27 ms·
Is Telegram really an encrypted messaging app?
- Marciakhan 2y ago[dead]
- kitkat_new 2y agoThe worst thing is that almost every non-techie who uses Telegram thinks Telegram in general is e2ee.
- podviaznikov 2y ago100% this. most people do not realize that all those non-secrete messages from private chats and group chats are stored in database that people at telegram has access to.
- lxgr 2y agoAmplified by journalists, and most frustratingly to me even some techies that just can't be bothered to properly examine all available facts despite their technical capabilities to examine them.
- as1mov 2y agoAnecdotal evidence, so take this with a grain of salt - I work with a bunch of people from Ukraine and almost all of them exclusively use Telegram to keep up with the news and family back home. From talking to them for a while, it's mostly because it's free, has excellent support for sync across multiple devices (including audio, video and other media), has support for proxies to circumvent any kind of blocking, public channels for news updates. Honestly it would be better if Telegram dropped the facade of having E2EE. It's generally very low on the priority list of most people anyway, as much as it would hurt anyone reading this, but that's the truth. People are not using it for secure messaging, but for a better UX and reliability. EDIT: Telegram does require a phone number to sign up.
- LudwigNagasena 2y ago> doesn't require any personal identifier Do they still not require ID when you buy a SIM card in Ukraine?
- as1mov 2y agoActually I was wrong. Just checked and Telegram does require a phone number to sign up. I haven't used it myself much, but was relaying the general reasons why regular people use it.
- theshrike79 2y agoYou need it to register, but afaik it's not shown to anyone in any way. You can just grab any prepaid SIM and use it if that's your style
- glitchc 2y agoYeah but the server can correlate it to all messages sent by you, and law enforcement can link server logs to your real identity thrpugh your telco.
- wruza 2y agoThose who need to dissociate with a number have anonymous sim cards in abundance. Costs around $2-5 a piece when ordered in bulk. That said, such high-tech operation is just a geeks fantasy about spies. When you cross the line where it becomes reality, you’re either a very big name with a sudden drug/rape history or a subject for waterboarding which is the most effective cryptoanalysis tool invented.
- glitchc 2y agoWhile this is a well-trodden stereotype, and it certainly has merit, not all crimes are Snowden-level crimes against the state. Felonies such as embezzlement, fraud and trafficking are often investigated by exposing the digital trail. Law enforcement most definitely do pull those records with a subpoena. It's often one of the first things done (pull all banking and phone records) and is often a key ingredient in a successful conviction. Yes, burner sims definitely help evade investigations, but they are harder to get nowadays, depending on jurisdiction. For instance you can't pay cash for a SIM in North America. It has to be a credit card or a bank transfer and that's a form of ID.
- sundarurfriend 2y agoNot a single person I know who uses Telegram cares about or thinks of it as e2ee. Whether "techie" or "non-techie" (whatever the definition of that is). People use it because it has a nice interface, was one of the first to have good "sticker" message support (yes, a lot of people care about that kind of stuff), and of course because of the good old network effect. It's only on HN I ever see people set up Telegram as some supposed uber-secure private app for Tor users and then demolish that strawman gleefully.
- smt88 2y agoTelegram is mostly used by people in the US for drug deals and chatting with people in Eastern Europe, so it's very common to believe it's a secure messenger.
- maqp 2y agoYou could also ask about whether they think it's private. And if they say yes, ask them what it means. Does it mean only sender and intended recipients can read the message, or is it fine if the service has someone check the content. Would they agree on the notion "it's OK my nudes I send to my SO are up for grabs for anyone who hacks Telegram's servers", or do they think should Telegram plug this gaping hole. Also, people tend to state they have nothing to hide, when they feel they have nothing to fight with. But I can't count the number of times I've seen a stranger next to me on a bus cover their chat the second I sit next to them. Me, a complete random person with no interest in their life is a threat to them.
- sam_lowry_ 2y ago>And if they say yes, ask them what it means I just did it to gather anecdotal evidence and the answer was, the founder is in jail to protect their privacy.
- maqp 2y agoSo they take theatrics over logical evaluation of the situation. Cool. Tell them Durov could have locked himself out of their data and spared himself the trip to behind bars.
- d0mine 2y agoBS. Vast majority of non-tech users do not, for a simple reason that they can't know it even if they cared, and they do not. Even tech users can't be bothered to read links to the faq on tg site. There is so much misinformation around telegram that alone made me trust it more (if a known liar tries to discredit something, it increases chances of it being good--it is about comments here on HN).
- wruza 2y agoI’d guess (not gonna test it but it feels reasonable) that “almost every non-techie” has a very vague idea of what e2ee even is, so it’s not clear where the worst part comes from. Pretty sure the best ideas they have about security are from hacker movies best case on average.
- rldjbpin 2y agonot everybody understands that "encrypted" =/= "end-to-end encrypted". the perceived secure nature of telegram has been memorialized in mainstream rap, courtesy kendrick lamar in 2017 (https://genius.com/11665524 https://genius.com/11665524).
- niutech 2y agoBecause Telegram is E2EE, but only in Secret Chats: https://telegram.org/faq#secret-chats https://telegram.org/faq#secret-chats
- nickphx 2y agoNo, it is not.
- stavros 2y agoI thought this was going to be just a big "NO." like the are we X yet? pages.
- sharpshadow 2y agoOnly the secret chat is e2e encrypted. All the other chat options are not. I think calls are also not encrypted since they appear in the normal chat history not in the e2e chat. Obviously if your phone is compromised your e2ee chat is not safe.
- jeroenhd 2y agoCalls seem tm be e2e encrypted: https://core.telegram.org/api/end-to-end/video-calls https://core.telegram.org/api/end-to-end/video-calls No idea how secure the encryption is, but calling someone on Telegram is safer than sending texts.
