What does it mean privacy nowadays? #2 Telegram, Whatsapp and Signal.

in GEMS5 years ago

Some days ago, I found out that telegram is less privacy oriented than WhatsApp. I thought it was a bulls*it. Or a fake news. Or whatever. How is that even possible, the same company kicked out by Russia for not have provided their key of encryption? But then I discovered this studied conducted by the University of Massachusetts. However, we should make acquaintance with another word:

Encryption

I was waiting for this moment, A LOT.
OK, think about a letter that you want to send to your girlfriend/boyfriend or whoever. As you might know a letter usually contains a message.

photo_20200603_093933.jpg

If we send a message with no encryption, we basically give our letter open directly in the hand of a post mail man. We are not sure if this employee is reliable and might found out that your bf/gf is a cheater.

postman3095678_640.jpg

If we use encryption, we put this message into a lockbox. So, the post mail man is not able to read it. Or is he? Let me explain you a little difference. In this case the post mail person is the same person who provides you the lockbox. And you don’t know if he has the key. STAY CALM AND DON’T DESPERATE.
Some post mail men had created another method:
When you send a message you put all the information in the lockbox, you closed it and you keep one key. The receiver (so called ex bf/gf) has the other key (totally different) but this other key fits perfectly in the hole and so does your. MAGICAL, isn’t it? and change every time you send a message. The post mail man cannot see in the lockbox because he provides the keys, but they are randomically generated and like infinite. This is called End-to-end encryption.


I will massively quote, so please be aware I AM NOT STEALING, just be aware: Soooo, let me go back to my first assumption. WhatsApp is using a protocol called signal protocol, which is one of the most reliable encryption protocols. https://www.signal.org/docs/. And telegram utilizes another protocol way less secure. You’ll find out everything in the link below. https://courses.csail.mit.edu/6.857/2017/project/19.pdf

“Telegram’s end-to-end encryption feature is not enabled by default on the application. For this reason, lots of the users who don’t have enough expertise on security/encryption end up using the Telegram without ’secret chat’ feature thinking their messages are encrypted. Without secret chats, the users have to trust Telegram servers.”

“Telegram uses a home-grown cryptographic protocol called MTProto, a decision which has been heavily criticized; common security doc-trine dictates that developers should never ”roll their own” crypto, and should leave cryptographic protocol design to the experts. Those who have examined the protocol themselves have also come away skeptical; cryptographer Matt Green commented that

”Telegram is ten million rube gold bergian moving parts, all put there to support a single, unau-thenticated Diffie-Hellman key exchange”

“Telegram initially asks for the contact list from the phone/desktop and stores them in their servers. This provides huge social network information for them that either be attacked on their servers or can be possibly sold to different authorities without users’ consent. This is another case when the users have to trust Telegram with their data.”

Except for privacy chats and call, your messages also the stuff that you used to save into Telegram’s folder are not protected as people think. Which is weird. It is also weird that Whatsapp has a higher encryption protocol (Whatsapp has other issues such as unencrypted backups, unencrypted web app. You made sure that the travel was safe but then burglars break into your house without you even realize it). Damn. So, unless you modified the way the chat between you and your mate is encrypted (options-->secret chat. How many people seriously do this operation every time except when they send their nudes?), people like telegram’s developers can see you chats and maybe sell to the best seller. I am just guessing. Ah also, no encryption for telegram groups.
So, remember that your data are unsafe, even if you found a very worthful channel that show you the best deal on amazon. Also stay away from software that doesn’t want to be ENTIRELY OPEN SOURCE.
What’s the best option?

Probably there’s no better option than Signal .

Signal_ultramarine_icon.png

We said before Whatsapp's encryption is made by Signal, but what is Signal? It is an instant messaging application, so you can send text, images, video and audio-messages plus the right of making calls and video-calls. The software is totally opensource, so check it out!

https://github.com/signalapp