@ddnomad@infosec.pub avatar

ddnomad

@ddnomad@infosec.pub

Terminal stage of console

This profile is from a federated server and may be incomplete. Browse more on the original instance.

ddnomad,
@ddnomad@infosec.pub avatar

Telegram’s servers are located in US, Singapore, Netherlands (and maybe some other countries) from what I’ve gathered. And all chats that are not E2EE’ed are stored there, encrypted at rest at best with keys in the same database, or somewhere else that can still be accessed in automated way. Maybe it is not even encrypted at rest.

The point is, all those countries are either in 5 eyes or have information sharing agreements with 5 eyes countries. So as far as I’m concerned, TLAs can still have their fingers in those pies, in addition to Telegram’s overall shadiness and Russian ties. So maybe you get KGB strongman keeping a watch over your chats too.

This is not something I’d have much confidence in to be honest.

ddnomad,
@ddnomad@infosec.pub avatar

And E2EE is only available on phones, circa a couple of years ago anyways

ddnomad, (edited )
@ddnomad@infosec.pub avatar

Switch to Telegram

You know it’s not even E2EE by default, and when it is it uses a homegrown algo that is not exactly well spoken of? (at least V1)

  • All
  • Subscribed
  • Moderated
  • Favorites
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #