Hi :) I know that Telegram is not save and not a good messenger if you are a privacy-geek. Sadly some parts of my family still think so. I brougth up the arguments, that they are cooperating with Russia, that they or closed-source on the server-side and that e2ee is not on by default and only available for 1-on-1 chats.

My question now is, if you gals and guys might have some other arguments or sources I could use.

I don’t want to convince anyone to switch away from Telegram (because I am no missionary :D) I just want people to understand the risks of using Telegram.

  • @kitnaht
    link
    6
    edit-2
    5 days ago

    How about: Signal is better? Though, they recently were caught with some unencrypted shit on the desktop client.

      • @Zak
        link
        85 days ago

        Lemmy thread and link.

        Basically, anyone who can read your home directory could decrypt your Signal database. That’s about typical of traditional desktop applications, but questionable for security-oriented software. Mac OS and (sometimes) Linux have more robust credential management options, and Signal signaled (yes, pun intended) its intent to adopt them.

        • @[email protected]
          link
          fedilink
          135 days ago

          I feel that if someone can read your home directory, signal isn’t your worst worry. However, it’s still an issue and I’m glad they’re going to move to better security.

          • @Zak
            link
            35 days ago

            I’m inclined to agree, and said so in the linked thread.

    • @[email protected]
      link
      fedilink
      55 days ago

      Caught? It was like kinda obvious. You could always locate your Signal folder where everything is downloaded and just see all pictures…

      I ignored this flaw as I kept my PC Luks encrypted, but a friend on Windows might not, where everyone with physical access could read everything.

      So, yeah. I also dislike the idea that its not encrypted in some sort of way.

    • Possibly linux
      link
      fedilink
      English
      35 days ago

      The messages in the desktop client aren’t encrypted. However, someone would need access to your machine to get them

      • @[email protected]
        link
        fedilink
        25 days ago

        Also, if the data were encrypted, the encryption key would have been on the Computer anyway, but yes it could have been better protected.

        • Possibly linux
          link
          fedilink
          English
          14 days ago

          Technically they could require a password. However, people would forget it