This is an article written by telegram’s founder and CEO Pavel Durov in 2019 on “Why whatsapp will never be secure”. Your thoughts?

85 points
*

Sure, fuck WhatsApp, but Telegram isn’t even end-to-end encrypted most of the time. Their group chats never are, and their “secret chat” encryption for non-group chats must be explicitly enabled and hardly ever is because it disables some features. And when it is encrypted, it’s with some dubious nonstandard cryptography.

It’s also pseudo open source; they do publish source code once in a while but it never corresponds to the binaries that nearly everyone actually uses.

And the audacity to talk about metadata when Telegram accounts still require a phone number today (as they did five years ago when this post was written) is just… 🤯

State-sponsored exploits against WhatsApp might be more common than against Telegram, or at least we hear about them more, but it’s not because the app is more vulnerable: it’s because governments don’t need to compromise the endpoint to read your Telegram messages: they can just add a new device to your account with an SMS and see everything.

(╯° °)╯︵ ┻━┻

Anything claiming to prioritize privacy yet asking for your phone number (Telegram, WhatsApp, Signal, …) is a farce.

permalink
report
reply

Anything claiming to prioritize privacy yet asking for your phone number (Telegram, WhatsApp, Signal, …) is a farce.

Yeah, sure. The privacy farce signal.

I’m getting tired of this stupid hardline-take.

permalink
report
parent
reply
10 points

Telegram isn’t perfect, but it is infinitely better than Whatsapp because it doesn’t belong to Facebook, and also isn’t from the United States. Also it can be used by normies without problem, unlike Matrix or Xmpp or what have you.

permalink
report
parent
reply
2 points

Brother, it has servers all over the world (including the US) where it hosts your data unencrypted. Telegram is nearly not inifinitely better than WhatsApp.

permalink
report
parent
reply
1 point

Sure, WhatsApp exposes you to US jurisdiction and Meta bullshit. At the same time, Telegram is very friendly with the Kremlin and associated intelligence services. So it basically comes down to whether you want to be spied on by Russian or US entities.

Source: Wired cover story

Wired story from a year ago about the FSB using Telegram to track down political activists.

permalink
report
parent
reply
1 point

Thats just speculation. The fact remains most of the Ukrainians (including their president) used telegram to raise their voice.

permalink
report
parent
reply
9 points

Shit, 2019 really was five years ago.

permalink
report
parent
reply
5 points

And the audacity to talk about metadata when Telegram accounts still require a phone number today (as they did five years ago when this post was written) is just… 🤯

Not only that, but I believe that they actively try to prevent VoIP numbers from being used to create accounts.

permalink
report
parent
reply
4 points

Then what is the choice?

permalink
report
parent
reply

Signal is just fine. This with the PhoneNumber is a really stupid hardliner-take.

Something can be private without being anonymous.

permalink
report
parent
reply
8 points

Read up on Xmpp or matrix as good alternatives.

permalink
report
parent
reply
4 points

Matrix not yet untill they implemented proper encryption and security stuff

SimpleX is pretty cool

permalink
report
parent
reply
2 points
*

Simplex - requires nothing, just install. But you connect with other people by sending a code outside of SimpleX. Though they’ve added a directory service for groups.

XMPP

Wire (not Wiremin), though it requires an email account, which is easily addressed with a disposable email.

Signal is very secure from what I’ve read, despite the phone number identifier.

permalink
report
parent
reply
4 points

I don’t agree with everything but that last point of yours. Requiring your phone number only means your are not anonymous. There is no need to be anonymous to communicate privately. In fact, it can be counterproductive, since your are much more vulnerable to social engineering.

permalink
report
parent
reply
3 points

And also not secure if somebody sim swapped you, and then your privacy goes into the hands of the FSB agent who sim swapped you

permalink
report
parent
reply
3 points

Signal is great. Stop being overzealous

permalink
report
parent
reply
3 points

Bravo, bravo, bravo!!

Dude, see you on the same side of the barricades when the time comes to fight the centralized army of agent Smiths 👏👏👏

permalink
report
parent
reply
56 points

What a load of hipocrisy. The dude uses unauthenticated DH for his apps “secret chats”, which a bored student with a laptop can MITM in seconds. Other chats use just TLS, meaning they get to read EVERYTHING.