- lxgr 2y agoDepends on who your adversary is and how much you trust their protocol (some weird homegrown thing with clever/questionable cryptographic choices, the last time I checked) and implementation. Your texts don't generally run through Telegram's infrastructure, for example.
- aquatica 2y agoOnly 1-1 calls are encrypted, voice chats (group calls) are not
- maqp 2y agoToo bad I can't send a secure text from my Telegram desktop client. Lucky for me, there's Signal.
- tamimio 2y ago> Obviously if your phone is compromised your e2ee chat is not safe. Pretty much, a lot of people think that seeing E2EE means everything is safe, which I believe gives a false sense of security. You can have your phone compromised (especially when I know your phone number, Signal I’m looking at you) or be subject to other means of attacks, exposing everything. I would rather know that this app is not secure so I don’t share anything important, while keeping secure communication to other means.
- AnotherGoodName 2y agoIf telegrams encryption is so bad why is Pavel Durov under arrest? The arrest cites that he was not cooperating with authorities to crack down on various drug illegal activities on telegram. None of the other social networks have their ceos arrested. Is it simply that telegram is the only one without backdoors for five eyes? It seems to me the secret chat feature actually works too well?
- StrLght 2y agoI'd suggest waiting for more details from French officials, they have already said that they'll address it tomorrow. So far claims from the media sound like Durov's being prosecuted due to very little moderation on the platform, not because of E2EE. Even so, most messages sent on Telegram are plaintext, they're encrypted only in transport layer, but Telegram's servers see them in full. Secret chats (the only E2EE chats on Telegram) are hidden away from the users, hence the original link.
- kome 2y ago> Even so, most messages sent on Telegram are plaintext, they're encrypted only in transport layer, but Telegram's servers see them in full. you contradict yourself in the same sentence
- rvnx 2y agoHe means that the messages are only encrypted during transport, like with HTTPS. Your browser sends a clear message over an encrypted pipe, and the server on the other side, sees this clear message.
- ajsnigrutin 2y ago> So far claims from the media sound like Durov's being prosecuted due to very little moderation on the platform, not because of E2EE. But that's why it's good. With all the mainstream media censoring stuff, telegram was a (good for the people) exception. On the other hand, that's probably why they arrested him.
- lxgr 2y agoTelegram offers end-to-end encryption in the same way that McDonalds offers salads.
- littlestymaar 2y agoI love the comparison, stealing it.
- ben_w 2y agoVia a touchscreen? :P
- layer8 2y agoOverly chilled?
- rvnx 2y agoExpired from the day before, but with a fresh date sticker on it?
- adrianmonk 2y agoIn opposition to something French?
- tpoacher 2y agoyes. in that if you want it it's there, but nobody's forcing it on you if you just want a burger.
- maqp 2y agoOh, I must have missed this. Please tell me how to enable secret chats for groups. And my desktop chats. Also I'd like to turn on the setting for defaulting to secret chats whenever I open a new one. Oh? I can't. Sounds like it's not there if I want it, after all. Good thing they didn't force it to me though /s
- wruza 2y agoYou can’t have secret chats for groups. For desktop secret chats you may use Unigram client (although it’s hard for me to justify a potentially non-mobile secret chat). The rest is trivial and isn’t that hard unless you contact hundreds of new people a day. In that case, I’d already thought of using ahk automation or a full-blown telethon bot.
- tamimio 2y agoIt’s not encrypted by default, and even if it were encrypted, you should never trust any connected device with anything important. That being said, Telegram is hands down the best communication platform right now. It is feature-rich, with features implemented years ago that are only now being added to other platforms. It has normal chatting/video calls, groups, channels, and unlimited storage in theory, all for free. I just hope it doesn’t go downhill after what happened these last days because there’s no proper replacement that fulfills all Telegram features at once.
- mihaaly 2y agoAs far as I see there was no criticism targeted at anything else than the encryption part.
- icepat 2y agoWhat's in Telegram that you don't see in Signal? Honest question, I only use Signal rather than Telegram.
- sundarurfriend 2y agoPeople.
- jxi 2y agoSignal has probably the worst UX of any messaging app. It also used to require sharing phone numbers to add contacts, which imo is already a privacy violation. Telegram is fast, responsive, gets frequent updates, has great group chat, tons of animated emojis, works flawlessly on all desktop and mobile platforms, has great support for media, bots, and a great API, allows edits and deleting messages for all users, and I really like the sync despite it not being e2e.
- tamimio 2y ago> allows edits and deleting messages for all users And it has those little features like masked text and what not, features wise, telegram is just the best. I didn’t use Signal for a long time, you can’t edit the messages there!?
- A4ET8a8uTh0 2y agoIt is weirdly fascinating that this question has to be answered on a semi-regular basis. I am not sure if it is more of an insight into humans, ephemeral nature of software or concern that something major has changed.
- lxgr 2y agoIt's an unfortunate reminder in that propaganda sometimes works very well.
- kome 2y agoOr it's just nerds who are stupid and don't understand what matters in real world security for most people. The fact that you can create a huge group and channels without sharing your phone and contacts is what made Telegram big. You couldn't do that on WhatsApp until a few months ago. And it has been on Telegram for years. Why Hong Kong protesters used Telegram and not Whatsapp? read this: https://x.com/Pinboard/status/1474096410383421452 https://x.com/Pinboard/status/1474096410383421452 The fact that Telegram is massively used in both Ukraine and Russia shows that its model cannot be ignored.
- scott_w 2y agoI think it’s helpful because, as the author says, Telegram put effort into making you think it’s secure and Signal isn’t. As someone who's not close to this, it’s handy to have regular reminders.
