Comment on Telegram says it has 'about 30 engineers'; security experts say that's a red flag

frezik@midwest.social ⁨4⁩ ⁨months⁩ ago

Headline is terrible. The big red flags are that they don’t do end-to-end encryption by default, the servers are in Dubai, and use a proprietary algorithm.

Last part should be clarified further. They didn’t reinvent AES or anything. It’s more like a protocol that puts together existing algorithms. It means they can use transport layers without TLS or anything else that wraps your messages in crypto otherwise.

core.telegram.org/mtproto

I’d still say this is a red flag. How you wrap encryption around your messages has several pits you can fall into. It’s not as bad as reinventing AES, though.

source
Sort:hotnewtop