Hi :) I know that Telegram is not save and not a good messenger if you are a privacy-geek. Sadly some parts of my family still think so. I brougth up the arguments, that they are cooperating with Russia, that they or closed-source on the server-side and that e2ee is not on by default and only available for 1-on-1 chats.

My question now is, if you gals and guys might have some other arguments or sources I could use.

I don’t want to convince anyone to switch away from Telegram (because I am no missionary :D) I just want people to understand the risks of using Telegram.

7 points
*

How about: Signal is better? Though, they recently were caught with some unencrypted shit on the desktop client.

permalink
report
reply
7 points

Sauce? I tried searching and couldn’t find anything (at least not on the first page of results). Thanks.

permalink
report
parent
reply
7 points

Lemmy thread and link.

Basically, anyone who can read your home directory could decrypt your Signal database. That’s about typical of traditional desktop applications, but questionable for security-oriented software. Mac OS and (sometimes) Linux have more robust credential management options, and Signal signaled (yes, pun intended) its intent to adopt them.

permalink
report
parent
reply
15 points

I feel that if someone can read your home directory, signal isn’t your worst worry. However, it’s still an issue and I’m glad they’re going to move to better security.

permalink
report
parent
reply
16 points

i think they mean that signal on desktop does not encrypt their content at rest, which is acknowledged and not an issue they are intending on addressing.

But it seems to have recently changed? I’m learning thus as I wanted to find a source.

Source: https://candid.technology/signal-encryption-key-flaw-desktop-app-fixed/

permalink
report
parent
reply
4 points

The messages in the desktop client aren’t encrypted. However, someone would need access to your machine to get them

permalink
report
parent
reply
2 points

Also, if the data were encrypted, the encryption key would have been on the Computer anyway, but yes it could have been better protected.

permalink
report
parent
reply
1 point

Technically they could require a password. However, people would forget it

permalink
report
parent
reply
5 points

Caught? It was like kinda obvious. You could always locate your Signal folder where everything is downloaded and just see all pictures…

I ignored this flaw as I kept my PC Luks encrypted, but a friend on Windows might not, where everyone with physical access could read everything.

So, yeah. I also dislike the idea that its not encrypted in some sort of way.

permalink
report
parent
reply

A solid privacy conscious youtuber, The Hated One, just published a video on this exact topic. It’s very detail oriented and should be easy for anyone to follow along. Here’s the link: https://youtube.com/watch?v=A8ZXDiQLH9I

permalink
report
reply
2 points

awesome, thanks for the link, I will have a look 👍

permalink
report
parent
reply
11 points
*

Is it true that Telegram doesn’t encrypt group chats at all? Maybe that would get their attention?

My biggest criticism of Telegram (but not the only one) is that they use homebrew crypto. Of course, I don’t know if your family would understand why that’s bad.

permalink
report
reply
12 points

It’s true. I’m also really annoyed with rising telegram premium stuff. It used to be just a nifty addon, now it’s everywhere.

permalink
report
parent
reply
2 points

what exactly do you mean by “telegram premium stuff”?

permalink
report
parent
reply
4 points

Basically more perks which honestly is just more useless bloatware imo.

permalink
report
parent
reply
2 points

Gift someone premium, do this and do that with premium, now there are some ads too etc

permalink
report
parent
reply
2 points

oh yeah that is a good point (well tge encryption-part and the one with the group-chats). they will not understand why this is bad but that should be easy yo explain (i guess :D ).

permalink
report
parent
reply
3 points

Their crypto is still AES it’s just the stuff around it that’s home brewed… And even then telegram has been around 10+ years now with no known breaches via the encryption.

That argument was a lot stronger years ago.

permalink
report
parent
reply
24 points

WIRE or Signal. Granted, convincing your people to move with you is like trying to get an act of Congress in play.

permalink
report
reply
21 points

people download apps for all kinds of bullshit.
but messaging? nah…

permalink
report
parent
reply
6 points

They download apps for all kinds of bullshit because all their friends and people they follow are on there. They won’t install a messaging app if none of the people they interact with are there. It’s not specific to messaging. I was able to convince my immediate family to move to Signal just for our family group chats. It’s not much but it’s a start.

permalink
report
parent
reply
2 points

Couldn’t even get a friend to swap to whatsapp from facebook messenger. I collect messaging apps like pokemon it seems

permalink
report
parent
reply
1 point

sad but very true 🙈

permalink
report
parent
reply
3 points

Quite simple: Telegram is not end-to-end encrypted by default, that means that they can read all your chats if they want to.

Better switch to Signal.

permalink
report
reply

Privacy

!privacy@lemmy.ml

Create post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

Community stats

  • 4.7K

    Monthly active users

  • 2.9K

    Posts

  • 77K

    Comments