Hacker News new | ask | show | jobs
by Tepix 2581 days ago
It‘s not homemade crypto. It‘s just not the latest and greatest modern crypto but it has no glaring weakness.
2 comments

[citation needed]..

But it’s absolutely homemade by math PhDs (not crypto specialists). And if you search for ‘telegram security’ you’ll find any number of articles pointing out a bunch of weaknesses. It’s also only half open source.

> half open source

Not just that. The official clients repos (specifically Android) lag several weeks, if not months, behind the apps, or at least they did at one point.

Though that doesn't matter much with not-quite-verifiable releases...

Granted, there are no known weaknesses with their protocol -- however, Telegram leads the user to believe their conversations are encrypted, which, unless they opted in to secret chats (and this is not supported on desktop ), its all in the clear.

So if you are using it on desktop, all your messages belong to Telegram, and whomever they are sharing it with.

As has been pointed out before this should be plain wrong. Keys and messages are kept separate, in separate jurisdictions even.

This way Telegram can back up messages without dumping them to Googles servers like WhatsApp does by default.