# Pavel Durov on Signal

**URL:** https://discuss.privacyguides.net/t/pavel-durov-on-signal/37058
**Category:** General
**Tags:** software
**Created:** 2026-04-11T13:41:53Z
**Posts:** 39

## Post 1 by @spyfall — 2026-04-11T13:41:53Z

[https://xcancel.com/durov/status/2042710443316130038#m](https://xcancel.com/durov/status/2042710443316130038#m)

“That’s why Telegram Secret Chats never show message content in push notifications. Since 2013, Secret Chats have remained the most secure usable way to communicate. US gov funded Signal has too many questionable dependencies on other US companies (AWS, MS, Intel SGX…)”

”Turning off notification previews won’t remove the risk — you never know whether the people you message have done the same. Telegram’s Secret Chats design is the only solution. Disabling previews hurts usability, hence two types of chats: Secret and Cloud.”

---

## Post 2 by @Pragmatic — 2026-04-11T14:12:49Z

I follow Pavel Durov’s X accounts just to see the absolute bollocks that clown spouts all day long, it’s always a laugh.

---

## Post 3 by @micdan — 2026-04-11T14:14:44Z

The way that defends his own app by dismissing users in his thread… :triangular_flag:

I mean, I’m pretty sure he relies in other proprietary services too, like Google billing APIs for TG Premium. Talks like his app is bullet-proof, and it’s not even E2E by default. :joy_cat:

---

## Post 4 by @shadowwwind — 2026-04-11T14:58:41Z

In app message translation uses google translation API lul

---

## Post 5 by @hashcatHitman — 2026-04-11T15:05:26Z

This does make me wonder, though: is there any mechanism in Signal we can use to prevent our message contents from appearing in the recipient’s notifications regardless of how they have configured the setting to do so? It was hard enough to get my friends and family to start using Signal as it is, and in most cases, I’m not sending anything I would be worried about, so I do not think it is feasible or reasonable to convince them to accept such a huge loss of convenience from what they are used to for the few times when I send messages I would be worried about.

---

## Post 6 by @Expert4870 — 2026-04-11T15:08:49Z

> [@spyfall](#):
>
> Disabling previews hurts usability, hence two types of chats: Secret and Cloud.”

So 99% of your users aren’t even using an e2ee messenger and therefore their chats are vulnerable to data breaches and remote LE requests. I will say that is probably a teeny bit worse than needing to break into a confiscated iPhone.

---

## Post 7 by @Expert4870 — 2026-04-11T15:10:22Z

If you are not messaging friends and family who are likely to have their phones taken by the FBI, I wouldn’t worry about it.

---

## Post 8 by @crossroads — 2026-04-11T15:12:53Z

> [@hashcatHitman](#):
>
> This does make me wonder, though: is there any mechanism in Signal we can use to prevent our message contents from appearing in the recipient’s notifications regardless of how they have configured the setting to do so?

No, and there won’t be. Regardless of service used, the only way is that all participants in conversation are equally aware of risks and consequences.

It is similar with 3rd party apps and matrix bridges. You can not be sure what other side is using on their device. Even you agree to use e.g. Signal, without notification messages, they can install some malware app, leave unlocked phone on train station, etc.

Maybe solution is to call (via Signal) and say important thing, or even better, meet in person.

---

## Post 9 by @hashcatHitman — 2026-04-11T15:27:48Z

> [@Expert4870](#):
>
> If you are not messaging friends and family who are likely to have their phones taken by the FBI, I wouldn’t worry about it.

…and if I _am_? Unfortunately, I think a lot of people I know are at higher risk of such than they realize.

> [@crossroads](#):
>
> No, and there won’t be. Regardless of service used, the only way is that all participants in conversation are equally aware of risks and consequences.

To a certain extent, yes, of course. Everyone should be aware of the risks and consequences. But at the same time, I can still see something like this _helping_ to reduce risk.

> [@crossroads](#):
>
> It is similar with 3rd party apps and matrix bridges. You can not be sure what other side is using on their device. Even you agree to use e.g. Signal, without notification messages, they can install some malware app, leave unlocked phone on train station, etc.

For example, it is much easier for me to personally verify that they install a legitimate version of Signal than to make sure they keep a specific setting enabled. From there, their OS and app store can make sure updates are valid. They could install some _other_ malware, yes, or leave their phone unlocked in public, yes, but those are both situations that I think are more likely to be immediately and obviously unwanted by the average person, and they are more likely to want to prevent such things actively without my pressuring them to do so.

> [@crossroads](#):
>
> Maybe solution is to call (via Signal) and say important thing, or even better, meet in person.

For particularly important things, yes. But even outside of that, I think it would be nice to be able to do so for things that are “potentially risky to say, perhaps in the future if not now”. I am not terribly concerned that the FBI is going to find out that I tell my mom I love her. If I were telling her about my plot to take over the world, obviously I would be. If I were discussing politics in general with her? It would seem like overkill to both of us to meet in person or call every time such a topic came up, but at the same time, it isn’t completely out there to think that discussions about politics could put us at risk at some point in the future.

At the end of the day, it isn’t a huge deal for me, personally, but I do think it would be a relatively cheap feature to add (as the machinery to hide the contents of a notification already exist), and I can only see it improving the situation, or at worst, making no difference.

---

## Post 10 by @micdan — 2026-04-11T15:33:38Z

I mean, notification snatching it’s more an OS thing than an app problem, but Durov tweets like if Signal was the problem. Lol

And it’s even worse since TG is not E2E encrypted so…

---

## Post 11 by @Ganther — 2026-04-11T17:41:41Z

> [@micdan](#):
>
> Durov tweets like if Signal was the problem.

Gotta deflect the fact that his app is insecure garbage somehow.

---

## Post 12 by @maqp — 2026-04-11T17:58:22Z

> Since 2013, Secret Chats have remained the most secure usable way to communicate.

Ah yes, the secret chats that

- Are not available for groups so 0% of group chats use them
- Are not enabled by default so 99% of users don’t use them at all
- Are not available for any desktop clients so you can’t use them without forcing you and your contact (who’s always lazier than you) to whip out the phone hundreds of times per day, when the desktop-client is alt-tab away, and thus that is unusable in practice and thus only exists on paper and online debates about Telegram’s supposed security. So 80% of users who try Secret Chats eventually give up using them giving Telegram access to all messages.
- When enabled, yield extremely valuable metadata about user explicitly trying to hide their communications from Telegram with a selected contact.

The secret chats that are / have been riddled with issues from

- 2⁶⁴ complexity attack, to
- IND-CCA vulnerabilities, to
- graphical-pixel-map-only safety numbers you can’t communicate over authenticated line
- Nepo-bro yoloed crypto like AES-IGE and [The Most Backdoor-Looking Bug I’ve Ever Seen](https://words.filippo.io/telegram-ecdh/), to
- Still no post-quantum key exchanges, to
- Still no double ratchet protocol (no break-in key-recovery) to
- No private backups

Yes, but let’s listen to this clown tell how Signal is so bad because iOS f’d their users’ privacy.

Also lol

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/d/7/d7656e82b3ba1cc8986f0f4d09f8d6d99b1b7e88.png)

The grifter in charge tries to gaslight people into thinking E2EE comms is an item on a feature list you can glue on top, like stickers. It’s not. E2EE is the foundation of the application, and you build all features over that foundation. Like Signal does.

EDIT: Oh whoa, I expected the Twitter thread to be like 90% of TG shills doing damage control. Instead it’s 95% annoyed people calling them out.

---

## Post 13 by @Gersand — 2026-04-11T21:04:26Z

I don’t think there is any idiot-proof solution for privacy. And when i write “idiot-proof”, i don’t mean to insult anyone, the idiot can be me or anyone at times. It’s just an expression to qualify an architecture and emphasise that whatever the tool, the weakest points of a communication between two humans are often the two humans. Even if there was a perfect setting imposed to your friends, you can never be sure they won’t just say or share what you sent to someone else, they won’t ever be drunk, they won’t ever be blackmailed etc. At some point there is a tradeoff between what you **need** to send, your trust in the recipient’s capacity and will to keep it secret, and some acceptance that when sending/sharing/saying something to someone, you don’t fully control that “something” anymore. For example, remember how the world learned about top secret US stuff despite the use of Signal: [United States government group chat leaks - Wikipedia](https://en.wikipedia.org/wiki/United_States_government_group_chat_leaks?wprov=sfla1)

Also, i would trust more Meredith when she says nothing unencrypted travels in the push notification than Pavel saying otherwise: [https://x.com/mer\_\_edith/status/1734320963074797917](https://x.com/mer__edith/status/1734320963074797917)

---

## Post 14 by @dngray — 2026-04-11T21:12:16Z

I’ve always wondered whether Telegram is permitted in some places because it has known weaknesses certain governments are privy to.

Signal on the other hand, has a much smaller surface area (less bullshit features) and far more scrutiny put into the crypto the actual thing that keeps your information confidential.

Telegram is about as secure as Discord, IRC or a public matrix room with no encryption enabled. I wouldn’t use it with any expectation of real privacy.

---

## Post 15 by @maqp — 2026-04-11T21:20:35Z

Proving any links to states is next to impossible and if one could show show credible link to FSB/SVR they’d probably get offed by the agency quite fast. If Telegram is an op, it’s one of the biggest on the planet. But whether it is or not, doesn’t matter that much: In any case, it is one set of zero day exploits away from leaking 800M users’ data, and all major nation states have such exploits. If the spy teams of major nation states haven’t pwned Telegram severs by now, they deserve to get fired for not taking the lowest hanging fruit out there.

---

## Post 16 by @dngray — 2026-04-11T21:26:55Z

> [@maqp](#):
>
> If Telegram is an op, it’s one of the biggest on the planet.

I’m not sure that’s what I had in mind, more a friendly firm that will collaborate on some occasions where the state asks it to, rather than an actual back door.

Remember most people _don’t actually use secret chats_ therefore there is no encryption on most conversations, unlike Signal which doesn’t have an unencrypted mode.

> [@Gersand](#):
>
> Also, i would trust more Meredith when she says nothing unencrypted travels in the push notification than Pavel saying otherwise: [https://x.com/mer\_\_edith/status/1734320963074797917](https://x.com/mer__edith/status/1734320963074797917)

Merideth is correct on that, [I looked at the source code some time ago](https://discuss.privacyguides.net/t/apple-reveals-push-notification-spying-by-foreign-governments/15440/8) and I doubt it’s changed since 2023.

---

## Post 17 by @Gersand — 2026-04-11T21:32:02Z

If there were any links, i doubt it would be with FSB or so, since Russia has now totally banned Telegram ( [Blocking of Telegram in Russia - Wikipedia](https://en.wikipedia.org/wiki/Blocking_of_Telegram_in_Russia?wprov=sfla1) ) or is about to do it.

**Or** , this biggest op is also the most wicked one.

---

## Post 18 by @donutfreak — 2026-04-11T21:53:14Z

Signal could improve the notifications situation if the default for notifications was “No name or message”.

If the user selects one of the other two options, Name or Name And Message, then a warning could be displayed and after that’s set, a “Are you absolutely sure? This is a privacy leak.” type of response the user would have to agree to.

Or similar.

---

## Post 19 by @maqp — 2026-04-11T21:57:48Z

> [@dngray](#):
>
> rather than an actual back door.

Lack of E2EE is the backdoor. It’s a front door to security researchers, and backdoor to users who have no understanding how the protocol really works.

There’s no overlooking the fact that Telegram intentionally portrays to be more private than WhatsApp, despite having no E2EE. They claim to use MTProto for all messages (true), and they say their E2EE protocol is called MTProto (true). What they don’t say out loud is that the insecure client-server encryption is ALSO called MTProto, and that Telegram doesn’t default to E2EE messages under any circumstances.

Durov has had the ‘Fuck You Money’ to employ a team of cryptographers, full time, to port entire TG system to E2EE: all 1:1 chats and all non-super-groups, since they started. The only reason Telegram doesn’t do that, is because Durov has a reason for it not to.

Instead they’ve created “[Telegram Support Force](https://tsf.telegram.org/)”, a team of useful fools (Russian propaganda technique) to promote Telegram’s view on forums, about these things are supposedly supposed to be done. This is money wasted. They could’ve instead addressed the underlying issue.

> Remember most people _don’t actually use secret chats_ therefore there is no encryption on most conversations

I find it really weird you missed my detailed dissection of this very thing in my first post on this thread.

---

## Post 20 by @maqp — 2026-04-11T22:03:48Z

> [@Gersand](#):
>
> If there were any links, i doubt it would be with FSB or so, since Russia has now totally banned Telegram

Yes, what could Russian intelligence establishment, that [wrote](https://en.wikipedia.org/wiki/Russian_military_deception) half the books on misdirection, know about creating honeypots.

They don’t need to spy on Russians on TG if they can force every Russian to use MAX. They will need a way to spy on everyone else, and Durov who supposedly lives in exile, and who “fights” the Russian state, is their best bet. So let me pose it this way, if Durov lives in exile in the fear of Putin, why has he returned to Russia over SIXTY times? [https://kyivindependent.com/kremlingram-investigation-durov/](https://kyivindependent.com/kremlingram-investigation-durov/) How has Putin failed to detain him at the airport and throw him to the cell that belonged to Navalnyi? Exactly.

---

## Post 21 by @WhyRhy — 2026-04-12T07:15:22Z

> [@hashcatHitman](#):
>
> is there any mechanism in Signal we can use to prevent our message contents from appearing in the recipient’s notifications regardless of how they have configured the setting to do so

I may be wrong here - and very happy to be corrected by those more technically minded - but I _think_ there is a way.

In Signal group chats, snippets of your replies to messages are sent to everyone - even if you’ve got them blocked! By this I mean: you can send a message in a group chat, but if someone replies to your message, everyone can see the first line of text (to a degree) even if they’re blocked. So, to rectify this you write something on the first line (emojis, a full stop, any letter etc) then press enter twice - something like this:

:smiling_face_with_sunglasses::smiling_face_with_sunglasses:

MESSAGE HERE

So, the preview shown will only be :smiling_face_with_sunglasses::smiling_face_with_sunglasses: and not the message. Those you have blocked (or even those not on block) will just see “:smiling_face_with_sunglasses::smiling_face_with_sunglasses:” in the reply preview. NB: Those not blocked will still be able to click the preview to take them to the correct message referenced)

Why am I saying this here for this use case? Well, I suspect this may also fit in this instance. Apple notifications don’t show you the WHOLE message, just a snippet. So, adopting something similar to the above might work. When sending messages, try making the first two lines or so meaningless. See what comes up on their notification. If it’s garbage in, it’ll probably be garbage out?

EDIT: Incl Spoiler

Formatting the spoiler may also work (but I can’t offer any guarantees as I don’t know whether Apple notifications sees the original message or the obfuscated one)

 ![IMG_5280](https://forum-uploads.privacyguidesusercontent.com/original/3X/7/8/7809c84f3cf28074cd6940b1bf95364bd1b84eac.jpeg)

 ![IMG_5281](https://forum-uploads.privacyguidesusercontent.com/original/3X/b/9/b97a7a054962a32d58025fc5ba2a14e4a187ffcd.jpeg)

EDIT 2: After some testing, it looks like the :smiling_face_with_sunglasses::smiling_face_with_sunglasses:/multiple line method will NOT work. The entire content is displayed in the notifications. So while it’s good for group chats / blocked users, it’s not good here.

BUT the ‘Spoiler’ formatting of text does seem to prevent the real message being displayed. What that looks like on the Apple logs I don’t know….

---

## Post 22 by @Gersand — 2026-04-12T08:19:08Z

I think i wasn’t clear. It’s not that I think Russia wouldn’t do it. And actually they have done it, including with Telegram. I am just saying that since Russia is now completely and technically shutting down Telegram on its territory, Telegram is becoming worthless to them.