Use Signal, people.

permalink
report
reply
18 points
*
Deleted by creator
permalink
report
parent
reply
5 points

which a bored student with a laptop can MITM in seconds

No, how can a bored student breach e2ee in seconds? note that no such cases have been reported by any telegram user so far.

permalink
report
parent
reply
7 points
*

Because the DH is unauthenticated, as I already said. Users can’t report it because there is no way to tell for them.

permalink
report
parent
reply
-2 points

Users can’t report it because there is no way to tell for them

Atleast the one who breached can tell? no telegram users data have been seen on dark web yet, no person/org have claimed to get any vulnerability in their system. Also if its that easy to breach why govt’s keep banning telegram for not giving them userdata? despite telegram is the biggest app where most terrorist orgs operate, hub of piracy and illegal things, you can call it “public” darkweb.

permalink
report
parent
reply
-4 points

Signal is based in the United States, enjoy having CIA and NSA reading all your messages.

permalink
report
parent
reply
38 points
*
Deleted by creator
permalink
report
reply
1 point

Telegram backend is still closed-source, btw

permalink
report
parent
reply
27 points

“Here’s what someone who has never created a private messenger thinks about Whatsapp’s privacy.”

Why would anyone care about what he has to say? 💀

permalink
report
reply
9 points

Owned by Facebook, which is a giant US company.

Of fucking course it has backdoors.

permalink
report
parent
reply
4 points

I’m confused regarding why you don’t consider telegram a private messenger.

permalink
report
parent
reply
12 points

It’s been a while since I looked into it, and things might have changed since then, but some stuff off the top of my head:

  • Messages are stored on the server, not on the device
  • end-to-end encryption not enabled by default
  • uses proprietary encryption, making security audits difficult

Apart from that it’s somewhat politically questionable, based in Dubai (I think), with dubious financial backing and Russian developers. Because it’s closed source and the encryption is proprietary, there’s no way of knowing how much info it leaks.

permalink
report
parent
reply
5 points
*

Messages are stored on the server, not on the device

Yes, pretty much necessary to provide multidevice support

end-to-end encryption not enabled by default

True that and telegram sucks big here, but I donth think e2ee can be enabled in a feasible way for multiple devices.

uses proprietary encryption, making security audits difficult

The MTProto isnt open source but its fully documented, there have been security audits on it.

dubious financial backing

No. Pavel Durov have always said since starting he paid for telegram’s servers from his pocket, in recent years telegram has started monetisation programs to cover its costs.

Russian developers

The founders were born in Russia, but they now have dual citizenship of UAE and France. If you are talking about politically questionable, even signal have been accused of having backdoors for CIA.

permalink
report
parent
reply
3 points

Never has been, no default e2ee, and those exploits that leaked a ton of users locations.

Not to mention, no messenger is verifiably private unless it is fully open source.

permalink
report
parent
reply
2 points

Telegram isn’t, so you must be very confused indeed

permalink
report
parent
reply
20 points
*

Clicking the link gives me the following warning:

The site ahead may contain harmful programs

Firefox blocked this page because it might try to trick you into installing programs that harm your browsing experience (for example, by changing your homepage or showing extra ads on sites you visit).

permalink
report
reply
4 points

weird, works for me in firefox with all privacy features enabled, can you please try this link: https://telegra.ph/Why-WhatsApp-Will-Never-Be-Secure-05-15

permalink
report
parent
reply
7 points

Your original link is blocked at DNS level on my ‘Threat intelligence’ blocklist.

And that link is blocked at DNS level by ‘Toxic’ and ‘Stop Forum Spam’ filters.

So it’s blocked before the browser can even connect for me.

permalink
report
parent
reply
4 points

I got the same warning for the original link with ff as well.

Your comment link didn’t throw up a red flag.

permalink
report
parent
reply
2 points

sorry for the inconvenience, thing is this website supports multiple domains and is banned in some countries so we have to use different domains to access it, which might give red flags.

permalink
report
parent
reply
2 points

Great, thank you!

permalink
report
parent
reply

Privacy

!privacy@lemmy.ml

Create post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

Community stats

  • 3.9K

    Monthly active users

  • 3K

    Posts

  • 78K

    Comments