Google’s answer to WhatsApp

Do you even understand the difference?

Default settings - The transport is encrypted between you and the server and the server the the recipient. So it's not encrypted and probably stored unencrypted at server level or at some point.

Secret chats (not enabled by default) - The transport and message is encrypted from you through the server to the recipient using some dodgy , home-baked, proprietary method which is unknown and not peer reviewed.

Now ask yourself this - Why not enable this by default and why not use a more industry accepted encryption method? Duh.

Yeah, obviously I do. If you are paranoid about Telegram intercepting your messages during the brief moment that messages are decrypted and re-encrypted on their servers, then you can just use secret chats instead of normal chats. At least Telegram gives you the freedom to choose.

The reason E2E chats are not the default is because E2E sucks. A cloud-based platform is so much more convenient. The untethered standalone desktop app for Telegram is my favourite aspect of the service. And Telegram can run untethered on tablets that don't have a sim card.
 
Don't trust either

https://gizmodo.com/why-you-should-stop-using-telegram-right-now-1782557415

What makes you think that Telegram is not just a Soviet spy machine? Their not for profit status?
I love how this one keeps getting posted, when it makes assumptions rather than facts.

By the way, what happens if the client is insecure in E2E encryption? The encryption was never broken, so no worries...
You need to think things through a bit.

Your shock horror link in the Telegram desktop app is the same as with emails, don't click the stuff you don't trust. You can probably do the same in WhatsApp if download file, pretty sure their web.whatsapp.com portal would also be "vulnerable".
(and while writing this I followed one of the links in the article: https://www.theregister.co.uk/2017/03/15/booby_trapped_photo_whatsapp_telegram_risk/

"This new vulnerability put hundreds of millions of WhatsApp Web and Telegram Web users at risk of complete account take over," says Oded Vanunu, head of product vulnerability research at Check Point. "By simply sending an innocent looking photo, an attacker could gain control over the account, access message history, all photos that were ever shared, and send messages on behalf of the user."
https://www.theregister.co.uk/2017/03/15/booby_trapped_photo_whatsapp_telegram_risk/

Which is again sensationalism, as the risk is this as mentioned:
Since messages were encrypted on the side of the sender, WhatsApp and Telegram were blind to the content, thus unable to prevent malicious content from being sent. After fixing this vulnerability, content will now validated before the encryption, so that malicious files can be blocked.
Rather than a flaw of either Telegram or WhatsApp.


Yeah, obviously I do. If you are paranoid about Telegram intercepting your messages during the brief moment that messages are decrypted and re-encrypted on their servers, then you can just use secret chats instead of normal chats. At least Telegram gives you the freedom to choose.

The reason E2E chats are not the default is because E2E sucks. A cloud-based platform is so much more convenient. The untethered standalone desktop app for Telegram is my favourite aspect of the service. And Telegram can run untethered on tablets that don't have a sim card.

Exactly, I take the ease of not having my phone constantly being connected and waiting for it to reconnect to use web.whatsapp over E2E encryption for 99% of my conversations. The tools required to spy on me via Telegram's stuff will definitely not be worth the data, and I "trust" Telegram over Facebook, since FB has had multiple cases of actual data breaches/stupidity.
 
Yeah, obviously I do. If you are paranoid about Telegram intercepting your messages during the brief moment that messages are decrypted and re-encrypted on their servers, then you can just use secret chats instead of normal chats. At least Telegram gives you the freedom to choose.

That's quite a circular argument. The whole point of encryption is to avoid the paranoia and ensure privacy. If there was no paranoia about privacy then why would encryption be required? Why do you need to have choice between privacy or not to have privacy?

The reason E2E chats are not the default is because E2E sucks. A cloud-based platform is so much more convenient. The untethered standalone desktop app for Telegram is my favourite aspect of the service. And Telegram can run untethered on tablets that don't have a sim card.

End to end encryption is the ideal for privacy as long as it's implemented correctly. I'm not sure what a cloud-based platform has to do with it? As far as the untethered preference each to their own. My own preference is to keep mobile messaging separate from desktop.
 
That's quite a circular argument. The whole point of encryption is to avoid the paranoia and ensure privacy. If there was no paranoia about privacy then why would encryption be required? Why do you need to have choice between privacy or not to have privacy?



End to end encryption is the ideal for privacy as long as it's implemented correctly. I'm not sure what a cloud-based platform has to do with it? As far as the untethered preference each to their own. My own preference is to keep mobile messaging separate from desktop.

I'm not sure why you're getting caught up here. The whole point is that WhatsApp is not secure. If you didn't read the article I linked you to then this conversation never had much chance of going anywhere.

The most secure messaging platforms have neither the userbase nor user experience to balance the security. Telegram is the best middle-of-the-road option I'm aware of. It has over 200 million users, a familiar user interface that WhatsApp users will be at home with, a very long list of fantastically useful features and a much more trustworthy point of origin than most messengers. Certainly much more than Facebook, which clearly has no regard for user privacy and wants to incorporate advertising.

Most people just want the best user experience. Telegram provides a substantially better experience than WhatsApp. That it is also likely much more secure and comes from a non-profit organisation are the cherries on top.
 
Good old Google and their throw shyt at the wall and see what sticks approach to product development.
 
I'm not sure why you're getting caught up here. The whole point is that WhatsApp is not secure. If you didn't read the article I linked you to then this conversation never had much chance of going anywhere.

The most secure messaging platforms have neither the userbase nor user experience to balance the security. Telegram is the best middle-of-the-road option I'm aware of. It has over 200 million users, a familiar user interface that WhatsApp users will be at home with, a very long list of fantastically useful features and a much more trustworthy point of origin than most messengers. Certainly much more than Facebook, which clearly has no regard for user privacy and wants to incorporate advertising.

Most people just want the best user experience. Telegram provides a substantially better experience than WhatsApp. That it is also likely much more secure and comes from a non-profit organisation are the cherries on top.

My point is to demonstrate that no solution is perfect and thus responding with fandom-based arguments blindly advocating for one solution over another is problematic. Also, its apparently lost on you that a non-profit company with $1.7 billion in funding over 2 rounds doesn't need to generate revenue in order for that investment to be recouped.
 
:unsure:

looks like Telegramvangelists are a step above even hard core religionists.
 
Another failure like G+. Just give it up and stop wasting our time.

This is more of a response to Apples iMessage. Unless it is cross platform it won’t take off.
As I’ve said before until providers world wide include it in its data bundles as they do with free WhatsApp and available on entry level devices WhatsApp will remain king.

Google have a very bad track record with messaging apps and chop and change every few years. Never mind trusting Google with your privacy this is going to be a big effort to get momentum.
You trust Facebook with your privacy?

https://www.theregister.co.uk/2018/02/13/telegram_messaging_app_bug

Telegram has fixed a security flaw in its desktop app that hackers spent several months exploiting to install remote-control malware and cryptocurrency miners on vulnerable Windows PCs.

The programming cockup was spotted by researchers at Kaspersky in October. It is believed miscreants have been leveraging the bug since at least March. The vulnerability stems from how its online chat app handles Unicode characters for languages that are read right-to-left, such as Hebrew and Arabic.


A JavaScript file could be sent as a message attachment to a victim, with the filename crafted to exploit the Unicode bug and cover up the fact it's a .js document. This tricks the mark into opening what appears to be a safe .png attachment. Windows asks the victim if they are sure they want to open the JavaScript file: if they select "Run," or configure their PC to not bother asking, then the script is executed, and malware is downloaded and run.
One more reason to show extensions. Why is windows still with the default of not showing such a huge security risk that's responsible for almost all instance of malware? And why would anybody click 'run' for image files that open in their default apps? As long as people are stupid and trust dodgy companies like MS nothing will protect them.

Do you even understand the difference?

Default settings - The transport is encrypted between you and the server and the server the the recipient. So it's not encrypted and probably stored unencrypted at server level or at some point.

Secret chats (not enabled by default) - The transport and message is encrypted from you through the server to the recipient using some dodgy , home-baked, proprietary method which is unknown and not peer reviewed.

Now ask yourself this - Why not enable this by default and why not use a more industry accepted encryption method? Duh.
The method may be proprietary but it's not unknown. I'd bet many have reversed engineered it by now as it's not hard to do.
 
Telegram provides a substantially better experience than WhatsApp. That it is also likely much more secure and comes from a non-profit organisation are the cherries on top.
Hey, that's just like, your opinion, man.
 
