>>I think it's simplistic and short-sighted that many tech people seem to think that "security" means E2EE and absolutely nothing else.

>In private messaging apps security begins with E2EE.

This may be clearer from a product point of view. Your apparent viewpoint, and that of Signal etc, seems to be that protection from the server (and admittedly whoever can coerce whoever owns the server) is the only thing that matters, no matter what other features you have to throw out to get it.

What I am calling out is that this is a fundamentally ideological point of view. You can believe that and act according to it if you want, but general readers should be aware of what they are losing in order to enact this ideology with benefits that seem to be a bit dubious in the real world.

It is well known that Meta is happy to hand over to any legitimate law enforcement agency any content they have. To the best of my knowledge, Telegram never has, and neither has Signal. The fact that Telegram potentially could someday seems more theoretical to me. Again, to the best of my knowledge, all actual leaks of messaging group content have been by various authorities compromising individual devices and/or their owners, which works equally well against Telegram and Signal.

Meanwhile, Telegram gives you a lot more practical security regarding what information to share with other users, and how to manage what other users can do in large chat groups, which seems like a much more real-world concern regarding actual dangers to users than what the company that owns it might potentially do at some future date.

I think for real security, it's better to pay attention to the business model of the company that runs it. Meta's business model is indeed to basically sell your data to advertisers. Telegram does not do this, and shows no signs of wanting to. Instead, you can pay for premium, and they allow advertising as messages in public channels, and they're doing some semi-dubious stuff with cryptocurrency. Signal seems a little weird, they are apparently funded by some sort of donations from unknown parties. It seems to work okay for now, I guess, but is their financial future any more secure?

>>so you're screwed if you lose that.

>No you can keep backups in the cloud these days to recover your account. Unlike Telegram, the backups are actually encrypted so that the service provider can't read them.

I wasn't talking about that, but about the ability to de-auth your mobile device (the one probably most likely to someday get lost) from another device, since no one device is the "primary". Yes, an attacker could potentially lock you out if they get into your Telegram on the compromised device before you get on one of your other devices. But on Signal, you're screwed if it's your mobile, and fine if it's any other device.

Though since you mentioned backups, I think Telegram's way is arguably more secure. Individual user backups, even encrypted, means all your communication security is at the mercy of whoever in your group has the weakest encryption keys and backup storage location. With a centralized system like Telegram, it's never anywhere but their servers.