“Telegram is not a private messenger. There’s nothing private about it. It’s the opposite. It’s a cloud messenger where every message you’ve ever sent or received is in plain text in a database that Telegram the organization controls and has access to it”

“It’s like a Russian oligarch starting an unencrypted version of WhatsApp, a pixel for pixel clone of WhatsApp. That should be kind of a difficult brand to operate. Somehow, they’ve done a really amazing job of convincing the whole world that this is an encrypted messaging app and that the founder is some kind of Russian dissident, even though he goes there once a month, the whole team lives in Russia, and their families are there.”

" What happened in France is they just chose not to respond to the subpoena. So that’s in violation of the law. And, he gets arrested in France, right? And everyone’s like, oh, France. But I think the key point is they have the data, like they can respond to the subpoenas where as Signal, for instance, doesn’t have access to the data and couldn’t respond to that same request.  To me it’s very obvious that Russia would’ve had a much less polite version of that conversation with Pavel Durov and the telegram team before this moment"

  • Kailn@lemmy.myserv.one
    link
    fedilink
    arrow-up
    0
    ·
    6 months ago

    As much as I’d like to favor foss and federated messenger apps, telegram isn’t as much garbage as whatsapp:

    1.The client is somewhat open source and have forks like Forkgram, Materialgram and unoffical clients like Telegrand.
    2. Telegram isn’t E2EE by default but at least it doesn’t lie about it and have E2EE secret chat when nessesary, that means crucial chats stay on your device and the rest stay on their database recoverable and syncable across devices.
    (Yes, whatsapp supposedly is E2EE but we can’t know for sure, it’s closed-source.)
    3. You can use telegram as a cloud service with only 2GB per file limit, unlike whatsapp.
    (There’s even a third-party app that utilise this as a cloud gallery.)
    4. Even tho telegram has ads in large channels, telegram isn’t funded by a greedy big-corp and it doesn’t datamine you, ads are based on the channel’s topic.

    Yes, in terms of privacy, telegram isn’t the best option, Signal, Session, XMPP, Matrix, or SimpleX have better privacy features, less linkability and E2EE by default but telegram is very mainstream and got more publicity, making it the whatsapp alternative it advertises itself as-is.
    Publicity doesn’t make a better messenger app, but for what it tries to do, it’s adoptable for simple users, doubles as cloud storage and is more secure than the garbage being whatsapp.

    Immigrating users to different apps is a headache on it’s own, but if they know of telegram and it’s not privacy invasive, that’s not bad.

      • Kailn@lemmy.myserv.one
        link
        fedilink
        arrow-up
        0
        ·
        6 months ago

        Yes, but how would you know Meta doesn’t have a copy of your encryption key (ex: when you sign up) and keeps a copy of your encrypted messages somewhere?
        AFAIK your encryption key resides as whatsapp’s data folder but since whatsapp is closed-source you can’t guarantee that whatsapp gave the encryption key to Meta’s server at some point when it was created; (or it was created on their servers and sent to your device.)

        One would just assume the encryption key is made on your device and never sent to Meta and all the E2EE messages aren’t kept on Meta’s server after they are sent.

        Again, Meta is a company that is profiting on targeted advetising and selling user data, how would whatsapp be a free service without any profit?

        Also, Here’s someone who saw their whatsapp chat used for targeted ads on them in case you have doubt.

        • Etzello@midwest.social
          link
          fedilink
          arrow-up
          0
          ·
          6 months ago

          Yeah don’t get me wrong, I despise meta and their facade pretending WhatsApp is private. Your example is evidence but not proof but it does not mean I doubt you because it really doesn’t surprise me. Gmail likes to pretend it’s secure and private too because data in transit is supposedly encrypted but they can still just read absolutely everything in your inbox themselves

          • Kailn@lemmy.myserv.one
            link
            fedilink
            arrow-up
            1
            ·
            5 months ago

            Just…
            Don’t let them deceive you;

            If you must use deceitful software like Gmail, Whatsapp, Discord, office or whatever, just try your best not to leak your personal data on them, and if you can hinder the tracking, do so.

            If you can use other (preferably FOSS) software, do so, there’s plenty of solutions out there and most of them are free, and sometimes selfhost-able.

            Google, Meta, Microsoft or whatever corp can lie about security or privacy all they want, but in the end, they only fool themself thinking their monetary practices aren’t obvious and they can fool everyone, trust is a hard thing to earn and they can’t earn it with fraud.

            The product mostly show itself, and you have to go around it to know what’s it’s deal, if you prefer to not do so, you can search if any security researcher or analyst did investigate the product; For example Google claims Chrome browser is “safe” and “secure” dispute them giving so much trackable APIs for websites, and having a horrable default permissions, and don’t forget the “Manifest V3” transition just to remove ads (and trackers) blockers like uBlock Origin.
            You don’t need solid proof to know what is what.

            And then you just type " Foss Chrome Alternatives" or “Private Browsers” on a search engine like DDG where you can find many articles to help you find one (like this) and you’d be done.

            Forget about ““Others”” right now, your well-being matters the most.

  • sleepy@lazysoci.al
    link
    fedilink
    English
    arrow-up
    0
    ·
    6 months ago

    SimpleX is the most private of the big three. No phone number or account needed. Able to self host.

      • Hanrahan@slrpnk.net
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        1
        ·
        6 months ago

        A messenger app Musk touted as better than Signal some time ago

        It’s a turd of an App, it’s not even close to ready for prime time.

  • ☆ Yσɠƚԋσʂ ☆@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    6 months ago

    It’s also important to continue educating people about the fact that Signal is incredibly problematic as well, but not in the way most people think.

    The issue with Signal is that your phone number is metadata. And people who think metadata is “just” data or that cross-referencing is some kind of sci-fi nonsense, are fundamentally misunderstanding how modern surveillance works.

    By requiring phone numbers, Signal, despite its good encryption, inherently builds a social graph. The server operators, or anyone who gets that data, can see a map of who is talking to whom. The content is secure, but the connections are not.

    Being able to map out who talks to whom is incredibly valuable. A three-letter agency can take the map of connections and overlay it with all the other data they vacuum up from other sources, such as location data, purchase histories, social media activity. If you become a “person of interest” for any reason, they instantly have your entire social circle mapped out.

    Worse, the act of seeking out encrypted communication is itself a red flag. It’s a perfect filter: “Show me everyone paranoid enough to use crypto.” You’re basically raising your hand.

    So, in a twisted way, Signal being a tool for private conversations, makes it a perfect machine for mapping associations and identifying targets. The fact that Signal is operated centrally with the server located in the US, and it’s being developed by people with connections to US intelligence while being constantly pushed as the best solution for private communication should give everyone a pause.

    The kicker is that thanks to gag orders, companies are legally forbidden from telling you if the feds come knocking for this data. So even if Signal’s intentions are pure, we’d never know how the data it collects is being used. The potential for abuse is baked right into the phone-number requirement.

      • ☆ Yσɠƚԋσʂ ☆@lemmy.ml
        link
        fedilink
        arrow-up
        0
        ·
        6 months ago

        The problem is that you just have to trust them because only people who actually operate the server know what they do or do not store. Trust me bro, is not a viable security model. As a rule, you have to assume that any info an app collects, such as your phone number, can now be used in adversarial fashion against you.

        • 0_o7@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          0
          ·
          edit-2
          6 months ago

          Yeah there’s a reason they don’t allow you to use your own self hosted server.

          People just accepting what companies say is how we ended up in the current mess. But here we are again. Companies work around how people perceive things to be secure and private all the time. It’s just one small cog in the big machine.

          It’s how some NGOs are part of a intelligence and surveillance network but people only focus on the social work and it becomes immoral to criticize the good things they do as a cover.

          There’s also reluctance to release it in f-droid. They say they want to becontrol the distribution, but they have no problem with Apple and Google being the main distribution platforms. They haven’t even looked at unified push. And that just adds to the “there’s something else going on” factors.

          Signal protocol might be bullet proof but the app supplier, centralized server, and phone number requirement and the most mainstream OS aren’t. When you combine with how mainstream OS companies like Microsoft, Apple and Google work together with the feds, there’s ways that the bulletproof protocol may not be sufficient and is only a part of the bigger picture. There’s also US government spying on notification.

          They may work without them but the inconvenience will deter 99% of people. Being dependent these external factors, It just doesn’t feel as bullet proof as a whole.

          Whatsapp also uses the signal protocol, but you wouldn’t trust them because they’re under facebook, would you?

          • ☆ Yσɠƚԋσʂ ☆@lemmy.ml
            link
            fedilink
            arrow-up
            0
            ·
            6 months ago

            I also find it really weird how aggressively Signal is being pushed everywhere, and how any criticism of it gets dismissed or ridiculed. It feels a bit like a cult at this point.

            • Dessalines@lemmy.ml
              link
              fedilink
              arrow-up
              1
              ·
              6 months ago

              I’m fully convinced its just like apple’s support: they make some vagueish unprovable claims about privacy, and have a functional and shiny app. That’s enough for people to overlook all the privacy issues, and build a cult-like fanbase.

              Like if anyone walked into a privacy conference and said, “Hey everyone, I’m going to make a private messaging service. I need everyone’s phone number!”, they’d get laughed out of the room. But because their app looks nice, then people need to develop the cult-like following whenever it gets attacked, because its touching on an unresolved cognitive dissonance of this being a terrible idea.

              • ☆ Yσɠƚԋσʂ ☆@lemmy.ml
                link
                fedilink
                arrow-up
                1
                ·
                6 months ago

                Pretty much yeah, and they’ve had a really good marketing campaign too. They got a whole bunch of prominent tech influencers incessantly pushing it, and it just feels like a massive astroturf campaign to me. Like you said, if a random person pitched this idea, they’d be laughed at, but you get some people with clout to do it, and it sticks because everybody respects them and trusts them.