Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> (and I doubt that one-on-one encrypted communication --it's a setting you MUST turn on-- in Telegram is actually really E2EE).

Secret Chats in telegram really is E2EE.

It is just a bit clumsy to use because it offers quite good protections. Because of it, it only works between two people and on one device of each participant. They also must be online at the same time for the key exchange/generation protocol to work. This makes it a hassle and nobody uses it. But what is there does meet the requirements of E2EE even more so than WhatApp or Signal where for example an extra party can be added to an encrypted chat. The police have used this feature to snoop in Germany: https://cybernews.com/privacy/police-telegram-whatsapp-signa...

With Telegram Secret Chats they wouldn't be able to do this. On the other hand, because it's so clumsy nobody uses it and thus people use the much worse off alternative of no E2EE at all in the regular Telegram which the police have also monitored. So it's arguable that whatsapp/signal's compromise was a good one. If you put up too many hurdles in security the people will stop using it.

But I wouldn't call Telegram's secret chats "not real E2EE".

 help



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: