Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Except does it even have reasonable end to end encryption?


What I hear from others if that it isn't up to par with encryption standards that Signal and WhatsApp use since Telegram rolls their own. Also, you have to explicitly start a e2e chat with a given person, otherwise it's through, and stored in, Telegram servers.


No if you believe vague handwaving.

Yes if you see they have an open bounty


Regardless of how their encryption is done, if you reregister your phone number you get an sms and you’re in and the complete message history is decrypted. So clearly they have all the keys, otherwise they couldn’t send it to you. Practically it’s not end to end encrypted.

Note that this is the same with many services that claim encryption, for instance Apple.


Does apple have the keys or does iMessage just resend as a regular text if you deregister? End to end means only the two parties involved have the keys period.


For Apple this is with their iCloud backups, storage etc. If you lose the password and your devices it can still be reset.


Well I can't remember specifics but I seem to recall somebody pointing to the flaws of their open bounty that it had very specific rules like not MITM'ing someone or something along those lines. Good end to end encryption shouldn't be able to be MITM'd is the thing.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: