How bad is Telegram when using only secret chats?

I know I know. I’m trying to find a middle ground for a platform I can actually talk to people on. I have convinced all my friends and family to move to Signal for the most part, but I am meeting new people now and I do not want to be using SMS. Honestly I am also just burnt out trying to push people towards a privacy respecting platform.

Right now I am using WhatsApp in the private space of my GrapheneOS phone, but I think I may need to find something more sustainable - a way that people who don’t care about privacy can actually reach me.

Is using Telegram with only secret chats that bad? I know the e2ee is dodgy at best, and the company is just flat out weird, with Pavel claiming Telegram is more secure than Signal.. honestly.

What are your thoughts, and what’s your middle ground? Can’t use iMessage.

The forward secrecy only works for every 100 messages and the usability is pretty bad considering you can’t sync with other devices or chat with more than one other person per secret chat. There’s also no post-quantum cryptography like most other messengers have now. That being said, if it’s the only way you can get ahold of someone then it’s alright. You have to meet people where they’re at sometimes.

Would you say it’s better to use a Telegram secret chat, or WhatsApp?

I don’t really know, I don’t think it’s going to be meaningfully better one way or the other. Just go with whatever they will agree to use.

Yeah probably true. A factor in my decision making, as much as I dislike Telegram, is that it’s actually open source. So I would be fairly happy to use it, I suppose, for secret chats. I’m not really cryptographically inclined enough to say whether that’s worth the trade off for the flimsy crypto though. Do you know apart from the 100 message PFS key rotation, if the crypto is fairly robust?

If you meet someone using iMessage or Google Messages, I’d consider encrypted RCS via Google Messages. Otherwise the next best “mainstream” options are between WhatsApp and Telegram. WhatsApp’s E2EE has issues but Telegram’s E2EE is still pretty bad in comparison. However, Telegram seems to have a better privacy policy than WhatsApp.

If you’re more concerned with protecting the contents of your messages, I’d prefer encrypted RCS > WhatsApp > Telegram. If you’re more concerned about hiding your phone number or handing over your metadata to the likes of Meta and telecom providers, I’d prefer Telegram > encrypted RCS > WhatsApp. In my experience, finding a Telegram user IRL is as rare as finding a Signal user. If Telegram isn’t super common where you are, you may be stuck with WhatsApp or encrypted RCS regardless of what you deem a lesser evil.

WhatsApp by a long shot.

It uses the Signal protocol & individual components of WhatsApp have been independently audited (e.g. E2E backups, IPLS.)

And opposite side can make unencrypted backup to Google, giving them all your chats in plaintext.

At best you can have a federation of apps for talking to people on their platform of choice, be that Sesson, SimpleX, Signal, WhatsApp, Telegran, Element, or whatever. I do hope the first three get more use in the future. The two commercial platforms have their critics.

Over time, you can always ask them: “Got Signal? Y? Want to move our chats there?” At some level, others won’t want to move.

Guy Kawaksaki has a free epub of how to use Signal. Two points he brings up :

"We have a firm group of the obvious: private and secure messages and email are complicated and a pain-in-the ass. But it’s important.

Approximately 90 percent of Guy’s communication is done with Signal and Proton. 5 percent in Apple Messages because he can’t get his family to join Signal. And 5 percent and declining is Gmail for historical reasons."

  • From end of Chapter 28

The opposite side can make backups across any messenger. Or they could have malware on their phone that exfiltrates the messages. Or they could be a federal agent forwarding every message to LE. Could? No, they are indeed a federal agent. They know about your drug purchasing habits and your address has been burned. Expect a knock on your door any moment now.

If your concern is the other person saving the correspondence, then you should probably speak more on four eyes.

Yes and no. If it’s possible for you and the contact to not revert to non-E2EE chats, then checking the fingerprints should be decent. This still leaks to Telegram the metadata that you intend to hide all messages from them which is horrible compared to E2EE by default messengers, but if you use secret chats with everyone, at least they can’t detect which contacts you find more valuable. There’s a lot of bells and whistles from stickers to cross-platform chats on TG that lure you to drop E2EE even for 1:1 chats so unless you can slowly onboard them to something more private, one of you is likely going to grow tired of the inconvenience and open a normal chat.

@fria mentioned the per-100 message forward secrecy and no post quantum secrecy. I’ll add that the break-in key recovery is likely also per-100 messages, as TG naively replaces the key instead of mixing in entropy for subsequent key exchanges. This has implications to post-quantum security, at least JP Aumasson talked about Signal having some post-quantum resistance from the DH ratchet alone. It’s probably got to do with the sheer number of key exchanges they’d have to break, as well as the notion that there’s new keys constantly being sent and missing single one will make attacker unable to obtain the ratchet state with Shor’s algorithm. And this is all before Signal added the sparse post quantum ratchets.

WhatsApp is better for content protection, you’ll get multi-device E2EE with Signal protocol. There’s a 0.1% chance it contains a backdoor so if you can’t take it, Telegram might be better provided you actually read the client source code.

AFAIK nobody’s done it for ages, and I’m not surprised, it’s abhorrent. The files have thousands of lines of code, functions have hundreds or thousands of lines. Some had like 14 levels of indentation. There’s no docstrings or comments explaining it. Dunno if they strip them before release of what. The cyclomatic complexity is so bad I’d argue Telegram did vibe coding before it was cool.

Open source client is a necessity for transparent security and can act as deterrent for adding anything malicious, but if you do terrible enough job, nobody’s reading that source. Still my hunch is Telegram’s backdoor is hidden in plain sight, not in secret chats: There’s no E2EE for anything by default, for groups, for desktop clients, and users get to blame themselves for not using E2EE in Telegram.

This would require a more recent code review to see what’s going on. In its current state it’s better than no E2EE, but if you’d stack E2EE implementations, it would be near bottom.

I don’t use WhatsApp so I wonder if backups are enabled or pushed onto users by default? If not, I’d expect most users wouldn’t be making any backups at all.

Not by default you have to go out of your way to enable it. It’s very possible for someone to enable non-E2EE backups though, I think they should really just enforce E2EE backups like Signal.

That’s honestly just a marketing BS. There is a reason Telegram is not recommended.

with custom telegram clients you can still see deleted messages or deleted chats even from secret chats. i don’t think it’s really a safe option telegram.

Though I’d suggest looking at Comparison of Instant Messengers to get another POV.

Holy cow that interview clip carefully maneuvered around the entire question who has access to your encryption keys.

Reproducible builds are important to verify the encryption works, and Telegrams key management and default protocol is the backdoor, not algorithms.

Durov’s project is built on the lie it’s more safe than the always E2EE WhatsApp. He criticizes WhatsApp for it being not possible to check if WhatsApp has no backdoor, and he ignores that on his platform the reproducible build confirms the existence of the backdoor.

I’d argue that it depends on the phone you’re using. I have an Samsung Galaxy Note 20 and after an update Samsung did, my phone was no longer compatible with RCS. I can still message, it’s just not RCS. When I tried to turn in on in the settings, I stopped being able to send messages

Interesting, I have a Samsung phone not much newer than yours and hadn’t noticed any issues with encrypted RCS on Google Messages. This sounds like it could be a bug, have you investigated that issue any further?

Definitely, if you want consistent E2EE messages WhatsApp would be the #1 preferred mainstream alternative to Signal, SimpleX, etc. I only prefer encrypted RCS when I know my contacts are also using it.