take these thing seriously. And yet they don't mind the lack of encryption?
by whyoh 5y ago
>whereas Telegram users typically take these thing seriously.
And yet they don't mind the lack of encryption?
- dotancohen 5y agoI cannot speak for everybody, but for me the lack of encryption - thus allowing state actors to intercept - is a far better trade off than the explicit sharing of data with advertisers. Note that I live in a nation in which I support and trust my state. Yet I do not trust advertisers and other entities who seek to influence my opinion. I'm sure that for those who live in states where the government is viewed as adversarial then Signal would be a better choice.
- lxgr 5y agoThat's the thing, though: Telegram cannot be intercepted by state actors. They are jurisdiction hopping to evade that responsibility. > Note that I live in a nation in which I support and trust my state. Given the above: Do you trust any state's government?
- dotancohen 5y ago> They are jurisdiction hopping to evade that responsibility. From a technical perspective, whoever is running those servers can access the data. That aspect is far more important than the legal hurdles. > Given the above: Do you trust any state's government? Yes, my own. But I understand that not everybody has that privilege.
- lxgr 5y agoEr, sorry, I meant "every", because you don't trust yours with Telegram – you trust a more or less random one, depending on their jurisdiction hopping location of the day.
- dotancohen 5y agoI see. Well, you are correct. I'm sure that a particularly motivated entity with access to my Telegram could find something on me, and coercing foreigners with blackmail could be a good strategy for any government.
- lpcvoid 5y agoCan we stop comparing the lack of default-on e2ee in Telegram to "no encryption"? There is transport encryption in MTProto since the beginning. There are e2ee chats for those who want them.
- whyoh 5y ago>Can we stop comparing the lack of default-on e2ee in Telegram to "no encryption"? I don't think we should. In the context of messaging at least, encryption should mean E2E encryption. Bragging about client-to-server encryption is pointless nowadays, when 99% of the internet is already encrypted this way.
- lpcvoid 5y agoThat is quite misleading to a vast amount of people without tech background. I find it dishonest, even more so because Telegram actually does offer e2ee chats - and 1:1 voice/video chats are already e2ee, for what it's worth.
- tapoxi 5y agoIs it? In WhatsApp all of your messages are E2EE. In Telegram it’s an option, only works in 1:1, doesn’t support desktop, and uses homegrown encryption.
- whyoh 5y ago>That is quite misleading to a vast amount of people without tech background. Not as misleading and potentially harmful as saying "Telegram is encrypted" as a blanket statement, because: 1. as I said, the client-to-server encryption is not noteworthy (almost everything has that) and it shouldn't be enough for privacy-conscious people. 2. even though Telegram does offer some e2e encryption too, its availability is quite limited and not representative of the typical Telegram usage. Sure, I was being too dismissive there. But I don't like how Telegram gets brought up as a "private messenger", in the same context as fully e2e-encrypted messengers like Signal or even Whatsapp. For all intents and purposes, Telegram is more similar to apps like Discord or Slack, seeing how most of the comms can be read by anyone who has access to the server. And Telegram can only be used with a phone number, so in terms of anonymity it's even worse than those.
- tryauuum 5y agoI understand and respect your motive for saying that telegram has no encryption. At the same time I cannot stop hating you for improper use of words. I wish there was a simple and catchy word for describing a "vulnerable to the government" encryption
- nani8ot 5y agoFor me, transport encrypted (e.g. TLS) is the bare minimum everything going over a wire should be encrypted with, so encryption in the context of messenger is for me always about E2E. As far as I know, Google and Apple don't even allow apps to use unecrypted HTTP if dev's want them to be in their respective app store. As a term, e2e encryption is quite short, and is also easy to search for, if someone does not know what it is.