Skip to main content
The 2024 Developer Survey results are live! See the results

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

25
  • 35
    Reiterates lots of the criticism, but so far I have yet to hear a non-theoretical vulnerability. Can anyone read encrypted messages as they go over the wire, change contents without the other party noticing (even if the attacker doesn't know what the decrypted output will be), or spoof the sender? If not, I don't see a problem with this self-designed protocol. All protocols have been designed by one team or another at some point.
    – Luc
    Commented Apr 5, 2014 at 16:27
  • 84
    @Luc I really wish I can downvote comments. Really? Non-standard crypto doesn't make you nervous? Do you want to encourage people to use crypto protocols without strong theoretical foundations? What happens when adoption reaches critical mass and a serious vulnerability is found? Yes, protocols need to be designed by people. But the people designing them should be trained cryptographers and the protocol needs to be peer reviewed by other trained cryptographers.
    – user10211
    Commented Apr 5, 2014 at 16:39
  • 25
    Using Cryptocat as an security exemplar is actually quite dangerous. It has a very controversial history, and lots of well known security professionals think it's actually dangerous. So, please remove that from your answer. You should also mention that Moxie worked for OpenWhisper. And that OpenWhisper don't have a usable iOS client.
    – anu
    Commented May 21, 2014 at 14:36
  • 31
    An update would be nice. Telegram responded to the linked blogs and it looks like a lot of accusations were based on an out-dated documentation or misunderstanding of it. They also adjusted rules for their hacking contest. Therefore this answer seems deprecated to me. Commented Aug 18, 2014 at 11:54
  • 26
    Just found out that EFF has given 7/7 of it's secure messaging checklist to Telegram secret chat eff.org/secure-messaging-scorecard
    – Bibhas
    Commented Mar 13, 2015 at 11:34