More so than Google, besides the Whatsapp team are trying hard to keep it private
You think facebook with multiple security breaches and default settings that are anti-privacy is to be trusted more than google who gave complete control and built their platform from the ground up with privacy in mind? Ok then...
 
Youre looking at it in one dimension if you think users data was not breached by that flaw.
You're looking at it from a weird perspective if having the user download a file and execute it is a data breach rather than a user error.
Rolling your own is well known as a bad idea in the infosec industry.

https://resources.infosecinstitute.com/the-dangers-of-rolling-your-own-encryption/#gref
Your link doesn't say anything about Telegram being compromised though, just a critique at Telegram?
You still haven't answered how E2E encryption is worth a damn if you control both clients.
Good old Google and their throw shyt at the wall and see what sticks approach to product development.
(this is also @Swa)
Well, the RCS initiative started in 2007, before WhatsApp (2009). The problem was industry players taking so long, and now Google is forcing the adoption to move forward since it's been a very long time coming and nothing's been happening.

WhatsApp's actual competitor was Google+ in 2011, RCS is an entirely different product because it comes as a default replacing something that is already commonly used, we all already exchange phone numbers, so why bother with downloading and using WhatsApp instead. With Google+/Hangouts etc. you had to download another app, with RCS, it's already there, everyone is guaranteed to have it.

And Google's "throw stuff at the wall and see what sticks" is actually pretty good for software as you can reuse components. They can afford the cost of the R&D as nothing is isolated, every piece developed may be used somewhere else as well. Apple is the exact opposite, but you'll start to see them shift as well as they move into software as a service type products as their hardware revenue flat lines (there are only so many iPhones you can sell and Apple is a victim to its own success, no reason to upgrade from anything post iPhone 6S about (inc)).
 
Vulnerabilities are vulnerabilities. The Telegram one allowed more than just access to your Telegram data.
No, they are not. There are levels of severity for everything, there is no software in the world that is not vulnerable to something. The question is how insecure, why it is insecure, and what is done to help test for those insecurities and how quickly it is patched. Telegram's desktop client having that issue is not a Telegram issue, it's a Windows / User issue, it's just something that Telegram can help mitigate using file signature scanning (and WhatsApp had the same issue and now does the same) to see what it reports itself as is what it actually is.

The Telegram one "allowing more than just access to your data" required you to download the file from the source and run it, I'm not sure how Telegram is truly supposed to stop every issue that lies between keyboard and chair.
That link is about infosec 101. You have no idea what or how Telegram implements (or doesn't implement) encryption. They don't declare that. Trusting a company blindly is your prerogative, but don't claim their product is secure when you have no idea how or what they do with your data, whether they have full access to it or not.
Can you claim WhatsApp is secure? Can you claim any messenger is secure? My argument is not whether it's truly secure, read my last post before the one you quoted, I said that it's secure enough.
What does that have to do with the Telegram discussion? I'm certainly not claiming Whatsapp is secure by a long shot.
But you're arguing E2E encryption is what makes e.g. WhatsApp secure? What alternative do you have then that works without interfering with usability?
Signal? That suffers from the same problem as Skype used to, both have to be online at the same time (could have changed in the last two years since I used it) and I can't run the desktop app independently of my phone.
Telegram is more convenient and I find the app is nicer (but that's a subjective opinion. I can definitely say scrolling through multiple chats is substantially faster than WhatsApp, that thing is slow).
 
(this is also @Swa)
Well, the RCS initiative started in 2007, before WhatsApp (2009). The problem was industry players taking so long, and now Google is forcing the adoption to move forward since it's been a very long time coming and nothing's been happening.

WhatsApp's actual competitor was Google+ in 2011, RCS is an entirely different product because it comes as a default replacing something that is already commonly used, we all already exchange phone numbers, so why bother with downloading and using WhatsApp instead. With Google+/Hangouts etc. you had to download another app, with RCS, it's already there, everyone is guaranteed to have it.