What is written in the article you mention is not necessarily surprising. A big lot of Russian government propaganda was through Telegram channels and groups. Telegram has been a tool of choice even for some military in Russia. Telegram was so big in Russia that it was a best tool for surveillance and propaganda. But now Russia thinks the opposition’s use of Telegram is too important and they sacrifice their own use by shutting it down.

Plus, the article doesn’t mention whether Durov’s entering Russia was legally or not. Russia is big and there are countless points of illegal entrance. It’s possible that intel has just known afterwards that Durov was there, without being able to know it when it was happening.

Finally, since Russia is really good at honeypot and misleading, it could quite easily have organised to send an anonymous spreadsheet then a corroborating FSB “leak”. (I don’t believe it is the case, i am just pointing that we are simple mortals who shouldn’t hold too tight on any opinion or belief in that kind of matter.)

---

## Post 23 by @PurpleDime — 2026-04-12T09:35:03Z

> [@Pragmatic](#):
>
> I follow Pavel Durov’s X accounts just to see the absolute bollocks that clown spouts all day long, it’s always a laugh.

I look forward to the day Telegram users realize how much of a deceiver he is. Durov has such a cult grip on them. Also, privacy companies need to STOP listing Telegram as the 2nd choice when comparing E2EE messaging apps. They are not helping. Just a couple of days ago [Proton did it again.](https://x.com/Proton_Pass/status/2042584947014140190) Telegram should not even be on the list, or it should be dead last. I don’t care how popular it is.

> [@Expert4870](#):
>
> If you are not messaging friends and family who are likely to have their phones taken by the FBI, I wouldn’t worry about it.

You can’t always know that. Most whistleblowers had no idea that they would become whistlenlowers. That said, it’s not a bad idea to warn them about this.

---

## Post 24 by @anon96036341 — 2026-04-12T10:32:49Z

> [@PurpleDime](#):
>
> They are not helping. Just a couple of days ago [Proton did it again.](https://x.com/Proton_Pass/status/2042584947014140190) They are not helping. Telegram should not even be on the list, or it should be dead last.

I agree.

But I also kind of feels Proton is only obligated to because people are expecting to see how Telegram fares (which is still fairly popular in some places). And that’s why they do it.

If they don’t and only list the best, then there is no list but only Signal and _maybe_ a couple others like SimpleX.

---

## Post 25 by @CarefulMouse — 2026-04-12T10:55:47Z

> [@hashcatHitman](#):
>
> This does make me wonder, though: is there any mechanism in Signal we can use to prevent our message contents from appearing in the recipient’s notifications regardless of how they have configured the setting to do so?

In addition to what @WhyRhy shared, I think you can also send one time picture messages with text applied. Think a blank background and using Signal’s text overlay feature.

@WhyRhy also including an image of what the recipient sees in the notification for spoiler. Personally, I think this would be visual only. Like you indicated, I imagine the full unredacted text is in the same log files, but would be interesting to get confirmation.

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/b/2/b21853f3943517fb0b2d94f55a6fce7757bedbff.jpeg)

---

## Post 26 by @maqp — 2026-04-12T12:11:13Z

> [@Gersand](#):
>
> Telegram is becoming worthless to them.

Again, to spy on domestic citizens, not to spy on Telegram that’s as per the Twitter thread being called out across the board. The war in Russia is going poorly, and Russia is controlling Internet to the point of blackout in Moscow.

> Telegram has been a tool of choice even for some military in Russia.

Exactly. people will soon start asking questions how the F did Russian state allow using Telegram to coordinate the war at operational level, if they didn’t control the infrastructure.

The shill campaigns on /r/privacy etc conveniently died during the war, which is another data point.

> But now Russia thinks the opposition’s use of Telegram is too important and they sacrifice their own use by shutting it down.

The opposition activists are catching up on Telegram’s security. They have zero issue using western messaging app because they know US would not let Russians get access to the data even on a non-E2EE platform. But majority of people pare simple enough to think “It’s banned, therefore it’s secure.”