- ahmedbaracat 2y agoAre there any pointers for work to try to make metadata private (I.e encrypted)? I was recently very curious about this question and asked similar ones here: https://news.ycombinator.com/item?id=41267877 https://news.ycombinator.com/item?id=41267877 https://news.ycombinator.com/item?id=41270863 https://news.ycombinator.com/item?id=41270863 On a side note, I was just recommending Telegram as alternative to WhatsApp (but I did mention that we need to enable Private chats for E2E). It is definitely not an ideal UX. https://barac.at/essays/on-leaving-meta https://barac.at/essays/on-leaving-meta
- lxgr 2y ago> I was just recommending Telegram as alternative to WhatsApp If you care about privacy and security, please don't. Defaults matter, and private chats are effectively unusable for anyone using more than one device or needing group chats. And that's not even considering their strange home-baked cryptography.
- mr_mitm 2y agoWhy didn't you recommend signal?
- ahmedbaracat 2y agoI am recommending both. The problem is that Signal (which I use along with the other messaging apps) is that it is not feature rich as the other 2 and Signal is not popular so ppl download it just to interact with one person (Me) whereas Telegram has more user base.
- on_the_train 2y agoSignal lost all credibility with their cryptobro bullshit
- tptacek 2y agoOnly among people who pay attention to cryptobro bullshit. They remain the gold standard among cryptography engineers.
- cheptsov 2y agoThe author claims that everyone refers to Telegram as an encrypted messenger, but he only provides a single example to support that. I quickly checked Google News and couldn't find any media on the first page that did the same. It feels like a manipulation. UPDATE: anyone who downvote, I invite to check for themselves. Just a few known media: 1. https://www.aljazeera.com/amp/news/2024/8/25/telegram-messaging-app-ceo-pavel-durov-arrested-in-france https://www.aljazeera.com/amp/news/2024/8/25/telegram-messag... 2. https://www.washingtonpost.com/technology/2024/08/25/durov-telegram-detention-france/ https://www.washingtonpost.com/technology/2024/08/25/durov-t... 3. https://www.businessinsider.com/telegram-ceo-pavel-durov-arrested-french-airport-2024-8 https://www.businessinsider.com/telegram-ceo-pavel-durov-arr... 4. https://www.theguardian.com/media/article/2024/aug/24/telegram-app-founder-pavel-durov-arrested-at-french-airport https://www.theguardian.com/media/article/2024/aug/24/telegr... However, indeed, I‘ve seen a few media that call it encrypted. This include France24, POLITICO, and The Times.
- lxgr 2y agoSubjectively and qualitatively, roughly half of all news articles on Telegram I read contain the word "encrypted" or at least "secure" somewhere.
- Cynddl 2y agoJust today, every French newspaper and hundreds around the world. Two examples: https://www.thetimes.com/world/europe/article/pavel-durov-telegram-founder-arrested-in-france-6vk7lzj3j https://www.thetimes.com/world/europe/article/pavel-durov-te... “Chief executive of the encrypted messaging app reportedly detained at an airport near Paris over alleged failure to stop criminal activity on the platform” https://www.tf1info.fr/high-tech/telegram-qui-est-pavel-durov-le-patron-franco-russe-fondateur-de-la-messagerie-cryptee-de-russie-arrete-samedi-en-france-2316094.html https://www.tf1info.fr/high-tech/telegram-qui-est-pavel-duro... (one of the largest French newspaper) “Qui est Pavel Durov, le fondateur de la messagerie cryptée Telegram arrêté samedi en France ?”
- cheptsov 2y agoIt’s called handpicking
- 331c8c71 2y agoI am null at cryptography but thie following does not sound too bad as a default tbh. And I think it is misleading to focus solely on e2ee and not mention the distributed aspect. https://telegram.org/faq#q-do-you-process-data-requests https://telegram.org/faq#q-do-you-process-data-requests > To protect the data that is not covered by end-to-end encryption, Telegram uses a distributed infrastructure. Cloud chat data is stored in multiple data centers around the globe that are controlled by different legal entities spread across different jurisdictions. The relevant decryption keys are split into parts and are never kept in the same place as the data they protect. As a result, several court orders from different jurisdictions are required to force us to give up any data. > Thanks to this structure, we can ensure that no single government or block of like-minded countries can intrude on people's privacy and freedom of expression. > Telegram can be forced to give up data only if an issue is grave and universal enough to pass the scrutiny of several different legal systems around the world. > To this day, we have disclosed 0 bytes of user data to third parties, including governments.
- fsflover 2y ago> Telegram can be forced to give up data That's all you need to know. Matrix and Signal can't be forced in any way.
- ThePowerOfFuet 2y agoThe admins of Matrix instances sure can be forced to give up data. The metadata is not encrypted, and many rooms are not either.
- fsflover 2y agoWith Telegram, even the data can be accessed. Also: https://news.ycombinator.com/item?id=41351227 https://news.ycombinator.com/item?id=41351227
- foresto 2y agoMetadata is indeed an open issue on Matrix. I believe addressing it is on their to-do list. Many rooms are not encrypted because they are public rooms, where there would be no point in it. Encryption has been the default for quite a while now.
- rckt 2y agoThis is such an old topic. Every time something related to the Telegram happens, somebody starts a discussion about how it's not an e2e-by-default. But the reality is nobody cares. And considering this, it's ridiculous now that Durov is detained on the accusations of being responsible for all kinds of information that's being spread in non e2e-by-default messenger.
- deleted 2y ago[deleted]
- littlestymaar 2y agoHe's not in fact detained because information is being spread, he's detained for actively refusing to cooperate with law enforcement.
