4 ms·
The fact that we're having this discussion at all is because Telegram is not end to end encrypted by default (and groups chats are never E2E encrypted). I trie
by 4ad 2y ago
The fact that we're having this discussion at all is because Telegram is not end to end encrypted by default (and groups chats are never E2E encrypted).
I tried to explain this fact to a lot of my friends but I always received of pushback, "it can't be true", "of course it's encrypted, it says on the web page it's secure!", etc. I cannot think of any other occasion where the reality of a situation is the exact opposite of what people think.
How did Telegram achieve perpetuating this lie? And more importantly, how do we stop it? What is a good resource to provide to people who think this is true? I usually send them an article written by Matthew Green[1], but it has always been dismissed as just "some dude's blog".
A lot of people are technical just enough to become dangerous. When I explained the problem to a lot of my friends they ran wireshark on the network connection and they saw gibberish. From this they have erroneously concluded they are safe...
[1] https://blog.cryptographyengineering.com/2024/08/25/telegram-is-not-really-an-encrypted-messaging-app/ https://blog.cryptographyengineering.com/2024/08/25/telegram...
- jazzyjackson 2y agoI'm impressed someone knows to use wireshark without knowing what HTTPS is (specifically, a connection the server decrypts). But yeah, similar experience around telegram, I guess somehow it's bucketed as a competitor to Signal and people just expect feature parity ?
- rsynnott 2y ago> How did Telegram achieve perpetuating this lie? They never actually lied about it as such. They just used terms around security a lot in their marketing, and people assumed.
- Analemma_ 2y ago> How did Telegram achieve perpetuating this lie? Marketing. Specifically, very aggressive marketing that used a combination of "you can't trust them, we're the only ones keeping you safe" messaging re: WhatsApp and exaggerating+exploiting complaints about Signal and Moxie Marlinspike, to get support from earnest-but-uninformed tech types who went on to evangelize it to others, thinking they were doing a good thing for the world (like the early days of Firefox). It was a very cynical campaign and depressing how well it worked, even after their hand-rolled crypto was broken like a day after the initial fanfare-filled release.
- wrs 2y agoAs we know, there’s no such thing as an expert, everyone is equally ignorant or knowledgeable about everything, and there’s no reason to trust anyone’s opinion over anyone else’s opinion, especially if they disagree with your preconceptions or their opinion is inconvenient to you. They “did their research” themselves with Wireshark.
- zzyzxd 2y ago> A lot of people are technical just enough to become dangerous. When I explained the problem to a lot of my friends they ran wireshark on the network connection and they saw gibberish. From this they have erroneously concluded they are safe... To me, that doesn't sound like technical "enough". And that's not more dangerous than non-technical people trusting a website saying "we secure your data with military-grade encryption".
- graynk 2y agoFrom my anecdata I don’t know anyone who thinks group chats are E2E encrypted or even “safe” in general. In my circles it’s sorta common knowledge even among non-technical people that secret chats are the safest ones. That said - nobody seems to care either way just because it’s too damn convenient (for now - Telegram has been actively enshittifying for years now)