• melfie@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    Tried to sign up once, but it wanted my real phone number and a fake one from a temp SMS site wouldn’t work. Private messaging? Sure, Jan.

  • sunbeam60@feddit.uk
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    I’m not sure they are lying. Yes, they’re not E2E but I don’t think they claim to be by default, do they?

    I’ve got a large group of friends there, since high school. We presume everything we write is available to the Russians so we never talk work details or share secrets. It would be insane otherwise.

    We’ve tried to organise a move to Signal, but honestly its client is nowhere near as polished or feature rich as Telegram.

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      I’m not sure they are lying. Yes, they’re not E2E but I don’t think they claim to be by default, do they?

      they claim to be “encrypted”. if I just make a new chat it will not be encrypted. this is false advertising. furthermore this highly advertised feature has artificial limitations, like that desktop clients can’t use it. it also cannot he used with group chats. so much for being “encrypted”.

      • Nalivai@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        That’s just your misunderstanding of the term. The chat is encrypted, no lies about it, it’s not end-to-end encrypted. Last time I checked they were quite explicit about that.
        So far, Telegram worked exactly as it was advertised, it’s just people for some reason have weird ideas about what words mean and how stuff should work, but that’s not on them to be honest.
        Plenty to criticize Telegram for, but lack of privacy isn’t it.

        • WhyJiffie@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          That’s just your misunderstanding of the term. The chat is encrypted, no lies about it, it’s not end-to-end encrypted.

          I was pretty sure someone is going to bring this up! “It uses HTTPS so its Encrypted™, you are just too dumb to comprehend it!”

          well, yes, point me to a chat service that is not encrypted on the wire nowadays. I still think it is false advertising, because their clear intention is to make the user think their service is somehow more secure than others, while that is not the case. why would you advertise privacy and encryption, if not for arguing that you the provider cant read messages?
          Ironically the owner of telegram is repeatedly posting on his channel about how much more secure telegram is over whatsapp, which is an actual end to end encrypted messaging app (but with other problems, like questionable key handling)

          • Nalivai@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            You know, if you end-to-end encrypted, but mishandle keys, it’s actually demonstrably worse than if you client-to-server encrypted but there was no confirmed cases of anything leaked.
            Nobody is misleading you because you have deeply held ideas on what words should mean.

            • WhyJiffie@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              0
              ·
              2 months ago

              Nobody is misleading you because you have deeply held ideas on what words should mean.

              if your definition of encrypted means telegram is an encrypted messenger, than “encrypted” is literally nothing more than a meaningless buzzword, since all messaging services do some kind of encryption.

              • Nalivai@lemmy.world
                link
                fedilink
                English
                arrow-up
                0
                ·
                2 months ago

                My definition of “encrypted” means that something is encrypted. You know, using cryptography.
                Your definition of encrypted means that something is end-to-end encrypted, with only two corresponding people having keys. And we actually have a term for that, it’s end-to-end encryption.
                I understand where you’re coming from, but only one of us using this word correctly.

                • WhyJiffie@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  2 months ago

                  what do you think, are those companies committing fraud that sell water with “extra H2O”, or with “more ions”, just to put themselves in a better light?

  • AeronMelon@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    Signal (assuming you live in a country that hasn’t blacklisted them for refusing to install backdoors).

    • lepinkainen@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Signal still doesn’t support bots and is shit for bigger groups

      Good for 1-10 friends and 1on1 chats tho

        • lepinkainen@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          People criticising Telegram have no idea how big some of the channels there are. They’re stupid big. Like full ass Discord server but with one channel big.

          That needs automated moderation tools - bots as well as built in tools to manage lager groups.

          Signal doesn’t do that at all. It’s a good replacement for group texts, not communities.

          And for me personally: missing first party bot support makes it a complete non-starter.

          • Coldcell@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            I mean, fair enough on you opinions, but it sounds as if all you’re saying is this one particular messaging tool doesn’t fit your requirements?