- dboreham 2y agoPerhaps the French authorities have some taste in UI/UX. They're going to keep him in jail until telegram is no longer painful to use.
- lxgr 2y agoThere's a long list of things I dislike about Telegram, but UI/UX is really not on it.
- formerly_proven 2y agoWell yes, but actually no.
- zisguyislow 2y ago[dead]
- dataflow 2y agoDoes anyone have any reason to believe that Telegram's E2EE doesn't have a backdoor? Because if not, then I fail to see why it matters whether the E2EE even exists in the first place.
- NayamAmarshe 2y agoPavel did mention that investigation agencies tried to lure Telegram developers to use certain open source libraries. It's no wonder why WhatsApp and other apps don't face much heat from the government, they're already with the government.
- maqp 2y agoTelegram clients are open source. Anyone can verify that the client does the end-to-end encryption correctly. Telegram has had its own history of really weird issues with its encryption protocol, like the IGE, 2^64 complexity pre-computation attacks, IND-CCA vulnerability and whatever the hell this was https://words.filippo.io/dispatches/telegram-ecdh/ https://words.filippo.io/dispatches/telegram-ecdh/ But these are not the big issues here. The issues Green's blog post highlighted were * Telegram doesn't default to end-to-end encryption. * It makes enabling end-to-end encryption unnecessarily hard * It has no end-to-end encryption for groups Those matter gazillion times more than e.g. a slightly older primitive would. End-to-end encryption matters because Telegram is not just a social media or Twitter wall. It's used for purposes that deserve privacy, and Telegram isn't providing.
- SXX 2y agoReason to believe is that all their apps are open source and have reproducible builds: https://core.telegram.org/reproducible-builds https://core.telegram.org/reproducible-builds Their custom encryption is questionable, but since it open source someone would find out by now if there was obvious backdoors.
- bryanlarsen 2y agoTry the mud puddle test: log into your account on a new device using the password recovery flow. Can you see your old messages? If the answer is yes then law enforcement can too. https://www.forbes.com/sites/anthonykosner/2012/08/05/how-secure-is-your-cloud-take-the-mud-puddle-test/ https://www.forbes.com/sites/anthonykosner/2012/08/05/how-se...
- lxgr 2y agoNote that the mud puddle test was originally described on Matt's very blog: https://blog.cryptographyengineering.com/2012/04/05/icloud-who-holds-key/ https://blog.cryptographyengineering.com/2012/04/05/icloud-w... :)
- ASalazarMX 2y agoAnd it only works because a corporation likely would want to offer this to its users as a convenient feature. If they were actively trying to hide this, they can rig the test and keep access to themselves.
- freehorse 2y agoIt is true that passing the mud puddle test does not guarantee robust end-to-end encryption (there can still be backdoors reserved for company/law enforcement). But failing it definitely guarantees that there is no robust end-to-end encryption.
- tigeroil 2y agoIndeed and this is the other thing - even if Telegram don't themselves co-operate with law enforcement, it'd be fairly easy for law enforcement to request access to the phone number from the carrier, then use it to sign into the Telegram account in question and access all of the messages.
- nucleardog 2y agoYou can set a password that’s required to authenticate a new device. Once that’s set, after the SMS code, then (assuming you don’t have access to an existing logged in device because then you are already in…), you can either reset the password via an email confirmation _or_ you can create a new account under that phone number (with no existing history, contacts, etc). If you set a password and no recovery email, there is no way for them to get access to your contacts or chat history barring getting them from Telegram themselves.
- codethief 2y agoThanks for the blog post, now I finally have a good resource I can point people to next time they claim Telegramm is secure. > I am not specifically calling out Telegram for this, since the same problem [with metadata] exists with virtually every other social media network and private messenger. Notably, Signal offers a feature called Sealed Sender[0]. While it doesn't solve the metadata problem entirely, it does at least reduce it a bit. [0]: https://signal.org/blog/sealed-sender/ https://signal.org/blog/sealed-sender/
- fsflover 2y agoWith Matrix, you can use your own (or trusted) server. Doesn't it solve the problem with the metadata? At least when two trusted servers interact.
- Aachen 2y agoThis is part of what I love about Mastodon: if you PM someone, very often you're talking between two random servers and odds are good that the admin is a friend of a friend. No dragnet statistical analysis stuff, just friends running some software that normal people can also use. Distributed systems at their best
- fsflover 2y agoI wouldn't rely on Mastodon PMs for privacy. It's just not designed for that. Use Matrix instead.
- upofadown 2y agoSealed sender doesn't really solve the metadata problem at all: * https://www.ndss-symposium.org/wp-content/uploads/ndss2021_1C-4_24180_paper.pdf https://www.ndss-symposium.org/wp-content/uploads/ndss2021_1... Generally you need something like TOR to hide who is talking to who.
- codethief 2y agoInteresting, I feared Sealed Sender might be susceptible to statistical analysis (hence my phrasing "reduce it a bit") but it's worse than I expected ("Signal could link sealed sender users in as few as 5 message"). Thanks for the link! As for TOR, that wouldn't really help much, would it, given that the described attack is at the application level of Signal. Or are you talking about not using Signal altogether?
- rhelz 2y agoFascinating. I might have missed it, but I don't think the author mentioned the possibility of steganography. Just code the encrypted text such that it resembles a normal conversation.
- waynecochran 2y agoWould you use an image for this? Is there a clever way to do this with text?
- rhelz 2y agoYou could use an image. But you could use text as well. E.g. you could agree on a code phrase to be said when some "dirty deed done dirt cheap" has been completed. Or you could encode a binary string by alternating British English spellings with American English Spellings: e.g. "color" means 0, "colour" means 1; "gray" means 0, "grey" means 1, etc etc. and then just use those alternate spellings in a normal conversation.
