this post was submitted on 05 Dec 2024
176 points (97.8% liked)
Cybersecurity
5834 readers
196 users here now
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
- Be respectful. Everyone should feel welcome here.
- No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
- No Ads / Spamming.
- No pornography.
Community Rules
- Idk, keep it semi-professional?
- Nothing illegal. We're all ethical here.
- Rules will be added/redefined as necessary.
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub
Notable mention to !cybersecuritymemes@lemmy.world
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Yeah that's cool and all but you're strawmanning. Your original comment, that I hear parroted a lot, is that Telegram is (basically) unencrypted, and regardless of your feelings about the suitability of MTProto (not SSL) that's patently untrue.
There's no evidence that MTProto has ever been cracked, nor any evidence of them selling or allowing anyone access to their servers and recent headline news backs this up. Whether you choose to trust them with your data is up to the individual to decide. I'm just tired of seeing the "Telegram is unencrypted" claim in every instant messaging thread, made by people who don't know or care to know the difference between encryption and E2E encryption.
Google, on the other hand, routinely allow "agencies" access to their servers, often without a warrant, and WhatsApp - who you cite as a good example of E2E encryption - stores chat backups on GDrive unencrypted by default. They added the option to encrypt last year but nobody was forced (or possibly even asked?) to turn it on, and to this day no encryption of backups is still the default. And while you might encrypt your backups, can you be sure the same is true for the people on the other end of your chats?
The entire point is that you shouldn't have to put your trust that a third party (Telegram or whoever takes over in the future) will not sell/allow access to your already accessible data.
Just because it's not happening now does not mean it cannot happen in the future. If/when they do get compromised/sold, they will already have your data; it's completely out of your control.
Exactly my point. Google are using the exact same "security" as Telegram. Your data is already compromised. Side note - supposedly RCS chats between Android is E2EE although I wouldn't trust it as, like Telegram, you're mixing high/low security context, which is bad OPSEC.
Valid concern, but this threat exists on almost every single platform. Who's to stop anyone from taking screenshots of all your messages and not storing them securely?
[1] https://www.tomsguide.com/news/whatsapp-encrypted-backups