            As I see it, (and I may be speculating and/or wrong), supporting bots might worsen some aspects of other users experience. If there necessitates a worsening of other users’ experience in order to support what you’d want to do, at what point should you just use a different app?

            There’s little reasoning for catering to a niche use like huge channels and bots, and tbh that sounds like a dreadful experience to me. Dev time is costly, feature creep is a killer, I don’t see lack of support for unwanted (to me) features as a negative.

            • lepinkainen@lemmy.world
              link
              fedilink
              English
              arrow-up
              0
              ·
              2 months ago

              Signal has bit me already. Every single *Claw supports Signal bots, which pretend to be actual people.

              Telegram has explicit first party bot support, a bot is always a bot and identified as such

  • flamingleg@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    it is not hosted in the US or a country affiliated with the US, which makes it infinitely more secure from the point of view of sovereign risk

        • Zedstrian@sopuli.xyz
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          No, but they do that to plenty of their own citizens.

          Better something from a non-authoritarian country that doesn’t also happen to be in the Five Eyes intelligence network.

    • Snot Flickerman@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      Oh, you mean the guys who were obviously such criminals they were run out of Russia and Europe and had to settle on being headquarted in Dubai?

      Oh the guys who instead of doing something thoughtful like Mullvad and having RAM only servers with no logs, they just hide all their datacenters behind shell companies to avoid complying with legal subpoenas? That’s not completely shady at all, nope.

      I mean, it’s not like Matrix or SimpleX chat or others that actually are secure (-ish, even Matrix leaks metadata!) and thoughtfully designed and open source that you can self host or don’t need servers or are incorporated in Europe (like Telegram tried to incorporate initially before settling on Dubai).

      Oh and don’t forget France had very good reasons to arrest Pavel Durov, co-creator of Telegram. He went on Tucker Carlson to defend himself, which says it all, really.

      • flamingleg@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        pavel not complying with russian or french requests gives me some confidence that if some agency subpoena’d telegram for user records, they might actually have the spine to say no

        Isn’t signal basically just a honeypot for feds these days like TOR? i didn’t know telegram was also hosted in the US, which is kinda heartbreaking but such is life in the imperial core i suppose

    • Treczoks@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      No, it does not. There is a different primary actor, but that does not exclude anything.

    • Natanael@slrpnk.net
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      They spent years lying about their encryption algorithms too acting like they’re more secure than Signal when they never were

        • atrielienz@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          Supposedly to combat spam (which makes sense) and some BS about bringing your social network.

          But let’s think about this logically. What can they do with your phone number when they don’t know who you are?

          Let’s say they receive a subpoena from a government law enforcement entity. That would have to include your phone number and even then what can they give that entity? The date you registered the number and the last time your account was active?

          At best my guess is that you and others who bring this up are worried about the information that you can buy from data brokers that would include a phone number and allow someone with the phone number to link it to a person.

          But at that point law enforcement already knows the number, already has likely used to same services to link that number to a human, and since most people haven’t de-googled or use an iPhone they likely know what apps are installed. Including signal.

          What is the threat profile that should be worried about this?

          Please note that I don’t think they should need to require a phone number and if you don’t want that you can use a different service.

          But I’d like someone to elaborate on their reasons for objecting to this.

          • FudgyMcTubbs@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            I would assume if an entity had my phone number they could easily connect it to me, like by spoofing it and calling themselves and getting the name off caller id or some shit, or even just subpoenaing the phone carrier for the id of the phone number. Why they would want to do that for little old fudgy mctubbs is beyond me.

            I’ll say it: I dont want anybody to know what I jack off to. It’s all legal stuff, but im too prudish to have that be public.

            Anonymity is impossible, but we can still attempt it.

            • atrielienz@lemmy.world
              link
              fedilink
              English
              arrow-up
              0
              ·
              2 months ago

              They don’t offer anonymity. Anonymity does not equal privacy. They aren’t the same thing. And if you’re using the signal app to jerk off I have some questions.

