If you have to be in the group chat with your real life identity, the only thing you can do is self-censor aggressively about yourself and your buddies, and hope your buddies do the same.
If it’s a group with mostly strangers and you don’t need to be there with your IRL identity, here’s how to minimize risks:
Anonymous usage
The first thing you want to do is buy a cheap burner phone and a COTS SIM card in a non-KYC country. You install Telegram on an OS that routes everything through Tor (or VPN). That’s easy with e.g. Qubes where you can control the network providing VM.
You’ll want to install Telegram desktop on the VPN/Torified Qube, and use the prepaid phone number and device during registration and discard (or if you want, stash until the pre-paid expires) them afterwards. Telegram doesn’t seem to want to re-confirm the number so you’ll be able to just keep answering “yes it’s still my number”.
In case the TelCo recycles the phone number, you’ll definitely want to enable Telegram’s 2FA password to something 128 bits or more. Use a generic strong password, like generate one with $ openssl rand -hex 16 or whatever to prevent account side-jacking.
Then use that anonymized account and avoid revealing anything about yourself in the conversation because anything you say can be used to deanonymize you by putting together facts about you. Remember to lie occasionally to poison the information pool. You need to also take extra steps to deanonymize your writing style (maybe run them through LLM), and invent separate personality.
Remember to also discard the account periodically to not tie too much information under single pseudonym.
If anyone in the group knows your real life identity, remind them in properly encrypted messaging apps to never reveal things about you in that group chat or contact you in Telegram’s DMs; You can’t have secret chats on the anonymized desktop client.
I’m not familiar with GOS so it’s hard to say where it can help here. If you can force Telegram through Tor there, registering with a secondary pre-paid SIM might work, and you could even have secret chats (naturally verify the the public key fingerprints). Use secret chats for ALL 1:1 conversations so that some conversations don’t stand out as more important than others.
As a bonus given the topic, I’ll give you another, separate harm reduction strategy:
End-to-end encryption on desktop.
Yes you heard me right.
If your threat model is more relaxed and you don’t mind leaking metadata about protecting one conversation, you (and your buddy) can use
to manage the phone from the desktop to have the same E2EE conversation there.
The problem is your contact might not know how to do this, get frustrated with opening their phone again and again, and just reply you without E2EE compromising the confidentiality.
Closing thoughts
This is NOT advocating for using Telegram in ANY WAY.
These are hacky harm-reduction strategies for a shitty app where NONE of this hoop jumping should be necessary in the first place.
If anything, showing how shit-hard making Telegram a bit safer is, and how your friends can still screw your anonymity and confidentiality by not caring, shows how insecure it is. Like, who’s ever heard of a protocol downgrade attack via “contact eventually gets lazy”.