rysiek,
@rysiek@mstdn.social avatar

Here we go again:

Telegram’s peer-to-peer SMS login service is a privacy nightmare
https://techcrunch.com/2024/03/25/telegrams-peer-to-peer-sms-login-service-is-a-privacy-nightmare/

sigh

Stop using . Seriously.

Telegram uses confusing language to pretend it is end-to-end encrypted by default. It is not — you have to enable that separately for each chat, and it only works for one-on-ones, not groups.

Telegram's protocol design is sus af (that's a technical term), and that's putting real people in real danger:
https://www.pwnallthethings.com/p/russia-is-spying-on-telegram-chats

rysiek,
@rysiek@mstdn.social avatar

I know your community might be there. I know this might not be easy. I feel your pain, and I know it's not as simple as "just move".

But even so, making an effort to move off of it, suggesting something else to your different contacts, trying to move specific groups to a different messenger is worthwhile. With time, you might find your whole network has moved.

Every new person on Telegram is a new reason for someone to join or stay there.

Every person that leaves Telegram is one reason fewer.

rysiek,
@rysiek@mstdn.social avatar

We — the people using platforms — are not the reason many of them are user-hostile, privacy-invading, outright dangerous or otherwise bad.

If blame is to be placed anywhere, it's on people who have agency in how a given platform is developed and run. In case of Telegram, that's Durov and his team.

But that doesn't mean we do not have any responsibility regarding which platform's network effects we boost by our presence and activity, and which we deny that kind of a boost. :blobcatcoffee:

Frisk,

@rysiek Well said. I left Telegram a long time ago mostly for privacy concerns (if I remember correctly). Now I made a promise to do the same with Discord, and it's extremely difficult.
There are communities which I'll have to leave as a result, some connections will be lost. But at the end I feel like it's the right thing to do. For myself especially, but in a way also for the others.

rysiek,
@rysiek@mstdn.social avatar

@Frisk it's not easy. I quit :birdsite: cold turkey in January 2013 (not a typo). Lost a lot of connections. The important ones though — we found each other, gradually.

Not everyone is in a position to do that, and that's important to recognize.

KatS,
@KatS@chaosfem.tw avatar

@rysiek Are they still using that hand-rolled, proprietary "trust me bro, it's secure" encryption protocol?

Asking because that was my reason for never touching it in the first place.

rysiek,
@rysiek@mstdn.social avatar

@KatS yes.

slothrop,
@slothrop@chaos.social avatar

deleted_by_author

  • Loading...
  • rysiek,
    @rysiek@mstdn.social avatar

    @slothrop do it!

    slothrop,
    @slothrop@chaos.social avatar

    deleted_by_author

  • Loading...
  • rysiek,
    @rysiek@mstdn.social avatar

    @slothrop

    ***** yeah ok
    **** fffffiiine
    *** meh
    ** sus af

    • nope

    :ablobwink:

    slothrop,
    @slothrop@chaos.social avatar

    deleted_by_author

  • Loading...
  • Vergil,

    @rysiek unrelated: sent you a follow request. Was on h.town (drskrzyk) in another life

    rysiek,
    @rysiek@mstdn.social avatar

    @Vergil I don't see it anywhere

    wolf480pl,
    @wolf480pl@mstdn.io avatar

    @rysiek what do you recommend people use instead?

    rysiek,
    @rysiek@mstdn.social avatar

    @wolf480pl I don't want to recommend specific tools, because use-cases and needs and threat models differ. And I don't want this to devolve into a thread about nit-picking each and every option.

    Personally, I use @signalapp a lot. That fits my needs well, though I would have preferred it to be decentralized. Can't win them all all the time.

    I know what I will definitely stay away from though: Telegram, Viber, Session IM; anything touting blockchain; anything where e2ee is not the default.

    xarvos,
    @xarvos@outerheaven.club avatar

    @rysiek @wolf480pl @signalapp wait, i thought session was a signal’s fork, both of which involves with its own cryptocoin? or did i confuse it with something else?

    rysiek,
    @rysiek@mstdn.social avatar

    @xarvos you confused it with Molly I think. I do use Molly, in fact.

    @signalapp @wolf480pl

    Powerfromspace1,
    @Powerfromspace1@mstdn.social avatar

    @rysiek Crikey 🙄

  • All
  • Subscribed
  • Moderated
  • Favorites
  • telegram
  • DreamBathrooms
  • ngwrru68w68
  • osvaldo12
  • magazineikmin
  • tacticalgear
  • rosin
  • thenastyranch
  • Youngstown
  • khanakhh
  • slotface
  • mdbf
  • kavyap
  • InstantRegret
  • GTA5RPClips
  • JUstTest
  • Durango
  • cubers
  • modclub
  • cisconetworking
  • tester
  • everett
  • ethstaker
  • Leos
  • anitta
  • normalnudes
  • provamag3
  • megavids
  • lostlight
  • All magazines