          • chameleon@fedia.io
            link
            fedilink
            arrow-up
            0
            ·
            2 months ago

            I ended up wanting an online pseudonymous identity as well as an offline real-life identity, which leads to needing multiple phone numbers when things are tied to said number. That’s extremely annoying to manage, especially with Signal’s current activity and update policies that essentially require you to keep a phone in a drawer, charge it and log into it every so often or risk losing your entire account due to inactivity, as only the mobile device counts for that purpose (this might supposedly be changing).

            In that particular scenario, I don’t really care if my least-favorite three-letter-agency or law enforcement can link my identities. It’s a nice bonus if they can’t, but not an absolutely required feature. The main worry is the person on the other end trivially learning it. But the person on the other end might have a different set of worries that makes Signal one of the few available options for them.

            That said, Telegram also requires a phone number and has exactly the same issue, so this is a rather weird thread to bring that up.

            • atrielienz@lemmy.world
              link
              fedilink
              English
              arrow-up
              0
              ·
              2 months ago

              Thank you for taking my questions seriously and giving your perspective.

              I suppose to some extent I do this with emails. I have an email for public and professional things and one for just hobbies and thing I enjoy.

              I think the main difference for me is I’m not trying to keep those two “identities” anonymous from each other or anything. It’s just good compartmentalization (to keep work stuff work stuff, professional stuff professional, and hobby stuff hobby stuff.

  • 1984@lemmy.today
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    I know but I trust it more than Google.

    There is value in spreading out your data to different companies in different countries. All the American big tech services sends a copy of everything to the nsa.

    Maybe telegram doesn’t. Who knows. Maybe they are being a bit more difficult at least.

    • DeckPacker@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      I think the point is not so mich whether you can trust Telegram or not (although I am shure you can’t).

      The issue with Telegram is, that (by default) it stores all your chats unencrypted on their servers. So they can just access every message of yours whenever they want. That is not only dangerous for privacy, but when their database gets hacked, there is a decent chance, that all of your chats are gonna be released. Also, if governments want access to Telegrams data, they are legally obligated to comply.

      What you should look out for, when you want more privacy is:

      1. Legit End-to-End encryption: That means, that all your messages are stored and transmitted encrypted and only you and the person, you are talking to have access to these keys. So even if the server of the messaging service, you use is malicious or the government forced the organisation, which is responsible for the messenger, it would be mathematically impossible to read any of your messages.

      2. Open Source clients, that can be verified by security experts. End to End encryption doesn’t mean much, when you can’t verify what the service, you are using is doing with your private decryption keys. In other words: It isn’t enough, if a company just says, they are doing encryption. The solution is Open Source clients, because that means, that everyone can see exactly what the apps are doing and can inspect the source code for backdoors or vulnerabilities. Usually, if a lot of people have been using them, you can be sure, that some experts have verified, that nothing fishy is going on.

      If you want a simple suggestion, that has good encryption and is fully open source, but is still easy to use, I would suggest you go with Signal.

  • wuffah@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    Every since the CEO of Telegram was basically lured to Paris, arrested, then read the riot act for Telegram’s non-cooperation with French authorities, the company has been responding to warrants and downplaying its “E2EE” features. Expect them to have a fully accessible backdoor for LE.

    By the way, don’t forget about that Bitlocker backdoor that “mysteriously” doesn’t affect Windows 10.

    The EU and US digital surveillance states have been tightening their grip on encryption and online anonymity for years now. “Age verification” is just the latest push.

    • wizardbeard@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      I can only assume there’s a different backdoor for 10 that just hasn’t been published. Even if there isn’t, Windows defaults to backing the key up to the attached Microsoft account. You think they’d ever tell intelligence agencies to come back with a warrant for that?

      Just use Veracrypt folks.

  • esc@piefed.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    It was made by m*scovites in m*scovia with fsb money, by the same guys that tried to copy facebook.