Hacker News new | ask | show | jobs
by fer 1480 days ago
It's not worse, aside from chats being unencrypted by default.

I've had suggestions on Instagram of people who I never got in touch with, only because my wife, who has no FB account, is in the same WhatsApp group as these people. They mixed in a bunch of other "you may know" people to make it less obvious, but when comparing her groupchat and my suggestions, it's clear they made links via IPs and phone numbers. At least Telegram isn't big enough (not yet, anyway) to cross correlate data to ID users like that to create such privacy concerns. FB? No, thanks.

2 comments

> It's not worse, aside from chats being unencrypted by default.

That is not a side point though. It's a major, major difference.

Chats are encrypted. The question who can decrypt them by default.

It is a trade-off between security and usability. By default, you get usability (e.g., you can chat across devices easily). But you think it is worth the cost, you can make encryption keys unavailable without corresponding devices (create secret chat).

My guess, most telegram users prefer usability or don't care/ignorant. It would be a mistake to make the experience worse (that people would notice ignorant or not).

> Chats are encrypted.

Not end to end. Let's not sell SSL connections as encryption please.

It is false that chats are "unencrypted" (I know, it is repeated on every submission about Telegram here but it does not make it true whatever Goebbels said). Here's a quote from the FAQ: "The relevant decryption keys are split into parts and are never kept in the same place as the data they protect. As a result, several court orders from different jurisdictions are required to force us to give up any data." https://telegram.org/faq#q-do-you-process-data-requests
That is only true for the End 2 End encrypted chats, which are a separate and not very user friendly thing. Regular chats and group chats/channels are by design unencrypted.
It is false. Click the link to the FAQ. The paragraph for the quote begins with "To protect the data that is not covered by end-to-end encryption"
To me a chat app not reading my messages is way more important than a chat app will not use my phone number for advertisement. Ideally I'd have both, but given a choice, the first one is way way more horrific than the other.

Though, for some cases Telegram is definately better, Groups, work related chats don't really need to be private as much and that's where telegram really shines for me. Specially since I can use it without giving my phone number away.

> is way more important than a chat app will not use my phone number for advertisement.

My profile being shown on a different platform to people that I might be close to (co-workers, in-laws, friends of friends) but I'm not interested in having on social media is pretty damn concerning, regardless of ads.