|
|
|
|
|
by maqp
1638 days ago
|
|
>So yeah, it's virtually public. Let's stop saying that as it implies users are somehow aware the service provider has access to the content, and that they make an informed decisions wrt their privacy. >Even your private messages only require you to enter an SMS code to view, so anyone that can intercept an SMS sent to you, can read your messages. The 2FA password is something everyone should enable. It's still an incremental security improvement if you have to use Telegram and your threatmodel is a banana dictatorship doing SMS interception but not server-side hacking. The right thing to do is get yourself and your loved ones the hell out of Telegram as soon as possible; Signal is your best bet here. Cwtch/Briar if you need to also protect metadata. |
|
No, this is not the right move. It's engaging with the ecosystem of messaging products balancing ease of use, ethics of the business and people behind it, and your own threat profile. Most will never be under threat of a state actor that necessitates getting their friends and family "the hell out of Telegram as soon as possible".
I also use Matrix but personally speaking I find Moxie Marlinspike a deeply unethical person who will gleefully slander the competition including up to suing them in his quest for supremacy. So I don't touch Signal because on my tripod of interests to balance, I don't want to go anywhere near his ethics.
Use Signal or Session or Element or Telegram but stop telling people not to use a thing because you believe E2EE is the next Jesus Christ. Only sith deal in absolutes.