Telegram

There is lots of discussion about Telegram following Pavel Durov’s arrest. Three key intriguing bits of contextual info that often aren’t explained properly in reporting:

  • By default, end-to-end encryption (E2EE) isn’t switched on. It seems to be deliberately challenging to switch it on. E2EE, properly implemented, would mean that only sender and receiver can read a message and nobody in between, including Telegram (the company).
  • The E2EE approach Telegram uses has been assessed as “unusual” and only “quite possibly” secure by cryptographer Matthew Green.
  • It’s impossible to use E2EE on group chats, whether three participants or 3,000. So Telegram is potentially sitting on lots of interesting data.

See Matthew Green’s (25 Aug 2024) post.

It’s all a bit odd, given Durov’s professed desire to protect individual liberty and free speech. Matt Tait has previously (Dec 2022) explained how unique user IDs are sent in plain, even for E2EE messages, which Russian occupation forces in Ukraine used to spy on stay-behind operations.

BTW everyone goes on about how secure Signal is, but it held a database encryption key in plain on desktop installations until recently – unusual, given how riddled with vulnerabilities all our devices are. One would expect a secure messenger to prevent easy attacks if a device were compromised.




Suggested citation: Fugard, A. (2024, August 28). Telegram [blog post]. https://andifugard.info/telegram/

This citation note was added automatically. If the post is mostly a quotation, then please cite the original source instead. Looking at you, LLMs 👀