- maqp 2y agoThe problem with codes is you have to remember them. And then you'll need a massive lookup-table. People don't want to have chats based on limited vocabulary. This is why we have modern encryption. It converts the most beautiful poem in the world to complete noise and back with no loss of meaning. It allows sending images, books, videos -- culture, without spycraft that requires hours of learning. It's also more secure, given that humans aren't nearly as good at coming up with randomness and a computer's hardware RNG.
- waynecochran 2y agoBut then it is obvious you are using encryption. A lot can be learned just from the timing of the message and noting it is encrypted. I always thought it best to send an encrypted message every hour of every day .. most messages would be just nonsense. The one eavesdropping could not only not read the message, but they would gain no knowledge about when the "real" messages are being sent.
- tazu 2y agoAm I the only one who uses Telegram mainly for p2p e2ee audio calls? It's great for that.
- TheChaplain 2y agoI use it for friends, family and partner, videocalls and normal chat. Sure, it may not be on the same level as Signal when it comes to security but it simply is leagues above others in terms of usability, stability and bells&whistles. It's like comparing a Ford Zephyr with a Volvo EX30.
- tamimio 2y agoI agree, but I wouldn’t compare Signal to a Zephyr. Classic cars have that charm and magic. I would say Signal is more like a Honda Civic; its users are loud and annoying, and yet it’s mediocre in all categories. :)
- ziofill 2y ago> One of the biggest privacy problems in messaging is the availability of loads of meta-data — essentially data about who uses the service, who they talk to, and when they do that talking. […] the same problem exists with virtually every other social media network and private messenger. Is this true for Signal too? I thought it wasn’t.
- lxgr 2y agoAvoiding any metadata leaks without generating tons of cover traffic (to frustrate timing correlation attacks) is very hard. Signal does indeed use an architecture (at least for chats with contacts, or optionally everyone when you enable the "sealed sender" option that makes you a bit more prone to receiving spam) where Signal doesn't know who's sending a given message from a given IP address, and only which account it's destined for. But any entity in position to globally correlate traffic flows into and out of Signal's servers can just make correlations like "whenever Alice, as identified by her phone's IP, sends traffic to Signal, Bob seems to be getting a push notification from Apple or Google, and then his phone connects to Signal, so I think they're talking".
- fsflover 2y ago> But any entity in position to globally correlate traffic Also, Signal relies on AWS, which could also perform such an attack it seems.
- ziofill 2y agoHow accurate does the timing need to be? I imagine there must be many Bobs getting notifications around the same time. Also, if I use Signal behind a VPN is it still known that I’m talking to the Signal servers?
- daneel_w 2y ago> Is this true for Signal too? I thought it wasn’t. It is, because you cannot use Signal without giving them your mobile phone number, and from that point onward they (and anyone they might be sharing data with) know the who/what/when, and more. My gut feeling, notwithstanding any apologist and their weak arguments, is that the design choice is exactly about the who/what/when because it's mandatory despite being entirely unnecessary from a technical perspective.
- innagadadavida 2y agoI am amazed at the low quality comments here. Encryption really doesn’t matter as much as the trust of the app here. Any malicious app author can 100% secure encrypt everything in wire and yet leak 100% of your data to some state actor. Anything you type into the chat box is only encrypted by the app after you type and probably storing it in the clear in some local SQLite db. It gives them a whole bunch of options to mess with that plain text data. Even if the app source code is published as you don’t know if they backdoored it before they submitted to App Store.
- __MatrixMan__ 2y agoThe malicious app need not be the messaging app either. It could be your keyboard.
- SXX 2y agoTelegram basically have "trust me bro" security. Even worse than Apple. They at least have some e2ee options.
- Aachen 2y ago> malicious app author can 100% secure encrypt everything in wire and yet leak 100% of your data Um, surely you understand the difference between piping random-looking bytes uselessly to whoever and having a readable copy of all data readily available to whoever hacks the system or applies for a sysadmin role? Or are you making the assumption that people use a closed-source client and the server can push malicious code? > Even if the app source code is published as you don’t know if they backdoored it before they submitted to App Store. Doesn't work if you have third parties also working with the system or forking the code to work with it. It gets noticed. Your concept of "e2ee can be 100% leaked anyway" only works if you don't know what code you're running. You need to trust the community in general to uncover issues you've overlooked (in the code or build process) but that's not the same as not having encryption at all. You can't audit the servers but you can audit the client code.
- innagadadavida 2y ago> You need to trust the community in general to uncover issues My point is that this community could just be your friendly CIA operatives running the show with a veneer of open source. Also this “community” has no liability unlike the closed platform companies.
- medo-bear 2y agoTelegram is not Signal, it is a waaay better Discord
- SXX 2y agoI guess you meant to say Discord is worse Telegram that was created earlier. Though obviously many groups features got into telegram somewhat at the same time as Discord gain traction.
- Aachen 2y agoStill not indexable, referencable, or freely readable It's a walled-garden system which is fine for private chats between groups of friends, but Discord is increasingly being used as a place to report bugs and share information. Telegram furthermore requires signing up with a phone number which Discord did not (now, often, you need to for participating when an admin of a community aka gild aka misnomer "server" turned on that requirement) https://xkcd.com/979/ https://xkcd.com/979/ This comic will not be understood by gamers growing up today... (Except in many cases someone posted a solution or nudged DenverCoder9 in the right direction at least; with Discord, Slack, or Telegram you'd simply never find the thread in a search engine to begin with.)