Ultimately, it’s the lazy westerners that Telegram now gives access to. And if it’s an op, it looks like there’s all sorts of illegal stuff being offered from warez to CSAM, that Russian intelligence agencies would have zero issues using as compromata. That’s probably how they’re keeping grip on the Epstein class.

> [@Gersand](#):
>
> Plus, the article doesn’t mention whether Durov’s entering Russia was legally or not.

Yeah I’m sure the guy slipped into the country 60 times and we know it was 60 times because there was an unofficial count on some airport customs wall but nobody told Kremlin who’s supposedly after him? There’s about 40 airports in Russia with international flights, so as per pigeon hole principle it wasn’t unique random airports, and you can bet your ass Durov didn’t take a taxi from Vladivostok to Moscow during his visits.

> It’s possible that intel has just known afterwards that Durov was there, without being able to know it when it was happening.

Sixty times? I know Russians are incompetent but they’re not that incompetent.

> i am just pointing that we are simple mortals who shouldn’t hold too tight on any opinion or belief in that kind of matter

All you’re doing is defending a tech-bro billionaire who failed his users, by sowing doubt.

---

## Post 27 by @PurpleDime — 2026-04-12T12:20:19Z

> [@anon96036341](#):
>
> But I also kind of feels Proton is only obligated to because people are expecting to see how Telegram fares (which is still fairly popular in some places). And that’s why they do it.

I can appreciate that, but as I said, Telegram shouldn’t be listed as second or even in the top 3. If you’re gonna list it, put it last. That’s how little consideration it should have, IMHO. WhatsApp should also be at the bottom of the list. I take no issue with good E2EE apps that are not known to the mainstream being listed in the top 5. At least their security is sound.

---

## Post 28 by @randomperson — 2026-04-12T15:47:56Z

If the FBI takes my phone they might be able to extract deleted messages from it.

Which means I should definitely use Telegram Secret Chats for criminal activity instead of Signal.

Well that’s easy to do, since I don’t do criminal activity and use my messenger to communicate with acquaintances, friends and family. About half of this communication is done in group chats. For those use cases, Telegram Secret Chats are impractical or in case of group chats impossible.

I’m fine with Signal not being marketed or recommended towards criminals or for being suitable for criminal activity. If it can protect me from criminals and overly greedy companies, who are working with criminals (Malvertising), I’m happy with Signal.

---

## Post 30 by @hashcatHitman — 2026-04-12T15:57:51Z

> [@maqp](#):
>
> If opposing the Christofascist state run by a narcissistic grifter pedo rapist war criminal is bad in your opinion, maybe it’s time to reconsider you value system. :slight_smile:

Regardless of this, someone who is perfectly content with the current political climate in their country may very well be a dissident tomorrow. Signal _is_ made for criminals. Thought criminals, specifically. I think everyone should aspire to be such a criminal; to think freely is to be human.

---

## Post 31 by @maqp — 2026-04-12T16:03:59Z

My message was too stern and the post I replied to didn’t actually make the implication so I removed it.

---

## Post 32 by @Gersand — 2026-04-12T16:18:35Z

I am really sorry if I ever wrote something that might make someone think i defend Durov or Telegram. I do believe they are both bad, i never used or even installed Telegram on any of my devices and i advise all my friends, family, employers or clients against it. If ever there was some doubt, it was unintentional and it’s now clarified.

That said, even if, on top of proprietary code and bad encryption scheme, i have thought of Russia’s controlling Telegram as a plausible and quite logical move, i have never faced any serious evidence supporting that hypothesis. It’s not sowing doubt, it’s being rational and intellectually honest with respect to the information I have seen so far.

Since i don’t like Durov and Telegram (and Putin), I am sincerely keen on receiving new information and evidence showing their compromission. It would indeed make the awareness raising part of my work much simpler. If you have such information, i would love to see it. But please refrain from using agressive tone, as i don’t think it is useful and it is really unpleasant.

---

## Post 33 by @maqp — 2026-04-12T16:42:02Z

> [@Gersand](#):
>
> But please refrain from using agressive tone, as i don’t think it is useful and it is really unpleasant.

