4 ms·
As far as I understand, not encrypted by default, and not very secure even when encrypted: http://www.alexrad.me/discourse/a-264-attack-on-telegram-and-why-a-s
by hurin 11y ago
As far as I understand, not encrypted by default, and not very secure even when encrypted:
http://www.alexrad.me/discourse/a-264-attack-on-telegram-and-why-a-super-villain-doesnt-need-it-to-read-your-telegram-chats.html http://www.alexrad.me/discourse/a-264-attack-on-telegram-and...
- dabeeeenster 11y agoNot encrypted by default? Really?
- lxgr 11y agoI think it's not end-to-end encrypted by default; for "private" chats they claim to use end-to-end encryption, but use some homebew cryptographic protocol of dubious security.
- MichaelGG 11y agoAnd, as far as I can tell, an idiotic visual key comparison only, so I've no way to call a contact and verify keys.
- lucb1e 11y agoThere are varying degrees of what "encrypted by default" means. WhatsApp used port 443 but sent plain text messages for years. Only fairly recently they switched around to actual encryption. Telegram messages have never been readable across the network and they claim that they also can't read the messages themselves. This is due to storing the encryption key in a different data center, but that begs for the question of how they deliver my phone the message if they don't have the decryption key. (Answering "incorrectly" that they can read my messages was how I didn't make it on the support team.) Then there is MTProto which everyone is buzzing about but which isn't even supported in all clients. This is the "secret chat" feature you see here and there, and it is actually encrypted end to end (and verifyably so). Clients are all open source so we can check that they are end to end encrypted -- WhatsApp or Facebook can ship you a backdoored version and you'd never be the wiser. Saying Telegram is "not encrypted by default" is like saying "https is not encrypted by default" because the server software can read the private messages you send to other people.
- hurin 11y agoYes, to clarify I assumed OP was asking about end-to-end encryption not SSL.
- darklajid 11y agoThey claim in their FAQ that messages are encrypted during transport and at rest - by default. End to end encryption isn't enabled by default though, the argument being that this way you lose some features (like a shared history on their servers..).