Many in the crypto and privacy community mistakenly trust Telegram because it’s “end to end encrypted”, but there are huge issues including not hiding the metadata, censorship, centralization, and phone numbers.
Send this video to your friend that asks why you won’t join:
https://video.simplifiedprivacy.com/why-telegram-sucks/
nobody “trusts” telegram. but at least it s not whatsapp.
Wow, not to pick on the narrator, but this comes off like the worst small town used car dealership TV advertisement I’ve ever seen.
Here’s a real rundown I’ve put together over the years:
Pavel Durov’s argument is that there should be a high functioning UI/UX experience for “non-secure” communication, and when you need it there’s something much closer to Signal’s very secure client-to-client encryption.
Arguably Telegram secret chats are even “close enough” to cloud chats an adversary might not notice you’re doing the “super secret things” (making it harder to identify what to target).
MTProto Cloud: https://core.telegram.org/file/811140746/2/CzMyJPVnPo8.81605/c2310d6ede1a5e220f
MTProto Secret (Wrapped in MTProto Cloud): https://core.telegram.org/file/811140633/4/hHw6Zy2DPyQ.109500/cabc10049a7190694f
They also provide verified builds even on iOS (though it’s a bit of a hack, not “really” quite the same thing).
The only things that can really be said about Telegram’s secret chat crypto are that:
- It’s not “the default”
- It’s their own crypto (i.e., they broke “rule #1” and “rolled their own”)
Ultimately though, it’s been just shy of 10 years since Telegram entered the scene, and nobody has actually broken Telegram crypto in any meaningful way – AFAIK, to this day. Still, there are hypothetical holes in the crypto when scrutinized vs something like signal. So, is it as good as Signal or Threema? Eh, probably not, is it good enough for the average person that isn’t target by a nation state? I’d say probably.
I think you missed the most important part: all accounts are tied to a phone number
Except that’s not even true… https://www.livemint.com/technology/apps/telegram-brings-new-update-no-phone-number-needed-for-sign-up-more-features-11670403019183.html
And for most people, it doesn’t matter. It really doesn’t. I’m not even going to argue about that. I personally couldn’t care less about instant messaging with anonymity; anonymity and private are completely separate concerns.
The point is not that it’s private, the point is that they are not owned by Facebook, don’t collect as much data and give up to law enforcement as Whatsapp does, and it is based outside of the West and the 14 eyes. People say WhatsApp is end to end encrypted but if it is proprietary and owned by the second largest ad driven company in the world, how can you be sure?
Yep, E2E isn’t sufficient to ignore it being made by Meta, I def still trust Telegram more
Why use either of those apps that you can’t trust when Signal exists?
Cause telegram has better UX, supports logging in on my 2 phones, can send uncompressed larger files, more appearance customization, etc
I love Signal too but Telegram is also great
Fair enough, the features are nice. I just want people to know that they’re compromising on security by using Telegram. But if you don’t have any REAL reason to be paranoid, then you don’t really NEED to use Signal.
Ye that’s how i feel. I scarcely send anything that I’m truly worried about and when I do, I’ll use their Private Chats or Signal
P.s. I also love Telegram stickers tbh. Silly I know but they’re great