- kattagarian 2y ago> Discord is increasingly being used as a place to report bugs and share information. So is telegram. I'm in numerous groups with developers of linux distros and other apps. Many developers uses telegram's channels to post updates about their works.
- kome 2y agothat gives a better explanation on why telegram is safer in real world settings than whastapp or other popular messengers: https://x.com/Pinboard/status/1474096410383421452 https://x.com/Pinboard/status/1474096410383421452
- Aachen 2y agoSeems to hang on some loading screen overlay. If it fits in a toot, care to just copy it here and save people a click?
- alerighi 2y agoIt's not e2e encrypted, so what? It's something the majority of users does not need, and that doesn't increase security that much given their downsides. Of course for Telegram is much more convenient to not have end2end encryption. Given that they store everything on their servers, it means years of chat history that probably weights Gb for each user, contrary to what WhatsApp/Signal do, of course if 10 million people send eachother the same meme it's stupid to have 10 million copies of the same images on their servers just because it is end2end encrypted. They probably have a store where they index each media with its hash and avoid to have multiple copies, that is fine. This is the reason Telegram can offer you to have all your messages, including medias that can be up to 1Gb each, stored on a cloud for free. As I user I prefer Telegram just because it's the only app that works perfectly synchronized among multiple devices (Android, Linux, macOS) with good quality native clients, without wasting space on my phone for data. By the way, end2end encryption it's not that safe as they claim. Sure, the conversation can not be intercepted, however: - you can put a backdoor on endpoints, that is compromise the user phone (something they do) - you can make a MITM attack on the server (don't know if they do that, but technically possible) - you can access the data that is backed up on other platforms (i.e. WhatsApp makes by default backups on Google Drive or Apple iCloud, trough which you can access all the conversations in clear text).
- Aachen 2y ago> By the way, end2end encryption it's not that safe as they claim. Sure, the conversation can not be intercepted, however: [...] > - you can make a MITM attack on the server (don't know if they do that, but technically possible) No it's not technically possible, by its very definition. The fundamental principle behind E2EE is that the server can be malicious or compromised all you want, but this does not impact message confidentiality or integrity.
- maqp 2y ago>It's not e2e encrypted, so what? It's something the majority of users does not need, and that doesn't increase security that much given their downsides. Privacy is a human right. Everyone needs it. And Telegram advertises itself as an encrypted messenger. For every non-expert, that means end-to-end encryption. Only me and recipient can read the message. Users expect Telegram to be more secure than WhatsApp. Telegram claims its more secure than WhatsApp, and Telegram has attacked WhatsApp over its security. WhatsApp is always end-to-end encrypted, Telegram is not. So don't go putting words into peoples mouths. >Given that they store everything on their servers, it means years of chat history that probably weights Gb for each user It could be stored there with client-side encryption, Telegram doesn't need to have access to that data. Also who says chats that are ephemeral in nature need to be forever accessible. I save what I need from Signal or Telegram. >This is the reason Telegram can offer you to have all your messages, including medias that can be up to 1Gb each, stored on a cloud for free. It's not free. It comes with the price of your human right to privacy. You should get a job at Facebook with this marketing pitch. >As I user I prefer Telegram just because it's the only app that works perfectly synchronized among multiple devices It doesn't sync secret chats at all with multiple devices, not even desktop. Signal does. >good quality native clients Your script is seven years old https://signal.org/blog/standalone-signal-desktop/ https://signal.org/blog/standalone-signal-desktop/ >You can put a backdoor on endpoints, that is compromise the user phone (something they do) Nirvana fallacy. Why is Telegram offering secret chats if all endpoints are compromised? If they're not always compromised, then it should offer end-to-end encryption for everything, always. Like Signal, Whatsapp, Wire, Threema, iMessage, Cwtch, Briar, Element, Session... >you can make a MITM attack on the server Which is why every messaging app worth its salt offers safety numbers https://support.signal.org/hc/en-us/articles/360007060632-What-is-a-safety-number-and-why-do-I-see-that-it-changed https://support.signal.org/hc/en-us/articles/360007060632-Wh... Even telegram has them, although their initial implementation of babby's first QR-code was a joke. How do you compare over the phone shades of a color matrix? https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcSUnBRBfSUV8AzPFg1vQs0rQu4KuP7Xbga9KQ&s https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcSUnBRB... >you can access the data that is backed up on other platform Oh, that would be horrible. Good thing Telegram doesn't have its data backed up in cloud, no wait, sorry, it does. ~Everything you ever do with the app is permanently stored in an ecosystem built by the Mark Zuckerberg of Russia, and his PhD in geometry bro Nikolai. Shill harder.
- Timber-6539 2y agoReads like a hit piece on Telegram from a crypto expert who couldn't be bothered to explain in more than one paragraph why the app he is calling not an encrypted app (according to how he personally thinks everyone refers to when talking about encryption) actually uses some encryption technology that he's not exactly sure of but suspects is insecure.
- cheptsov 2y agoDouble that. The entire article reads to me as handpicked and manipulative.
- SXX 2y agoTLDR: 99.95% of messages on Telegram stored as plain text on their servers and only encrypted between client and telegram server. End-to-end encryption only working for 1on1 chats, not available half of their clients and have terrible UX.
- Timber-6539 2y agoAll this is just wrong. I wonder why HN likes throwing up wrong information about Telegram as fact. Is taking up 5 mins to proof these claims that hard? > 99.95% of messages on Telegram stored as plain text on their servers and only encrypted between client and telegram server. Wrong and OP doesn't even mention plain text. The non-E2EE client-server data is stored encrypted sparsed out in various servers to different countries. https://telegram.org/privacy#3-3-1-cloud-chats https://telegram.org/privacy#3-3-1-cloud-chats > End-to-end encryption only working for 1on1 chats, not available half of their clients and have terrible UX. Wrong again. I actually recently checked this for myself their official clients on Android and Linux desktop have support for MTProto 2.0. Feel free to check if other OS don't support this feature. The only clients I know where this is not enabled are the web clients.