Yeah I apologize. My tone is not intended to attack you and this isn’t personal. My goal is to defend and protect users against the trove of lies Durov has built his social media on.

> [@Gersand](#):
>
> i have never faced any serious evidence supporting that hypothesis.

Unfortunately there is no such evidence and likely never will exist such evidence.  
FSB famously uses typewriters so unless someone walks into Lubyanka they won’t obtain paper trail about this, if it’s written down at all.

But it’s enough to see Telegram arguing why they should not enable E2EE. After that it doesn’t matter if Telegram is an op. They’re a centralized trove of information regardless. Whether Durov leaves the door open for FSB or whether they force use of the exploits does not matter. It’s Durov’s job to know what he’s doing and that what he’s now doing endangers all TG users.

Cryptography assumes systems insecure until you prove them secure. Lack of E2EE proves it is not secure.

Defending your product after being told that is willful ignorance.

---

## Post 34 by @randomperson — 2026-04-12T16:45:24Z

I know the “enemy of the state” attitude is pretty popular within the privacy community, but I don’t like to share such an attitude. I am also convinced it is actually harming all of us, because it hinders us in reaching normal people from adapting a better privacy posture.

You could end up on the wrong side of history, but most people would just change sides when needed. I’m pretty sure most of my family would just keep their head down and just want to be left alone whenever some dictator would take over my country. They would not want to oppose who ever is in power.

I don’t want to be a rebel or dissident or opposition to my government either. I do want to able to trust my community and my government. I just don’t want to have to trust that everyone in a position of power is and always will be benevolent towards me and people I care about. I also don’t want to have to trust everyone with in a position of responsibility never makes mistakes.

---

## Post 35 by @spyfall — 2026-04-12T17:21:19Z

[https://xcancel.com/durov/status/2043338467355013211#m](https://xcancel.com/durov/status/2043338467355013211#m)

”WhatsApp’s “E2E encryption by default” claim is a giant consumer fraud: ~95% of private messages on WhatsApp end up in plain-text backups on Apple/Google servers — not E2E-encrypted. Backup encryption is optional, and few people enable it — let alone use strong passwords.

Even if you encrypt your WhatsApp backups with a strong password, your messages still end up in unencrypted cloud backups — because 90%+ of the people you message haven’t done the same. Add the fact that WhatsApp stores and discloses who you chat with, and the picture is dire.

Apple and Google disclose backed-up WhatsApp messages to third parties thousands of times per year. Meanwhile, Telegram hasn’t disclosed a single byte of users’ messages in its entire 12+ year history.”

---

## Post 36 by @maqp — 2026-04-12T17:27:34Z

> [@spyfall](#):
>
> Meanwhile, Telegram hasn’t disclosed a single byte of users’ messages in its entire 12+ year history.”

Telegram has access to 100% of user metadata, 100% of group messages, and something like 99.99999% of 1:1 messages. Anyone who hacks the servers can read the messages because they’re all just sitting there. Any argument that they don’t disclose it means nothing when there’s big players who can hack the servers, and who never make any noise about doing that or how easy it is for them. Plus who knows for what purpose Telegram might use the messages they hoard for themselves. Not a single tech giant deserves your trust.

I’m not defending WhatsApp here, its ridiculous that you can never get rid of the backup reminders until you give in. But Telegram is objectively worse as the backups are created by the messaging app provider itself, and it’s impossible to opt out for groups and practically impossible to opt out for 1:1 chats.

And it’s not like you have to choose from the two either. Almost anything is better than Telegram and tons of messaging apps are better than WhatsApp. Signal, Element, Wire, Threema, even SimpleX. So why attack a strawman like WhatsApp?

