3 ms·
New messages yes, but old messages no.. The typical way group chat encryption is done is the client generate a key per message, it use that key to encrypt the
by tmottabr 2y ago
New messages yes, but old messages no..
The typical way group chat encryption is done is the client generate a key per message, it use that key to encrypt the content of that single message.
Then it will encrypt the message key with personal key for each member of the group, and it can only do that for current members of the group.
Once you receive a message the client will use your personal key to decrypt the copy of the message key encrypted with it, then use the message key to decrypt the message.
The problem with this is that, first it does not escale, the larger the group gets the harder it is to encrypt the messages because you need to encrypt the message key with more and more personal keys, this make the work load bigger and the message size bigger as well. Telegram support very large groups that make encrypting groups not practical.
Also Telegram allow you to see older messages sent before you join the group as those get stored in the servers, if you join the group later then for older messages the per message key will not have being encrypted with your personal key so you cannot decrypt it, thus cannot decrypt the message.
You would need to either store the per message key unencrypted in the server and make encryption useless as the server would be able to decrypt it, have the client from some older member of the group re-encrypt the per message key for older messages and send to new members or the simpler approach that Telegram took to not encrypt it at all.
- foldr 2y agoYou're overcomplicating it. The existing members of the group have the plaintext of the older messages. So they can totally send those messages to new members of the group. If I can copy/paste the history of the group chat and send it to a new group member, then the application itself can do the equivalent behind the scenes.
- 0points 2y agoSure, but that would defeat the purpose of the encryption since anyone could join at a later date and have other clients snitch out whatever was said in the past. Might as well use Telegram at that point ^_^
- foldr 2y agoIn a public group that anyone can join without an invite it’s unclear why you’d even want E2E in the first place, so we’re presumably talking about invite-only groups. In that case, sending old messages to new members may or may not be a desired behavior, but it doesn’t defeat the purpose of E2E.