This is an article written by telegram’s founder and CEO Pavel Durov in 2019 on “Why whatsapp will never be secure”. Your thoughts?

  • Clot@lemm.eeOP
    link
    fedilink
    arrow-up
    9
    arrow-down
    6
    ·
    6 months ago

    which a bored student with a laptop can MITM in seconds

    No, how can a bored student breach e2ee in seconds? note that no such cases have been reported by any telegram user so far.

    • crispy_kilt@feddit.de
      link
      fedilink
      arrow-up
      12
      arrow-down
      6
      ·
      edit-2
      6 months ago

      Because the DH is unauthenticated, as I already said. Users can’t report it because there is no way to tell for them.

      • Clot@lemm.eeOP
        link
        fedilink
        arrow-up
        7
        arrow-down
        10
        ·
        6 months ago

        Users can’t report it because there is no way to tell for them

        Atleast the one who breached can tell? no telegram users data have been seen on dark web yet, no person/org have claimed to get any vulnerability in their system. Also if its that easy to breach why govt’s keep banning telegram for not giving them userdata? despite telegram is the biggest app where most terrorist orgs operate, hub of piracy and illegal things, you can call it “public” darkweb.

        • crispy_kilt@feddit.de
          link
          fedilink
          arrow-up
          8
          arrow-down
          2
          ·
          6 months ago

          if its that easy to breach why govt’s keep banning telegram for not giving them userdata

          Same reason they ask Apple for backdoors even though they crack iPhones routinely. It’s about legal precedent.

          • Clot@lemm.eeOP
            link
            fedilink
            arrow-up
            1
            arrow-down
            1
            ·
            6 months ago

            That article literally praises telegram despite being non e2ee by default, authorities can only get ip address and phone number from it (those are public info already and both of them could be avoided by using voip amd paid VPNs), that just proves how solid mtproto have become. Also they are saying one can see your telegram message when they are physically logged in your account for which the Russian authorities took the help of their ISP, in that case its not telegrams fault, set up 2fa on your account or use VoIP.