---

## Post 37 by @hashcatHitman — 2026-04-12T18:19:37Z

I do not think we necessarily disagree. When I use the word “dissident”, I do not necessarily mean someone actively opposing “the state” or rebelling. I am taking the definition of dissident at face value, as per the Merriam-Webster dictionary:

> disagreeing especially with an established religious or political system, organization, or belief

If you “keep your head down”, but you do not necessarily agree, I would consider you a dissident. You may not have any intention of being a rebel of any kind; I am sure most people would much prefer they never have any reason to. But if today everything is fine, and tomorrow people of your ethnic background, religion (or lack thereof), or whatever other group you fit into are the subject of unjust persecution, regardless of whether you “keep your head down” or not, “the state” has decided you are “an enemy of the state”. Unless you can fundamentally change your beliefs and background at will, you will almost certainly disagree with it, and you will be, as far as I am concerned, a dissident.

I believe this roughly matches the sentiment you have expressed here:

> [@randomperson](#):
>
> I just don’t want to have to trust that everyone in a position of power is and always will be benevolent towards me and people I care about.

Which is more to the point I was trying to make. When I say:

> [@hashcatHitman](#):
>
> Signal _is_ made for criminals. Thought criminals, specifically. I think everyone should aspire to be such a criminal; to think freely is to be human.

All I mean to say is that everyone should be willing to hold their own beliefs, thoughts, and opinions. They do not necessarily need to share them, but they should never feel like they are not allowed to think the way they do because someone else said they are not, be it “the state” or otherwise. To the extent of how Signal helps with that, if your family is religious, for example, I am not saying you are a thought criminal only if you are using Signal to plan or discuss opposition against religious oppression. I would consider you a thought criminal for even being brave enough to discuss your beliefs amongst yourselves in any capacity, as “the state” does not approve of such thought. I would consider you a thought criminal for even having those beliefs, though to have such beliefs and never discuss them would obviously not require Signal.

---

## Post 38 by @randomperson — 2026-04-13T07:45:14Z

> [@hashcatHitman](#):
>
> All I mean to say is that everyone should be willing to hold their own beliefs, thoughts, and opinions. They do not necessarily need to share them, but they should never feel like they are not allowed to think the way they do because someone else said they are not, be it “the state” or otherwise. To the extent of how Signal helps with that, if your family is religious, for example, I am not saying you are a thought criminal only if you are using Signal to plan or discuss opposition against religious oppression. I would consider you a thought criminal for even being brave enough to discuss your beliefs amongst yourselves in any capacity, as “the state” does not approve of such thought. I would consider you a thought criminal for even having those beliefs, though to have such beliefs and never discuss them would obviously not require Signal.

I agree, but it does not help me promote the use of Signal.

Here is the reality of the people I have to convince to care for privacy and use services like Signal:

- The state, the police and the authority are there to protect me. They could never be a source of risk to me.
- Facebook, Instagram and WhatsApp is what keeps me connected to my social circle. Every problem people have with those services are other peoples problems or just an unavoidable reality.
- I’m uninteresting for people in power. I don’t know them, so they don’t know me and since I’m not significant they could not care about me.
- The app of the grocery chain is made to give me benefits and to enable me to save money.
- I don’t want protestors to be protected. I want them to shut up, so we can have peace.

Yes, to be confronted with such a naive view of the world is frustrating. Still these are people I have to share a communication platform with and they build the core of the society I live in.

Those are the people I have to convince to make a change. So here are the arguments that help:

- Information about people propagated by data brokers and ad companies will be used by criminals to run automated attack campaigns targeting those people. You will be attacked because you are an easy mark, not because of any interest in you. Reduce the amount of data collected to lower your exposure to criminals.
- You don’t have to suffer through all these adds. You can have a faster and cleaner internet experience.
- I’m on Signal, Matrix and XMPP. If you want to communicate with me, you have to use one of those services call on phone.

The reason I’m discussing the issue here is the following. If I peak a persons interest for privacy protection and they try to find information on their own, they will encounter the “enemy of the state“ attitude pretty fast. That will be off putting to them, because that is not what they want to be and those are not the people they want to associate with.

---

## Post 39 by @gasull — 2026-04-13T11:23:00Z

Telegram doesn’t have E2EE by default. You can enable it, but only on the phone, and it’s hidden behind UI dark patterns.

The Telegram app is just a wrapper for a website. When you chat on it, you’re posting on a website.
