Telegram Hits 400 Million Users

Security from obscurity is a brain-fart. Telegram always has been more than a little snake-oil.

Open Whisper Systems, (Signal), is where it's at. A proven secure platform. Properly open-sourced and audited with no dodgy obscuring of the underlying encryption methodology.

Telegram pinky-swears it's all good whilst leaking metadata to all and sundry.

Incidentally, WhatsApp uses OWS for at least some of their encryption.

Proof?
 
Not many I know uses it. Maybe in your tech industries it is used a lot while popularity grows among casual users. WhatsApp is more than enough for most, with the downside it is owned by Facebook. Even if Telegram could let you virtually go to the toilet, if there are not enough users on it, it is as useful as wet toilet paper. But it is getting there. Maybe.

Sadly it’s always the non-techy older or more disconnected folk that always keep that bloody WhatsApp on your device even though it’s comparatively rubbish.

It’s actually quite amazing when people tell me they’ve never heard of it and I’m always like “How?” But it is somehow true from my own many experiences.

Would be nice if it got more traction though.
 
Nothing I've bothered with recently given it's history of blunders, (server side messages stored in plain text, signalling which let everyone know when you were messaging, etc), but a nice overview:

Telegram's claims of security are based on a magical algorithm which they will allow nobody to vet because, if it gets out, the encryption is meaningless.

Signal, on the other hand, is E2EE as default, keeps no session/meta data anywhere and provides for vanishing messages, properly destroyed.
 
Nothing I've bothered with recently given it's history of blunders, (server side messages stored in plain text, signalling which let everyone know when you were messaging, etc), but a nice overview:

Telegram's claims of security are based on a magical algorithm which they will allow nobody to vet because, if it gets out, the encryption is meaningless.

Signal, on the other hand, is E2EE as default, keeps no session/meta data anywhere and provides for vanishing messages, properly destroyed.

Telegram. Just like Facebook, Telegram doesn’t provide end-to-end encryption to its chats by default. Only special one-to-one conversations started with the button ‘New Secret Chat’ are end-to-end encrypted. This is a big problem because Telegram is very vocal about its high security features, and most users ignore that they need to take extra steps to protect themselves with end-to-end encryption. They might also believe that they are fully secure when using group chat, which they are not.

To provide security to its non-end-to-end encrypted chats, Telegram explains that messages stored on its servers are encrypted, and that the encryption keys are stored in servers situated in different places in the world. This means that a single government cannot request access via legal means, as they would only be provided one of the many keys needed to decipher the messages. This is already much better than Facebook’s total lack of barrier in case of subpoena. However, it relies on trusting Telegram’s intents, as well as considering that it cannot be pressured into giving away the keys via extra-legal means, and that no-one would succeed to attack its server and take control of them.

Additionally, you can only see Secret Chats on the device you started writing / reading them from. So if you started writing a secret chat on your desktop, you’ll only see it when connecting to Telegram on your desktop. As for your contact, they will also only see that chat on the device they started reading it from. Neither of you are notified of these limitations, which means that you might send messages to your contact assuming that they will be capable to read them since they have their phone with them, but since they had started conversing with you while on their desktop, they can’t actually see any of your messages while on the go. This also means that most users who use both the desktop and mobile app quickly revert to non-end-to-end-encrypted chats as they want continuity of conversation instead of having several chats open depending on the devices they use.

I think Telegram has managed to strike a balance. Functionality and security. Functionality in the sense that the messages are stored on the server (with encryption and around the world so no government can force them to hand over the keys) and this allows you to use Telegram on many platforms at the same time without relying on your phone as the conduit and using more resources from your phone such as data and battery like WhatsApp does. Then if you are in very "sensitive discussions", you have the option of using secret chat, which is end to end and not stored on their servers at all and only the two devices that the chat started on can decrypt it. I think this is a very good balance and leaves the choice in the hands of the customer and what is more important on a chat by chat basis.
 
I think this is a very good balance and leaves the choice in the hands of the customer and what is more important on a chat by chat basis.
As opposed to Signal which does all of that from the get-go?

Telegram's security is more pinky-swear than proven. That's one of my primary issues with the service. Always has been. Nothing they've done since has succeeded in getting me to change my mind. Quite the opposite.
 