And Google's "throw stuff at the wall and see what sticks" is actually pretty good for software as you can reuse components. They can afford the cost of the R&D as nothing is isolated, every piece developed may be used somewhere else as well. Apple is the exact opposite, but you'll start to see them shift as well as they move into software as a service type products as their hardware revenue flat lines (there are only so many iPhones you can sell and Apple is a victim to its own success, no reason to upgrade from anything post iPhone 6S about (inc)).
Look, I have no problem with that. The issue is how google uses their products. G+ a case in point. Get people over to the platform and then can features people used and that made them switch over while not developing features people asked for. Then they claim it's not worth developing when it was non-development that killed it. Google finance another case where people started relying on something and then they just can it. No use exporting your data as the format is google specific.

How many messaging apps have google had now? None of them gaining adoption because they can't stick to one at a time so you can't blame people for being skeptical that this is just another experiment.

Vulnerabilities are vulnerabilities. The Telegram one allowed more than just access to your Telegram data. There are other flaws
https://www.forbes.com/sites/kateof...-bots-security-researchers-warn/#35c5edb815db
https://www.bleepingcomputer.com/ne...gram-reveals-awful-opsec-from-malware-author/
Still fail to see how that is a Telegram issue. That's why I have a beef with windows which for some reason you're not addressing here. When something is acting differently than it usually does the first thing you should do is be suspicious. Computing has been made so simple that every idiot can use one and it seems most people are idiots when it comes to security. And yet MS has done nothing to address this when the number one reason for security issues is user behaviour.
 
Look, I have no problem with that. The issue is how google uses their products. G+ a case in point. Get people over to the platform and then can features people used and that made them switch over while not developing features people asked for. Then they claim it's not worth developing when it was non-development that killed it. Google finance another case where people started relying on something and then they just can it. No use exporting your data as the format is google specific.
I don't use Google Finance, but:

Google launched a revamped version of their finance site on December 12, 2006, featuring a new homepage design which lets users see currency information, sector performance for the United States market and a listing of top market movers along with the relevant and important news of the day. A top movers section was also added, based on popularity determined by Google Trends. The upgrade also featured charts containing up to 40 years of data for U.S. stocks, and richer portfolio options. Another update brought real-time ticker updates for stocks to the site, as both NASDAQ and the New York Stock Exchange partnered with Google in June 2008.[2][3] Google added advertising to its finance page on November 18, 2008. However, since 2008, it has not undergone any major upgrades and the Google Finance Blog was closed in August 2012.

On September 22, 2017, Google confirmed that the website was under renovation and that portfolio features would not be available after mid-November 2017.[4][5]

In early 2018, a notice on the website announced that the website had been renovated. The notice said that that the portfolio feature was to be removed, and advised that stocks from the old portfolio feature would be migrated to the new website, and also giving the option for users to download the portfolio as a CSV file.[6]
E.g. Stockopedia supports the format of the CSV file.
Google couldn't compete against alternatives, so they closed it. I understand the frustration though.
How many messaging apps have google had now? None of them gaining adoption because they can't stick to one at a time so you can't blame people for being skeptical that this is just another experiment.
Well a vast majority are just rebranding the same thing over and over until it sticks properly, Hangouts is a good example, with it also having a "splinter" of Google Hangouts Chat for business, which is picking up quite a bit of market share as a lot of companies already have Google Suite, so why go Slack premium if already paying and it's integrated.
 
Look, I have no problem with that. The issue is how google uses their products. G+ a case in point. Get people over to the platform and then can features people used and that made them switch over while not developing features people asked for. Then they claim it's not worth developing when it was non-development that killed it. Google finance another case where people started relying on something and then they just can it. No use exporting your data as the format is google specific.

How many messaging apps have google had now? None of them gaining adoption because they can't stick to one at a time so you can't blame people for being skeptical that this is just another experiment.
Apart from Google+ being alive and well in Gsuite it's pointless to add features to something only diehard Google fans used. All the great features got spun off anyway like Google Photos and Youtube live (Hangouts on air).

Google Finance is still alive as well. I use it daily in Google Sheets...

AFAIK there were only 4 messaging apps. Gtalk they were forced to kill because MS and others integrated it into their ecosystems without allowing Google to do the same to theirs. Hangouts is still alive and well being used in businesses (Hangouts chat and meet) and coming to regular free Gmail also. Allo was the odd one out but as stated above they should've gone with the in house RCS thing sooner.
 
Top
Sign up to the MyBroadband newsletter
X