Telegram defaults to no encryption, does not do encrypted group chats, has a home-rolled encryption protocol which almost guarantees it's weak as nearly every home-rolled encryption system always is (if not also backdoored). Coupled with it being headquartered in Russia means it is completely untrustable.
The only reason Telegram comes out on top of Whatsapp in the document in question is because Telegram is a foreign company with little interest in cooperating with a US domestic police agency; the FBI has no leverage over Russian companies.
What that list doesn't show is what Telegram does when the FSB knocks. By all means, give your potentially embarassing message content to a hostile nation's intelligence service.
This is plain false as can be verified by anyone who can check Telegram GitHub repos or run the app in a debugging environment.
Telegram defaults to point-to-point encryption. Same as banks and gmail.
Fun fact: back in the days WhatsApp sent messages unencrypted (i.e. as plain text) over port 443(!).
> does not do encrypted group chats,
again, point-to-point encryption
> has a home-rolled encryption protocol which almost guarantees it's weak as nearly every home-rolled encryption system always is (if not also backdoored).
Earlier versions had serious problems. Newer versions are supposedly better.
Also there is a lot of difference between home-grown cryptography by a math wizard, made open source for everyone to inspect and various secret sauce variants.
HN has a long history of claiming it can be trivially broken, yet despite source code being available no one has done it? Lazyness or incompetence? Or maybe it isn't so simple?
I don't know but if you want to shut me up and make your claim to fame: do break Telegram cryptography. You'll do the world a service both by exposing it and by shutting up people like me.
Meanwhile, stop spreading lies. Telegram is not unencrypted. It is point-to-point encrypted by default.
I obviously was referring to e2ee; everything is point to point encrypted these days. e2ee is turned off by default and cannot be enabled for group chats.
I stand by my assertion that Telegram's proprietary secret encryption is nearly guaranteed to be weaker than industry-standard encryption. "Home grown is always weaker" is a well known position of almost the entire crypto community.
I further stand by my assertion that Telegram's encryption is nearly guaranteed to be backdoored, because there is literally zero reason for a startup to invest the massive engineering resources needed to successfully develop and maintain its own encryption algorithms, unless they were being paid to do so.
The NSA has a long history of backdooring private encryption technology through industry "partnerships."
Do you seriously think Putin would allow a domestic company to develop a communication tool that would allow Russians to communicate with each other in complete privacy?
> prove it or shut up.
Go read the HN commenting policy (specifically around civility) or shut up.
So you admit you weren't just spreading inaccuracies you heard from someone else but you knew you were posting disinformation.
> I further stand by my assertion that Telegram's encryption is nearly guaranteed to be backdoored, because there is literally zero reason for a startup to invest the massive engineering resources needed to successfully develop and maintain its own encryption algorithms, unless they were being paid to do so.
This is a good argument.
> Do you seriously think Putin would allow a domestic company to develop a communication tool that would allow Russians to communicate with each other in complete privacy?
Telegram is not a Russian company?
>> prove it or shut up.
> Go read the HN commenting policy (specifically around civility) or shut up.
Sorry. I was too harsh. I actually regret.
Compared to willfully spreading disinformation however it seems pretty minor though?
-----
A bit more: I know local police used to use Telegram. That worries me.
It is actually even more complicated:
If Putin reads my most personal messages I don't care.
If NSA or even worse, local police actually took their time to read my messages I'd be mad or worried.
However if FSB asked for help they would need a very good reason and I'd try to consult with local law enforcement first.
If local police however asked for help I'd go out of my way to help them.
That is a lot of speculation. If you read the encryption protocol, actual methods being used for encryption are well known. Client is open source and supports reproducible builds. If there is a backdoor, it is in front of our eyes.
> What that list doesn't show is what Telegram does when the FSB knocks. By all means, give your potentially embarassing message content to a hostile nation's intelligence service.
Telegram is in a lot of trouble in operating in Russia. It was blocked for two years. [1]
If they are so co-operative, why pass the opportunity to watch on their own people. Or did they become co-operative after unblock? It seems, that they help on some level [2], but does this threaten to other countries? Hard to say so.
Apple did stop updates for the Telegram. Google and Apple has weak history on compiling Russian requests. Maybe they complie with other countries more, but not Russian.
The only reason Telegram comes out on top of Whatsapp in the document in question is because Telegram is a foreign company with little interest in cooperating with a US domestic police agency; the FBI has no leverage over Russian companies.
What that list doesn't show is what Telegram does when the FSB knocks. By all means, give your potentially embarassing message content to a hostile nation's intelligence service.