Many in the crypto and privacy community mistakenly trust Telegram because it’s “end to end encrypted”, but there are huge issues including not hiding the metadata, censorship, centralization, and phone numbers.
Send this video to your friend that asks why you won’t join: https://video.simplifiedprivacy.com/why-telegram-sucks/

  • Janis@feddit.de
    link
    fedilink
    arrow-up
    100
    arrow-down
    3
    ·
    11 months ago

    nobody “trusts” telegram. but at least it s not whatsapp.

    • ShadowRebel@monero.townOP
      link
      fedilink
      arrow-up
      1
      arrow-down
      11
      ·
      11 months ago

      We sell self-hosted XMPP services and Session usernames. We did not make Session. What’s cringe is your lack of research or knowledge

  • Dark Arc@social.packetloss.gg
    link
    fedilink
    English
    arrow-up
    27
    arrow-down
    2
    ·
    edit-2
    11 months ago

    Wow, not to pick on the narrator, but this comes off like the worst small town used car dealership TV advertisement I’ve ever seen.

    Here’s a real rundown I’ve put together over the years:

    Pavel Durov’s argument is that there should be a high functioning UI/UX experience for “non-secure” communication, and when you need it there’s something much closer to Signal’s very secure client-to-client encryption.

    Arguably Telegram secret chats are even “close enough” to cloud chats an adversary might not notice you’re doing the “super secret things” (making it harder to identify what to target).

    MTProto Cloud: https://core.telegram.org/file/811140746/2/CzMyJPVnPo8.81605/c2310d6ede1a5e220f

    MTProto Secret (Wrapped in MTProto Cloud): https://core.telegram.org/file/811140633/4/hHw6Zy2DPyQ.109500/cabc10049a7190694f

    They also provide verified builds even on iOS (though it’s a bit of a hack, not “really” quite the same thing).

    The only things that can really be said about Telegram’s secret chat crypto are that:

    1. It’s not “the default”
    2. It’s their own crypto (i.e., they broke “rule #1” and “rolled their own”)

    Ultimately though, it’s been just shy of 10 years since Telegram entered the scene, and nobody has actually broken Telegram crypto in any meaningful way – AFAIK, to this day. Still, there are hypothetical holes in the crypto when scrutinized vs something like signal. So, is it as good as Signal or Threema? Eh, probably not, is it good enough for the average person that isn’t target by a nation state? I’d say probably.

  • MagneticFusion@lemm.ee
    link
    fedilink
    arrow-up
    18
    arrow-down
    1
    ·
    11 months ago

    The point is not that it’s private, the point is that they are not owned by Facebook, don’t collect as much data and give up to law enforcement as Whatsapp does, and it is based outside of the West and the 14 eyes. People say WhatsApp is end to end encrypted but if it is proprietary and owned by the second largest ad driven company in the world, how can you be sure?

    • N-E-N@lemmy.ca
      link
      fedilink
      arrow-up
      7
      ·
      11 months ago

      Yep, E2E isn’t sufficient to ignore it being made by Meta, I def still trust Telegram more

        • N-E-N@lemmy.ca
          link
          fedilink
          arrow-up
          8
          arrow-down
          1
          ·
          11 months ago

          Cause telegram has better UX, supports logging in on my 2 phones, can send uncompressed larger files, more appearance customization, etc

          I love Signal too but Telegram is also great

          • PeachMan@lemmy.one
            link
            fedilink
            arrow-up
            3
            ·
            11 months ago

            Fair enough, the features are nice. I just want people to know that they’re compromising on security by using Telegram. But if you don’t have any REAL reason to be paranoid, then you don’t really NEED to use Signal.

            • N-E-N@lemmy.ca
              link
              fedilink
              arrow-up
              2
              arrow-down
              1
              ·
              11 months ago

              Ye that’s how i feel. I scarcely send anything that I’m truly worried about and when I do, I’ll use their Private Chats or Signal

              P.s. I also love Telegram stickers tbh. Silly I know but they’re great

    • wischi@programming.dev
      link
      fedilink
      arrow-up
      0
      arrow-down
      1
      ·
      11 months ago

      You can sure it’s end to end encrypted because the client can be analyzed to verify that claim.

