Telegram is a double threat: the company is Russian and the founder was arrested then mysteriously released without any charges in France. Given why France wanted him and arrested him, the fact they released him a few days later with no charge annihilated the little shred of trust I had in this Russian piece of software, personally.

I don't know why anyone is using telegram when there is signal. Also with all the issues around telegram and their founder, you'd probably be safer using whatsapp even... :/

Telegram has way, way more features than Signal. First-class clients on every OS, much better behavior for large groups, far more sophisticated and granular permissions system for admins in groups, voice and video messages, folders for chats, etc.

It also has way more security features too, such as the ability for any session to de-auth any other session, while on Signal, only one mobile device is your "primary", so you're screwed if you lose that. Also tons of detailed permissions for who is allowed to see what information of yours and add you to groups. The only thing Signal actually does better is E2EE for groups. I think it's simplistic and short-sighted that many tech people seem to think that "security" means E2EE and absolutely nothing else.

>Telegram has way, way more features than Signal.

Except when you enable E2EE, you lose a lot of the features like stickers.

Also, enabling E2EE manually leaks additional metadata about intent to hide content from the service provider. That's insanely valuable even if you can't see the content.

Telegram treats E2EE like a door wreath hung from a nail. Practically all private messengers like Signal treat it like the foundations of the building.

>much better behavior for large groups

Telegram leaks a group as large as the size of 3 members, to the server, always, with ZERO way to opt-out. That's not better behavior. Whatever seasoning you apply on top of a turd, won't change what you're eating.

>far more sophisticated and granular permissions system for admins in groups

Yeah when you remove the "server has no ability to control the group" security feature you can do all sorts of things really easily.

>It also has way more security features too, such as the ability for any session to de-auth any other session

Way more in this case is clearly one. And this is a trade-off. Any of your devices gets stolen and the attacker can lock you out.

>so you're screwed if you lose that.

No you can keep backups in the cloud these days to recover your account. Unlike Telegram, the backups are actually encrypted so that the service provider can't read them.

>Also tons of detailed permissions for who is allowed to see what information of yours and add you to groups.

You mean, it allows you to control to whom the service provider yields the data. But the main privacy issue with Facebook, Telegram and any other surveillance capitalistic platform is the service provider. And Telegram isn't fixing Telegram learning everything about you.

>The only thing Signal actually does better is E2EE for groups.

Signal does EVERY thing better because every feature is private by design. Even if there's UX stuff to fix. You wouldn't claim some Trojan horse malware is really good because the game crack works and you can play a 30 dollar game while it steals your entire digital life or demands random or whatever.

>I think it's simplistic and short-sighted that many tech people seem to think that "security" means E2EE and absolutely nothing else.

In private messaging apps security begins with E2EE. Then you add tons of other features, like forward secrecy (Signal does it better than Telegram), future secrecy (Signal does it better than Telegram), Post-quantum security (Signal has it and Telegram doesn't), cross-platform messages usage (Telegram has no cross-platform E2EE), default security (Telegram has none), and that's just content. There's much more private tools for metadata protection, and on top of that you have advanced issues like endpoint security to deal with. E2EE is the bare minimum for e.g. PrivacyGuides app recommendations, and Telegram can't even cross that bar.

>>I think it's simplistic and short-sighted that many tech people seem to think that "security" means E2EE and absolutely nothing else.

>In private messaging apps security begins with E2EE.

This may be clearer from a product point of view. Your apparent viewpoint, and that of Signal etc, seems to be that protection from the server (and admittedly whoever can coerce whoever owns the server) is the only thing that matters, no matter what other features you have to throw out to get it.

What I am calling out is that this is a fundamentally ideological point of view. You can believe that and act according to it if you want, but general readers should be aware of what they are losing in order to enact this ideology with benefits that seem to be a bit dubious in the real world.

It is well known that Meta is happy to hand over to any legitimate law enforcement agency any content they have. To the best of my knowledge, Telegram never has, and neither has Signal. The fact that Telegram potentially could someday seems more theoretical to me. Again, to the best of my knowledge, all actual leaks of messaging group content have been by various authorities compromising individual devices and/or their owners, which works equally well against Telegram and Signal.