As opposed to Signal which does all of that from the get-go?

Telegram's security is more pinky-swear than proven. That's one of my primary issues with the service. Always has been. Nothing they've done since has succeeded in getting me to change my mind. Quite the opposite.

I tried Signal. Was not mad about it. Telegram has got much more features.
 
I tried Signal. Was not mad about it. Telegram has got much more features.
When last did you give it a bash? Feature-wise there is very little to distinguish them.

The vanishing messages has proven a huge boon to us. Injected into workflow, we can now instantiate a contractor AAD account and issue them their initial password in a dead message. No risk of propagation or interception.
 
I like that you can edit sent messages.

And much bigger groups (200,000 members, I think).
 
Nee f@k. I invested a lot of time getting my friends and family to switch to Telegram. Besides, Telegram has self destruct also and "delete for all" etc etc. I am very happy with it and so are my friends and family.
Sounds exactly like the WhatsApp people
 
Sounds exactly like the WhatsApp people

True .... but this is like a war tactic. You dont fight a battle halway through and then just as you are 1/3 away from winning decide to attack with a new strategy. I have my battle plan and god dammit....I will stick to it until Telegram is on every smart phone in this land!!!!!

:ROFL:
 
Nothing I've bothered with recently given it's history of blunders, (server side messages stored in plain text, signalling which let everyone know when you were messaging, etc), but a nice overview:

Telegram's claims of security are based on a magical algorithm which they will allow nobody to vet because, if it gets out, the encryption is meaningless.

Signal, on the other hand, is E2EE as default, keeps no session/meta data anywhere and provides for vanishing messages, properly destroyed.

Well done linking to an ancient article that doesn’t support your claims.

You stated they leak your metadata...yet the article couldn’t even determine what metadata that is....so surely if it was leaked it would be openly available
Not so?

Signal also sucks. So there is that. Security is pointless if it’s not usable.

Last I checked it doesn’t have the platform support or many of Telegram’s features.

If anything it was like WhatsApp Lite.

By that logic let’s plug out the internet because that would be the most secure.

Also, this is the opinion of one party. Do you always based decisions on the opinion of single parties?
 
Last edited:
As opposed to Signal which does all of that from the get-go?

Telegram's security is more pinky-swear than proven. That's one of my primary issues with the service. Always has been. Nothing they've done since has succeeded in getting me to change my mind. Quite the opposite.

It’s proven by not having been broken. Surely that is more than enough evidence that it works.

On the other hand it’s quite easy to see how WhatsApp has leaked and failed on many fronts.

Telegram’s secret chat function is also quite genius. Signal’s option to turn this on and off for the whole conversation/person just doesn’t offer the same functional value.

Also nobody uses Signal. Like nobody.
 
Last edited:
I like that you can edit sent messages.

And much bigger groups (200,000 members, I think).

Yeah I wish the rest would catch on with that.

Only Slack and Telegram do it last I checked and Slack doesn’t really fit in this class of app.
 
It’s proven by not having been broken. Surely that is more than enough evidence that it works.
Sure. It's the same claim to security as Apple's . Once that began to tumble....

I don't disagree it hasn't been proven fallible - I just don't trust the obfuscation underpinning the entire security stack which has been cobbled together around it.
 
Sure. It's the same claim to security as Apple's . Once that began to tumble....

I don't disagree it hasn't been proven fallible - I just don't trust the obfuscation underpinning the entire security stack which has been cobbled together around it.

Began?

Things do change with time, it’s a little unfair to live in the past and forever hold it against people and companies.

If anything the ones that dynamically adapt as required should be commended.

Anyway, I’ll give Signal an active bash again. I’ve always had it installed but nobody has ever cared to use it long enough to notice any major feature updates.
 
Well done linking to an ancient article that doesn’t support your claims.
Please don't make me work through this crud again... shiat like this:

Fact is, Telegram is just not all that secure by default and continues to be hit-and-miss because of its roots. Be it the cruddy client or it's blend of user-friendly trade-offs which absolutely require less security....

Signal remains, by far, the most secure option out there. Telegram's security remains firmly based in the security-from-obscurity model. Something which has proven, time and again, to be as secure as a rotting banana, regardless of how clever it is.
 
Top
Sign up to the MyBroadband newsletter
X