  • justastranger@sh.itjust.works
    link
    fedilink
    arrow-up
    9
    ·
    11 months ago

    The only reason telegram was unbanned in Russia is because they started collecting and handing over identifiable data about Russian users.

  • Gamey@feddit.rocks
    link
    fedilink
    arrow-up
    5
    ·
    11 months ago

    I try to explain that to people all the time, they only use E2E for so called secret chats and comply with every country as soon as a ban is on the table, there are even reports about a case in Dheli where they did so for Audiobook piracy!

  • partizan@lemm.ee
    link
    fedilink
    arrow-up
    4
    ·
    11 months ago

    Thats why Element(Matrix) is the way. Ideally selfhosted+federated, but even the default matrix.org is much better than most other chat apps.

    • EngineerGaming@feddit.nl
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      11 months ago

      Why Matrix and not XMPP? XMPP is also flawed, but much less bloated, easier to selfhost and doesn’t have so many people being on central instance like matrix.org (there are other arguments as well).

      • regalia@literature.cafe
        link
        fedilink
        arrow-up
        3
        ·
        edit-2
        11 months ago

        Because there’s not a single good app for XMPP and nobody uses it.

        Their bleeding edge app is Conversations which costs money (already unviable), and the app looks like it’s designed in 2012.

        • EngineerGaming@feddit.nl
          link
          fedilink
          arrow-up
          1
          ·
          edit-2
          11 months ago

          It does NOT cost money on F-Droid. You don’t even need to install the market itself, you can get the app from F-Droid’s website (though then you’d have to check for updates yourself). For me, it was a chance to get mom to F-droid.

    • ReversalHatchery@beehaw.org
      link
      fedilink
      arrow-up
      1
      ·
      11 months ago

      It may be once sliding sync and proper key handling of room history for new members get implemented.

      Right now sync is very slow, the apps are heavy weight too (as I know at least partly because of how sync works today), and if a new member joins an encrypted room, they will not see the history even if you set it that way, because the clients that know the keys won’t send to theirs.

  • KrisND@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    11 months ago

    I like mixing it up, even mid conversation, between Threema, Signal and Session. Put the puzzle together feds xD

  • ReversalHatchery@beehaw.org
    link
    fedilink
    English
    arrow-up
    2
    ·
    11 months ago

    Who thinks in the privacy community that Telegram is end to end encrypted? They were largely mislead. That’s an option, that even prevents sync of the chat between your devices.

    The thing is, Telegram has some shady things, but until Matrix becomes usable this is one of the very few usable options. And until then, use Telegram FOSS from F-droid.

      • ReversalHatchery@beehaw.org
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        11 months ago
        • Huge resource usage by clients
        • Huge sync times (not just first time, but also if the client was offline for a few weeks)
        • New room members in encrypted rooms can’t read old messages even if you have set it up that way

        Fortunately they are working on all of these, and as I just found out recently, they also have an alpha version app now that makes use of the new efficient sync, which I expect to fix 2 of the above (the resource usage is partly because of how sync works now)

  • Microw@lemm.ee
    link
    fedilink
    arrow-up
    2
    ·
    11 months ago

    The only thing Telegram has going for itself is that it’s Non-Meta and Non-Western.

    Anyone who has a closer look at Telegram’s reputation knows that their privacy claims are dubious. If you want end to end encryption, even WhatsApp is better. But these things depend on your individual threat model.

    • N-E-N@lemmy.ca
      link
      fedilink
      arrow-up
      0
      arrow-down
      1
      ·
      11 months ago

      Telegram can be E2E, no reason to switch to Meta’s app for it

  • elouboub@kbin.social
    link
    fedilink
    arrow-up
    4
    arrow-down
    2
    ·
    11 months ago

    Why isn’t this video uploaded to peertube instead of some dude’s personal bog?