Many people who focus on information security, including myself, have
long considered
Telegram suspicious and untrustworthy.
Now, based on findings
published by the investigative journalism outlet ISt
Hi, author here. First of all, in that piece I don’t happen to recommend using any specific piece of software. I mention Signal and WhatsApp for comparison, as tools that are considered similar, and yet avoid making the same weird protocol choices.
Secondly, if you have any proof that any specific communication tool is used to “spy” on people, I am sure I am not the only person who would love to hear about it. That’s the only way we can keep each other safe online. Surely you wouldn’t be making unsubstantiated claims and just imply stuff like that without any proof, would you?
And finally, I’ve spent a good chunk of time and expertise on analyzing Telegram’s protocol before I made my claims. I provided receipts. I provided code. I explained in detail my testing set-up. You can yourself go and verify my results.
Instead, you claim it’s “propaganda”, while mischaracterizing what I say in that post. Classy!
I can’t say I read the whole thing because the technical analysis went over my head, but I don’t think we read the same conclusion
Conclusions
Based on the analysis of packet captures above, I believe it is clear that anyone who has sufficient visibility into Telegram’s traffic would be able to identify and track traffic of specific user devices. Including when perfect forward secrecy protocol feature is in use.
This would also allow, through some additional analysis based on timing and packet sizes, to potentially identify who is communicating with whom using Telegram.
Hahaha , so the conclusión is ? Use usa and israel software so they can spy us ? F… this crap propaganda.
Hi, author here. First of all, in that piece I don’t happen to recommend using any specific piece of software. I mention Signal and WhatsApp for comparison, as tools that are considered similar, and yet avoid making the same weird protocol choices.
Secondly, if you have any proof that any specific communication tool is used to “spy” on people, I am sure I am not the only person who would love to hear about it. That’s the only way we can keep each other safe online. Surely you wouldn’t be making unsubstantiated claims and just imply stuff like that without any proof, would you?
And finally, I’ve spent a good chunk of time and expertise on analyzing Telegram’s protocol before I made my claims. I provided receipts. I provided code. I explained in detail my testing set-up. You can yourself go and verify my results.
Instead, you claim it’s “propaganda”, while mischaracterizing what I say in that post. Classy!
I can’t say I read the whole thing because the technical analysis went over my head, but I don’t think we read the same conclusion
Based on the analysis of packet captures above, I believe it is clear that anyone who has sufficient visibility into Telegram’s traffic would be able to identify and track traffic of specific user devices. Including when perfect forward secrecy protocol feature is in use.
This would also allow, through some additional analysis based on timing and packet sizes, to potentially identify who is communicating with whom using Telegram.
fr it’s literally
But I can’t lie the analysis is still quite in-depth and feels like an effortpost