An FBI document lays out the information various secure messaging apps can share with law enforcement.

Surprisingly Telegram awfully good on that list

Edit: I forgot to add that I found something little of about that report where Signal hash to phone numbers are absent " Which clearly signal store it"! And on Threema FBI still includ it even though it’s optional and 99℅ of the user will not put their number.

I cannot see the files/pictures (no js). I think they are referring to this. I also found a pdf version.

I imagine this is the reason we’re constantly told not to use Telegram. US has no control over the app or the servers, and none of US agencies were involved in development of its encryption protocols.

Governments never give shit to matrix.org protocol, does that mean it’s worse than telegram?

Dessalines
link
fedilink
42Y

The graphic doesn’t show matrix or xmpp, probably because there isn’t much they can do about them, especially if they aren’t hosted in the US.

As far as I know Matrix is sound. Probably just isn’t as big as Telegram yet.

Halce
link
fedilink
62Y

I find it dubious for Telegram to be the most private of them all, since their encryption protocol is not disclosed, but hey…

poVoq
link
fedilink
122Y

The Telegram app is open-source and the encryption algorithm as well. The problem is that it uses an totally non-standard in-house developed encryption algorithm that security researchers are suspicious off (but no actual vulnerabilities are known right now).

@brombek@lemmy.ml
link
fedilink
4
edit-2
2Y

They are finding problems like “crime-pizza”:

https://ethz.ch/en/news-and-events/eth-news/news/2021/07/four-cryptographic-vulnerabilities-in-telegram.html

Nothing super serious though so far… depending on your definition though :)

So Apple is the worst privacy, surprise, surprise! And Telegram is the best (of the worst, in US), but how knows what KGB can see :D

except iOS warns you that enabling icloud backup for whatsapp is a terrible idea. whatsapp is really just terrible all around, because you don’t know if the user you’re talking to does have backups enabled. it’s like relying on PGP, you have no idea if it’s being used on the other end, so, might as well not treat email as something secure.

If your backups are accessible to others then you have no privacy no matter what tools you use, it is the ultimate back door. Same as running “scanners” client side.

I’ve been using Session lately. Not sure how it stands up on the technical merits.

Jedrax
link
fedilink
32Y

Actually a super informational list. I’m glad they made it unclassified, can only help the masses.

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 14 users / day
  • 18 users / week
  • 24 users / month
  • 15 users / 6 months
  • 20 subscribers
  • 619 Posts
  • 1.56K Comments
  • Modlog