Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Telegram is absolutely the worst when it comes to privacy

Really? Telegram never said that they don't store your messages on cloud, they said that they do not sell your data or share it with third parties for profit.

Telegram has received a very good score on PrivacySpy (https://privacyspy.org), in fact better than any other messaging app. Telegram is good from a regular privacy perspective unless your threat model involves fearing cloud convenience.

Even FBI's leaked documents confirmed that Telegram does not ever share user data easily. [Source](https://www.securitynewspaper.com/2021/11/30/leaked-fbi-docu...)

If you're someone who requires spy-level opsec, you should be using Threema, Session or Speek. Maybe even a self-hosted XMPP instance.

Telegram is good at what it does and it states it very clearly. It does not lie about the things it does and it is open source. All while not selling user data, not manipulating user behavior through algorithms or censoring media by calculating hashes and providing what's arguably the most feature rich messaging app on the planet for free with a verifiable source code.

Also, be careful with what you're suggesting. Not only have Matrix servers been hacked twice but matrix also leaks metadata. If you're seriously suggesting true anonymity (not consenting privacy) then Matrix is not a good option.



> Really?

Yes, really. You don't even argue against it.

> pp. Telegram is good from a regular privacy perspective unless your threat model involves fearing cloud convenience.

Telegram stores almost everything online without E2EE.

> Not only have Matrix servers been hacked twice but matrix also leaks metadata.

Even Signal leaks meta data.

> If you're seriously suggesting true anonymity (not consenting privacy) then Matrix is not a good option.

Out of Matrix, Telegram and Signal, Matrix is the best option. It is the only one not making you share your phone number giving you anonymity up to your IP address.


> Yes, really. You don't even argue against

and yet I just did. Can we please stop confusing privacy and anonymity?

Your claims about Telegram being bad for privacy are baseless. Your concerns about messages is valid but it in no way compromises privacy because:

1. No telegram employee can read any messages. They use distributed key generation to encrypt data on servers which means no single server has access to decryption keys and all the servers are in different jurisdictions.

2. They do not sell message content data. If you can prove it, you can go ahead with a lawsuit and win a hefty sum.

3. They do not compromise security. They do not use E2EE by default. Their threat model and vision for a messaging platform is different than yours.

4. Telegram has never given message content for a court order. As mentioned in the privacy policy, they give out only the phone number and IP Address only in case of terrorism or child abuse and only when there's a court order from a country of a higher democratic index.

5. If you truly believe Telegram is bad for privacy even after all the evidence from FBI itself and PrivacySpy giving it a higher score than Signal, then please go ahead and sue them because surely they can't have a good privacy policy and bad privacy at the same time.


> 1. No telegram employee can read any messages. They use distributed key generation to encrypt data on servers which means no single server has access to decryption keys and all the servers are in different jurisdictions.

This is wrong. First, reported messages (via id) are read by employees. Second, regardless of your claims, Telegram can easily write a service which has access to plain text messages.

> 2. They do not sell message content data. If you can prove it, you can go ahead with a lawsuit and win a hefty sum.

How about you prove your claims? I hardly can bring them to justice when even the police doesn't have immediate access to them.

> 3. They do not compromise security. They do not use E2EE by default. Their threat model and vision for a messaging platform is different than yours.

Actually, they do by not using E2EE by default and providing bad encryption possiblities.

> 4. Telegram has never given message content for a court order. As mentioned in the privacy policy, they give out only the phone number and IP Address only in case of terrorism or child abuse and only when there's a court order from a country of a higher democratic index.

no idea about that

> 5. If you truly believe Telegram is bad for privacy even after all the evidence from FBI itself and PrivacySpy giving it a higher score than Signal, then please go ahead and sue them because surely they can't have a good privacy policy and bad privacy at the same time.

Since when is "bad for privacy" a reason for suing? The quality of a privacy policy doesn't have anything to do with privacy itself btw.

> and yet I just did. Can we please stop confusing privacy and anonymity?

I didn't, did I? please explain


> Actually, they do by not using E2EE by default and providing bad encryption possiblities.

These are again baseless claims. If you think MTProto 2.0, an encryption algorithm that has been audited multiple times by independent researchers is 'bad encryption', I'd like for you to prove it. Obviously, if you can prove it's bad, you could let Telegram know and win a bounty.

> How about you prove your claims? I hardly can bring them to justice when even the police doesn't have immediate access to them.

The burden of proof is not me as I did not make any claims, I simply restated what's on the Telegram website.

Even the FBI, Iran or Russian government couldn't bribe them so I do trust Telegram to not backdown on their statement and philosophy about not selling or using userdata for profit. https://twitter.com/durov/status/912812889236475904

> Second, regardless of your claims, Telegram can easily write a service which has access to plain text messages.

You do know even Signal could add a keylogger service to read message content right? I don't suppose their Google Play Store version has reproducible builds. See how easily arguments like these break down? You can almost assume anything and claim almost anything. As I said, these are baseless claims and assumptions. I'm only interested in the objective truth at the moment, not assumptions or guesses.

> Since when is "bad for privacy" a reason for suing?

You're suggesting Telegram's privacy policy is in direct violation of their privacy practices which is illegal. This is a huge claim, if you can prove it you should sue them, I'd honestly do that if I were you.

> I didn't, did I? please explain

Privacy is about choosing what to share, not about sharing nothing. You seem to lie more on the anonymity side of the argument than privacy rights. You're fighting for anonymity, not privacy if you claim malicious intent on Telegram's part because as I showed earlier, their privacy practices and security are totally A OK.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: