3 ms·
They claim that they store user data on different servers in different jurisdictions so it becomes more difficult for authorities to gain access [1]. Maybe that
by _ink_ 3mo ago
They claim that they store user data on different servers in different jurisdictions so it becomes more difficult for authorities to gain access [1]. Maybe that's true and it has something to do with these DCs that seem to be unused.
[1] - https://telegram.org/privacy https://telegram.org/privacy
- amima 3mo agoThey do not claim that. They do claim that they store specifically encryption keys in several data centers in different jurisdictions. Here is the exact quote: "All data is stored heavily encrypted and the encryption keys in each case are stored in several other data centers in different jurisdictions". So only keys are distributed.
- hkpack 3mo agoWhat does heavily encrypted even mean? Fully encrypted? Slightly encrypted? Encrypted enough to call it “heavily encrypted” but not enough to be protected from whoever is interested?
- Perz1val 3mo agoHeavily means the key is large so it takes longer to crack, but also longer to encrypt/decrypt, so the service is more costly to run and slower. At least I've seen it used that way
- maqp 3mo agoThere's nothing slow about AES. In this context "heavily" means "we can't legally claim it's end-to-end encrypted because it's not". Also it's not even post quantum, so it's not heavy. Telegram's Diffie-Hellman breaks instantly with a quantum computer large enough to run Shor against it. Also, the keys sit on the servers' RAM, no matter what they lie. There is no global distributed RAM system, especially one that encrypts data in distributed fashion and works at the negligible latencies that Telegram boasts.
- Perz1val 3mo agoI've never claimed that anything about telegram's encryption is "heavy", because I don't even know what they use, I just said what "heavy" usually means > In this context In this context it's marketing bs for people that only seen action movies where hackers quickly cracked encryption. I'm sure whatever telegram uses is not that ridiculously easy to crack
- Aachen 3mo agoIt's not slow though so that's clearly not it. It's just a marketing intensifier here
- dakolli 3mo agotelegram is the safest encrypted messaging app. Period, full stop.
- maqp 3mo ago>telegram is the safest encrypted messaging app. Period, full stop. Yes, let's see * Not end-to-end encrypted by default * No end-to-end encrypted groups * No end-to-end encryption on any desktop client by the vendor, forcing cross-platform users to drop secret chats. This includes 81% of working age people who sit on their computer during work day, and 100% of college students and IT workers. * No post-quantum key exchange * No future secrecy * No per-message forward secrecy * Bullshit claims about distributed keys https://security.stackexchange.com/questions/238562/how-does-telegrams-secret-splitting-scheme-work/243172#243172 https://security.stackexchange.com/questions/238562/how-does... * Lacks ALL metadata protection from server like phone number, IP-address and thus geolocation, contact list, group memberships, quantity and schedule of communication, data types. In fact -- * Secret chats leak additional metadata about intent to hide content from TG as the vendor. Also, History of poor encryption implementation * 2013: A cracking contest https://news.ycombinator.com/item?id=6932648 https://news.ycombinator.com/item?id=6932648 * 2013: Telegram, AKA "Stand back, we have Math PhDs!" http://unhandledexpression.com:8081/crypto/general/security/2013/12/17/telegram-stand-back-we-know-maths.html http://unhandledexpression.com:8081/crypto/general/security/... * 2015: IND-CCA issues https://eprint.iacr.org/2015/1177.pdf https://eprint.iacr.org/2015/1177.pdf, * 2015 64-bit complexity MITM attack https://web.archive.org/web/20160425091011/http://www.alexrad.me/discourse/a-264-attack-on-telegram-and-why-a-super-villain-doesnt-need-it-to-read-your-telegram-chats.html https://web.archive.org/web/20160425091011/http://www.alexra... * 2021 Valsorda "The Most Backdoor-Looking Bug I've Ever Seen" https://words.filippo.io/telegram-ecdh/ https://words.filippo.io/telegram-ecdh/, * 2021 https://mtpsym.github.io/ https://mtpsym.github.io/ and https://mtpsym.github.io/paper.pdf https://mtpsym.github.io/paper.pdf Some analysis: * 2025 Matthew Green analysis https://blog.cryptographyengineering.com/2024/08/25/telegram-is-not-really-an-encrypted-messaging-app/ https://blog.cryptographyengineering.com/2024/08/25/telegram... * 2025 "Telegram is indistinguishable from an FSB honeypot" https://rys.io/en/179.html https://rys.io/en/179.html Also, They employ volunteering sockpuppets https://tsf.telegram.org/ https://tsf.telegram.org/ Durov who supposedly lives in exile has visited Russia over 50 times https://eutoday.net/pavel-durovs-secret-visits-to-russia/ https://eutoday.net/pavel-durovs-secret-visits-to-russia/ I can't scream "drop & run" loud enough.
- bflesch 3mo agoIt's more about the fact that five eyes intelligence services prefer to officially spy on each other's countries so they don't have to answer to their respective bureaucrats. They prefer plausible deniability. Something like this: DC1 politically belongs to UK which "spies" on CA/US but physical servers are located in US so US ultimately retains control. DC2 politically belongs to France which "spies" on RUS/UKR/DE but physical servers are located in NL (e.g. in UK because one wouldn't be able to spot difference in ping). Maybe it's politically owned by UK/NZ or UK/AUS because France can't be publicly caught spying on Germany. But France wouldn't risk public arrest of Telegram CEO and the spectacle with russia if there is nothing to gain. DC4 politically belongs to USA which "spies" on UK/Israel but physical servers are in NL/UK DC5 politically belongs to UK/USA which "spies" on AUS/China/India but physical servers are in Singapore (e.g. former UK colony) I love mentioning the UK in these kind of discussions because the pushback is biggest every time the Crown is mentioned, and ultimately US/CA/NZ/AUS are all colonies under the King. Really cool to see realpolitik mapped out like this. It also highlights the problem of metadata with these kind of topics.
- orbital-decay 3mo agoThe reason it's in Singapore is that Telegram can't operate in China, and Singapore-washing is the closest thing to doing it. A ton of VPNs and other services targeting mainland users but not allowed in the mainland are hosted there, it's a huge hub for companies and networks.
- inigyou 3mo agoIs that because Hong Kong is falling under Chinese authority again?