You are reading a single comment by @Greenbank and its replies. Click here to read the full conversation.
  • Depends who "them" is?

    It's generally thought of to be secure (but hard to verify this).

    One thing for sure, if you use the Web interface then it's pretty safe to assume that the UK Government has access to the private key of their HTTPS Cert, and so all traffic to/from that site would be readable.

    I'd trust [EDIT] Telegram Signal a lot more than Whatsapp.

    [EDIT] Just for starters, Whatsapp is end-to-end encrypted, but:

    • It doesn't tell you how many endpoints you are sending each message to, so it could be sending every message to a collection endpoint that is gathering info
    • It doesn't tell you when a new endpoint is added for any existing messages (such as when you use Whatsapp on the web)
    • Even if it did it may lie and not tell you about the "other" endpoints
    • It doesn't easily allow you to confirm each endpoint is who they say they are, there's a "verify" feature if you see that contact in person, but the UX on it is terrible
    • You can't see the source for the phone app, even if you could there would be no way to verify that that is the source that your phone app was built from
  • I'd trust Telegram a lot more than Whatsapp.

    Why not Signal? Less Russian, less Meta, more open source. Or, are you using Telegram as a known-suboptimal system that is still better than WhatsApp?

  • So the whatsapp mobile app will decrypt messages and send them to whatsapp web in paintext (albeit over TLS)?

    Didn't know that :/

  • I'd trust Telegram a lot more than Whatsapp

    Well there's a hot take.

    Telegram rolled their own encryption and screwed it up, more than once. Still don't have verified encryption in place, most cryptographers believe that there's is a bit odd - looks fine, but the oddities are reason to be concerned.

    The only messenger with anything is Signal.

    But even I'll admit it doesn't have many users compared to WhatsApp or Telegram.

    Signal is the only one that cryptographers, government officials, journalists, and other either super paranoid or high risk, actually trust.

About

Avatar for Greenbank @Greenbank started