NEW – Telegram has released user data to the Federal Criminal Police Office of Germany in several cases, Spiegel reports.
The NGO CeMAS monitors 3,000 German-language channels & groups for "disinformation, antisemitism, and right-wing extremism."https://t.co/ib75xumI7L
— Disclose.tv (@disclosetv) June 4, 2022
Bad news!
Turns out, Telegram was just letting everyone post what they wanted so the intelligence establishment could monitor them!
Telegram was never secure @moxie has been warning about Telegram storing data in plain text for a long time. @signalapp is secure
— 0xAnon (@kumatomoon) June 4, 2022
It’s amazing to me that after all this time, almost all media coverage of Telegram still refers to it as an “encrypted messenger.”
Telegram has a lot of compelling features, but in terms of privacy and data collection, there is no worse choice. Here’s how it actually works:
1/
— Moxie Marlinspike (@moxie) December 23, 2021
Telegram stores all your contacts, groups, media, and every message you’ve ever sent or received in plaintext on their servers. The app on your phone is just a “view” onto their servers, where the data actually lives.
Almost everything you see in the app, Telegram also sees
2/
— Moxie Marlinspike (@moxie) December 23, 2021
Here’s a simple test: delete Telegram, install it on a brand new phone, and register with your number. You will immediately see all your conversation history, all of your contacts, all the media you’ve shared, all of your groups. How? It was all on their servers, in plaintext
3/
— Moxie Marlinspike (@moxie) December 23, 2021
The confusion is that Telegram does allow you to create very limited “secret chats” (no groups, synchronous, no sync) that nominally do use e2ee, even if the security of the e2ee protocol they use is dubious.
There’s no e2ee by default, but they talk about it like there is
4/
— Moxie Marlinspike (@moxie) December 23, 2021
FB Messenger also has an e2ee “secret chat” mode that is actually much less limited than Telegram’s (and also uses a better e2ee protocol), but nobody would consider Messenger to be an “encrypted messenger.”
FB Messenger and Telegram are built almost exactly the same way.
5/
— Moxie Marlinspike (@moxie) December 23, 2021
Some may feel okay letting Telegram have access to all of their data, msgs, images, contacts, groups, etc. because they “trust Telegram.”
However, the point of an “encrypted messenger” should be that you don’t have to trust anyone other than the ppl you’re communicating with
6/
— Moxie Marlinspike (@moxie) December 23, 2021
Actual privacy tech is not about trusting someone else w/ your data. It’s about not having to. A msg you send should only be visible to you & recipient. A group’s details should only be vis to the other members. Looking up your contacts should not reveal them to anyone else.
7/
— Moxie Marlinspike (@moxie) December 23, 2021
Privacy tech is really about making the tech consistent with the UI. But if Telegram’s UI were consistent with the way the tech worked, every chat would be a group chat with everyone that works at Telegram + everyone that hacks Telegram + every gov that accesses Telegram, etc
8/
— Moxie Marlinspike (@moxie) December 23, 2021
For the folks writing about this space, my request is that when you write “encrypted messenger,” it should at *minimum* mean an app where all messages are e2ee by default. Telegram and FB Messenger are built exactly the same way. Neither are “encrypted messengers.”
9/
— Moxie Marlinspike (@moxie) December 23, 2021
Well.
We told you not to use your real phone number or IP address on Telegram.
Hope you listened, because if they’re giving this data to the Germans, they’re giving it to everyone.
I’m not even saying “don’t use Telegram ever.” I understand why people use it. It does have a whole lot more information than any other social media – while also requiring your phone number. Frankly, the phone number is a lot more damning than the IP address, though you should hide both.
— Komotor 🔞 (@Kom_Anim) June 4, 2022
They can just spin it that not vaccinating toddlers is child abuse and that anything opposing the government is terrorism.
— Alæx B (@AlexBfromG) June 4, 2022
So much for a secure messaging app
— Sheldon Riedel (@SheldonRiedel) June 4, 2022
So, just right wing extremism, no left wing extremism? lol
— JLV (@CeltsnPats) June 4, 2022
“antisemitism” pic.twitter.com/6ftyMIqfd1
— 𝙗𝙖𝙨𝙚𝙙 🔋 (@basedinmatrix) June 4, 2022