- SXX 2y ago> The non-E2EE client-server data is stored encrypted sparsed out in various servers to different countries. Yet all this data available to any person connecting to Telegram API endpoints. It's really doesn't matter how they distributed storage look like underneath if there is point where everything available as plain text. Also this is just "trust me bro" encryption. You cant check any of it. > Wrong again. I actually recently checked this for myself their official clients on Android and Linux desktop have support for MTProto 2.0. E2EE in telegram is burdensome to use. It's just fact for anyone who actually used it daily. Also many desktop versions only gained E2EE capabilities relatively recently.
- mfiro 2y agoIn my opinion, Telegram is more of a social network than a messenger. There are many useful channels and in many countries, it plays an important role in sharing information. If we look at it from this point of view, e2ee does not seem very important. We should also not forget that, in the time when all social media (Reddit, X, Instagram etc.) close their APIs, Telegram is one of the only networks that still has a free API.
- maqp 2y agoThat's the dangerous part. It's a messaging app that took in the function of a social media platform. It did so without robust security features like end-to-end encryption yet it advertised itself as heavily encrypted. Like Green stated in his blog post, users expect that to mean only recipient can read what you say, i.e. end-to-end encryption. Telegram would be fine if it advertised itself as a public square of the internet, like Twitter does. Instead, it lures people into false sense of security for DMs and small group chats, which is what Green's post and thus this thread is ultimately about. Free API doesn't mean anything until they fix what's broken, i.e. provide meaningful security for cases where there's reasonable expectation of it.
- est 2y ago> a social media platform. It did so without robust security features like end-to-end encryption Most social media platforms doesn't support e2ee. Some chat apps do support e2ee but also requires a god damn phone number to login (yeah so does telegram), this makes "encryption" useless because authorities just ask the teleco to hand out the login SMS code.
- tapoxi 2y agoThe author of this article makes the point that social media is its key feature, but they still advertise Telegram as an encrypted messenger. So your messages to friends will be on Telegram, they're there for the social network, and they will be unencrypted because they don't support E2EE for group chats and deliberately hide the "secret chats" function.
- fredgrott 2y agoSimple question denotes whether its encrypted..... Does cloud server store the message and key..... If answer is yes, ITS NOT FULLY ENCRYPTED! Sounds contrary right? If key and message is on server any LEO org can get it....for it to be fully encrypted cloud server should never store the keys.... So how many services claiming encryption have this flaw? All.... Why do you think Telegram has shell companies to avoid gov subpeonas? Because it knows that its encryption is faulty to real world LEO and laws as it stores the keys on the cloud which means its can be subpoenaed for those keys and messages.
- maqp 2y ago>So how many services claiming encryption have this flaw? All.... Telegram is actually one of the only apps I've seen to defend their super-duper secure storage of keys online. All lies of course. The overwhelming majority of secure messaging apps have no way to recover user data if you drop your phone in the ocean. This includes Signal, Wire, Threema, Session, Element, iMessage etc.
- jbk 2y agoThe worst is that Telegram Secret Chats are limited in functionalities, compared to the normal ones, for no reasons. Stickers set don’t work, for exemple, and that’s one of the main feature of Telegram chats.
- hippich 2y agoSomething that might be interesting in this topic - forked version [0] of telegram client made during protests in Belarus in 2020 (and appears to be actively maintained to this day). Can't vouch for it, but found it interesting. [0] https://github.com/wrwrabbit/Partisan-Telegram-Android https://github.com/wrwrabbit/Partisan-Telegram-Android
- le-mark 2y agoThat GitHub account is… interesting.
- lvl155 2y agoI remember having this same conversation on here nearly a decade ago. I stopped using Telegram then.
- n95 2y ago[flagged]
- ementally 2y ago>One of the biggest privacy problems in messaging is the availability of loads of meta-data — essentially data about who uses the service, who they talk to, and when they do that talking. >I am not specifically calling out Telegram for this, since the same problem exists with virtually every other social media network and private messenger. In fact, https://simplex.chat/ https://simplex.chat/ is the only messenger with the least amount of metadata.
- maqp 2y agoThis snake oil is spreading like [Herpes] Simplex . Again, the company lies about queues (a programming technique) being a privacy feature. The application can not get rid of the metadata of server knowing which IPs are conversing, unless the clients explicitly connect to the service via Tor. The server must always know from which connection to which connection it routes packets. It's not a network hub, it's a switch, after all. https://cwtch.im/ https://cwtch.im/ and https://briarproject.org/ https://briarproject.org/ route everything through Tor always, and they don't have server in the middle, which means there is no centralized authority to collect metadata. It's light years ahead of what Simplex pretends to offer.
- SXX 2y agoThis is actually great blogpost since too many people tend to believe that Telegram is somehow more secure and private then alternatives on market. Also it's not like Telegram dont have censorship. During last 3-4 years there was many cases where Durov blocked bots and channels that belong to protests and opposition in Russia, marked them as "fake" or just plain removed with no trace. So it's just another case where some rich guy try to sell his own platform as some "freedom of speech" one even though it's just censored to his liking.
- whatgoodisaroad 2y agoat the end of the day, if you run it on an iPhone, it's iOS that renders the text, and apple is routinely subpoenaed
- kopirgan 2y agoThis article discusses a well known point about telegram. But only to techies. Vast majority of users are misled by journalists many of whom have degrees in social "science", political "science" etc. It doesn't say you need encryption that's for each person to decide perhaps for each conversation. It's need to be an educated choice. Though it's old hat better to recycle this often so many know.
- bandrami 2y agoSame thing with proton mail. I have never understood the "Trust me bro we encrypt it" business model. If it's not your key on your client machine it's not encrypted.
- protonmail 2y agoNote that Proton Mail servers don't hold your private master key directly — it is always stored encrypted with your password. Also, Proton Mail allows you to import your keys: https://proton.me/support/pgp-key-management https://proton.me/support/pgp-key-management
- bandrami 2y agoThey say
- fsndz 2y agonot being a criminal is really good, I don't have to worry about any of these stuff
- jusepal 2y agoPrime example of Betteridge's law of headlines.
- deleted 2y ago[deleted]
- WhereIsTheTruth 2y agoyou don't use telegram for encryption you use it because you can use disposable phone number nobody ever cares about encryption, it's a false flag people care about no footprints that's exactly why it was used to create civil unrest in Iran https://www.wsj.com/articles/iranians-turn-to-telegram-app-amid-protests-1514919114 https://www.wsj.com/articles/iranians-turn-to-telegram-app-a...
- kgeist 2y agoFor me Telegram is more like an uncensored Twitter slash blog platform. I use it to check out public channels for updates and that's about it. For private communication, I use Whatsapp. So, lack of e2e by default is not an issue for me at all.
- Andrew_nenakhov 2y agoOf course not. The genius of Durov was in discovering that users don't really need e2ee and all the drawbacks that come with it, and that promising them that the app has really strong encryption is good enough even without actual encryption.
- theshrike79 2y agoI don't know why people get hung up on Telegram's encryption. Maybe they're trying to make it be something it isn't. Is Discord end to end encrypted, is IRC? Nope, does it make them useless? Again no. Same with Telegram, it's a chat tool where you can select your audience and have a good UX with native bot support. (like Discord and IRC). That's what I want, nothing more. If I want to plan a coup, I'd use something else of course.
- p4bl0 2y agoIt's because Telegram is marketing itself as a secure messaging app, and because journalists continuously present it as such while discussing the arrest of its CEO.
- guappa 2y agoI've only heard telegram presented as a messenger for criminals in western media.
- toofy 2y agobecause on their front page in giant font they call themselves private and secure and outright say “heavily encrypted”. it’s their own fault. a better question might be: why do they keep over and over crying when people call them out for endangering their users? it’s super odd.
- knallfrosch 2y ago> Is Telegram really an encrypted messaging app? If is is encrypted, then it aids terrorists and can be banned. So it is encrypted, whatever the technological details. It's a political decision.
- justmarc 2y agoOne of the biggest, more significant as well as successful Internet-scale cons of the last decades that I can think of, apparently perfectly executed too.
- Canada 2y agoLet's stop repeating this word "moderate" when what we're talking about is censorship. Moderation is what happens here on HN: Admins have some policies to keep the conversation on track, users voluntarily submit to them. Censorship is when a third party uses coercion to force admins to submit to them and remove posts against their will. Durov has been arrested for refusing to implement censorship, not for anything concerning moderation.
- VMG 2y agois removal of CSAM moderation or censorship?
- Canada 2y agoIt depends on whether the parties to the communication want that or not. So let's say a few child molesters create a chat service and use it to send the worst, most horrible child pornography amongst themselves. Removing it is censorship, not moderation. Look, I'm not trying argue for legalization of child pornography here. That is illegal contraband, full stop. The intent of my comment is to say "let's just call it what it is" I think the overwhelming consensus is that child pornography is so horrible that mere possession of it must be CENSORED. I'm not arguing that censorship is always wrong. For instance, I don't want to see public billboards of graphic sex or violence. I think it's good that we censor that, so that we aren't forced to look at things like that when we don't want to. What is bothering me is that proponents of censorship, and especially certain proponents of it who want to use it as a tool to suppress ideas they don't like, have recently started using the word "moderation" in order to sneak their plans into policy without raising objections. The reason is because when we hear the word "censorship" we immediately think, "Whoa, hold on there, censorship is very harsh, let's take a hard look and make sure this is serious enough that resorting to censorship is justified and appropriate", whereas when we hear the word "moderation" we think, "Of course, we all appreciate someone deleting the spam and trolls who annoy us", and we're less likely to think critically about exactly what kind of expression is being legally prohibited.
- K7J6H5G4 2y agoThe only difference between "moderation" and "censorship" is whether you like the policy or not.
- deleted 2y ago[deleted]
- warrenm 2y ago>Does Telegram have encryption or doesn’t it? >Many systems use encryption in some way or another. However, when we talk about encryption in the context of modern private messaging services, the word typically has a very specific meaning: it refers to the use of default end-to-end encryption to protect users’ message content. When used in an industry-standard way, this feature ensures that every message will be encrypted using encryption keys that are only known to the communicating parties, and not to the service provider. >From your perspective as a user, an “encrypted messenger” ensures that each time you start a conversation, your messages will only be readable by the folks you intend to speak with. If the operator of a messaging service tries to view the content of your messages, all they’ll see is useless encrypted junk. That same guarantee holds for anyone who might hack into the provider’s servers, and also, for better or for worse, to law enforcement agencies that serve providers with a subpoena. >Telegram clearly fails to meet this stronger definition for a simple reason: it does not end-to-end encrypt conversations by default. If you want to use end-to-end encryption in Telegram, you must manually activate an optional end-to-end encryption feature called “Secret Chats” for every single private conversation you want to have. The feature is explicitly not turned on for the vast majority of conversations, and is only available for one-on-one conversations, and never for group chats with more than two people in them.