6 ms·
No analysis needed. Telegram holds the keys to decrypt the messages and that's all you need to know. It's why you are able to just login to your Telegram accou
by plexicle 4y ago
No analysis needed. Telegram holds the keys to decrypt the messages and that's all you need to know.
It's why you are able to just login to your Telegram account on another device and magically get all of your message history.
So while the tech might be solid, the keys are still out there. They can be leaked. They can be subpoenaed, etc.
- gwd 4y agoI like how Matrix handles this: You can either download and store locally a key that you enter into a new device to decrypt the encrypted messages stored on the server; or you have one of your other active devices decrypt its locally stored messages and send them to the new device (using some form of verification to prove you control both devices).
- tptacek 4y agoUntil very recently (weeks not months), Matrix servers controlled group membership, and could add arbitrary accounts to your group without permission, thus allowing them to decrypt messages to the group. Matrix servers could also silently add "devices" to your account. https://nebuchadnezzar-megolm.github.io/ https://nebuchadnezzar-megolm.github.io/
- cvwright 4y agoMatrix servers still control group membership, and probably will for a while (ie, months). The vulnerabilities that allowed such users and devices to steal keys have been fixed.
- tptacek 4y agoControl of group membership in Matrix is control of key distribution. That's generally how group secure messaging works. The vulnerabilities didn't allow unauthorized group messengers to "steal" keys; it added unauthorized members to groups, which causes authorized group members to negotiate key relationships with them.
- skyyler 4y ago>It's why you are able to just login to your Telegram account on another device and magically get all of your message history. Secret chats are secure, and you cannot access them except on the device you start them with. It's one of the pain points for people that use them: they don't sync like normal chats.
- palata 4y agoYou just said it yourself: "normal chats are not end-to-end encrypted". The normality on Telegram is messages that their servers can read.
- skyyler 4y agoTelegram's secure chats do not sync across devices. A secret chat is one device to one other device. If you start one on your phone, you won't even see that it exists on your laptop or tablet. Secret chats by default wouldn't make sense for telegram. It's not a secure messages app anymore... It's a social media platform with a secure chat feature.
- palata 4y agoExactly: it's not a secure messenger. It has an option of secret chats which is not as private as Signal. If you want privacy, use Signal. If you want UX, use Telegram. Just don't pretend Telegram is private. Both are fine, but people need to know what they are doing.
- skyyler 4y agoTelegram isn't private. Its secret chats are.
- lloeki 4y ago> Telegram holds the keys to decrypt the messages and that's all you need to know. That's an entirely different problem than TFA (an attacker accessing and being able to impersonate an account by subverting a third party 2FA middleman), which Telegram guards against as as soon as you have one device enrolled the code is sent over Telegram, not SMS. > It's why you are able to just login to your Telegram account on another device and magically get all of your message history. Being able to log in and get your history to sync is not a telltale sign that history is not encrypted and thus visible server side. It could be stored encrypted and upon login decrypted locally (how to achieve that is left as an exercise to the reader, see 1password, restic, borg, and many others that store with zero trust yet are accessible by multiple devices, or even multiple parties) (side note: claims that multi-device messaging can't be done because E2E are incorrect, e.g iMessage does it, by having each message encrypted multiple times, once for each device of the recipient account) > So while the tech might be solid, the keys are still out there. They can be leaked. They can be subpoenaed IIRC it was advertised that Telegram keys (presumably for data at rest) are stored split upon two (or more) different servers residing in different jurisdictions so that subpoenas would only get at most half of it or require international cooperation. But then if you enter that ground, Telegram just as much as Signal could be court-pressured to produce a client that wiretaps data right where it's decrypted and phone home, so E2E only saves you if you audit every client version that this does not happen. As always in matters of security, first step is to define your threat model, and who you want to secure against, as there's no such thing as perfect security. > No analysis needed. I would definitely like to see one done by an unbiased party, because everything I can find are blanket gut-feeling statements without reference. EDIT: just found this, which is a bit light but still something: https://restoreprivacy.com/secure-encrypted-messaging-apps/telegram/ https://restoreprivacy.com/secure-encrypted-messaging-apps/t... and this: https://arxiv.org/pdf/2012.03141v1.pdf https://arxiv.org/pdf/2012.03141v1.pdf
- orangepurple 4y agoTelegram has secret chats which are not the default