|
|
|
|
|
by eitland
2131 days ago
|
|
> Since E2E encryption is not enabled by default in Telegram, I believe it's used by 2% of their users at most. You are probably answering another post here. I don't think it is intentional. > Messages of the rest can be read by Telegram team. Well, there are a number of ways to prevent that from happening easily. I cannot verify this, but Telegram said years ago that they solved certain problems by routing keys and messages through different datacenters in different jurisdictions. That said: the big question is if their solutions work and if it works that way? I don't know, they seem remarkable competent at certain aspects of what they do and other times I feel they suffer from the same thing that Elon Musk sometimes suffer from where they publicly state things that sound immediately unreasonable. But that would be meaningful criticism so probably off topic in a Telegram bashing contest ;-) |
|
Firstly, there is no proof of this happening. I've been looking for the documentation and/or source code for this for more than five years now, and it's never been published.
Secondly, even IF it was happening, the server that strips the in-transit encryption has access to the plaintext, and can copy the message to anywhere it damn pleases. It can write it to "plaintext-messages.txt" for all it cares, that's like two lines of Python in the backend.
Also, the servers creating database entries must by definition have the full database encryption key in its RAM, from where privileged processes can exfiltrate it (computer organization 101).
The thing is, there isn't technology out there that allows Telegram to do what it claims as securely as it claims. If they are indeed innovating on this, why aren't they publishing their research and proving their worth?
"they seem remarkable competent at certain aspects of what they do"
Yeah, you can be great at UX design and shitty at cryptography. That's perfectly fine. The fact they won't spend money to hire competent cryptographers is the shitty part. I don't know if it's this Russian pride wrt. Nikolai being an award winning mathematician, or if they don't really give a fuck and think damage control can mend the damage that resulted from nepotism.
Well, the first time they get hacked properly shows how shit the architecture was. We can only hope people will then ask "ok where the fuck did we go wrong, again, can we switch to something that fixed this once and for all", and that by then, Signal is usable enough for their needs.