Meanwhile, Telegram gives you a lot more practical security regarding what information to share with other users, and how to manage what other users can do in large chat groups, which seems like a much more real-world concern regarding actual dangers to users than what the company that owns it might potentially do at some future date.

I think for real security, it's better to pay attention to the business model of the company that runs it. Meta's business model is indeed to basically sell your data to advertisers. Telegram does not do this, and shows no signs of wanting to. Instead, you can pay for premium, and they allow advertising as messages in public channels, and they're doing some semi-dubious stuff with cryptocurrency. Signal seems a little weird, they are apparently funded by some sort of donations from unknown parties. It seems to work okay for now, I guess, but is their financial future any more secure?

>>so you're screwed if you lose that.

>No you can keep backups in the cloud these days to recover your account. Unlike Telegram, the backups are actually encrypted so that the service provider can't read them.

I wasn't talking about that, but about the ability to de-auth your mobile device (the one probably most likely to someday get lost) from another device, since no one device is the "primary". Yes, an attacker could potentially lock you out if they get into your Telegram on the compromised device before you get on one of your other devices. But on Signal, you're screwed if it's your mobile, and fine if it's any other device.

Though since you mentioned backups, I think Telegram's way is arguably more secure. Individual user backups, even encrypted, means all your communication security is at the mercy of whoever in your group has the weakest encryption keys and backup storage location. With a centralized system like Telegram, it's never anywhere but their servers.

Just a small nitpick,

> Telegram has no cross-platform E2EE

If you mean between an Android and an Apple device, that is supported, to my knowledge.

Telegram's E2EE is acceptable only for limited use cases, though, it's crippled beyond belief.

No I mean between your smartphone and desktop clients.

When you can't continue the secret chat on your desktop device, you'll eventually get tired of having to dig your phone from your phone, unlock it, open telegram, navigate to chat, reply, lock phone, put it back to pocket continue work; the alternative of ditching security and just alt-tabbing to insecure chat on desktop client wins.

This is what a modern backdoor would look like. Vendor can't be blamed about introducing a backdoor, when using the backdoor feature is your own fault.

And this is just DMs where E2EE is possible in the first place.

Ah well yes; the chat is also bound to an individual device, it's not even possible to export it without root

The only purpose of the private chats feature at this point is to be able to claim that Telegram can do E2EE

Telegram has channels, which are a one-to-many (thousands or millions of people) chat feature letting you have basically your own social feed.

Lots of people follow channels for on the ground news reporting, especially since it's not censored or "advertiser friendly" like social media companies are incentivised to be.

The onboarding experience with Telegram is extremely easy, which is useful when dealing with non-technical audiences who might not even have a social media account (but do have smart phones).

My Bible study class has grown enough that standard SMS/MMS group texts are hitting up against Verizon's carrier limit (I think we have only two people who use Verizon), and RCS isn't an option. Telegram wasn't my first choice, but it was a lot easier for everyone, and it supports tablets out-of-the-box.

Matrix also has that.

Matrix clients do not allow to even select several messages to delete them at once. Matrix is a superior concept to proprietary Signal, Whatsapp, Telegram etc but the implementation needs some help yet and UI is far behind.

No it doesn't. Matrix has large groups, but they are limited:

1. You must join a group to see its contents. This puts a stupid "{user} joined the room" message in the room for everyone to see. Channel membership is anonymous.

2. Channels generate a public feed that doesn't require any special software to read from (see Durov: https://t.me/s/durov). Matrix requires a client of some kind, all clients are clunky at best and none have a public view.

3. Channels support millions of readers. Matrix rooms literally cannot do this, and rooms frequently get out of sync due to federation.

It's just extremely scamming or disinformation friendly

At that's the point. People are not choosing to use anything, they're using what they have to in order to communicate with people.

It's less about what they have but what the people they want to communicate are using.