Investigation by investigative journalism outlet IStories (EN version by OCCRP) shows that Telegram uses a single, FSB-linked company as their infrastructure provider globally.

Telegram’s MTProto protocol also requires a cleartext identifier to be prepended to all client-server messages.

Combined, these two choices by Telegram make it into a surveillance tool.

I am quoted in the IStories story. I also did packet captures, and I dive into the nitty-gritty technical details on my blog.

Packet captures and MTProto deobfuscation library I wrote linked therein so that others can retrace my steps and check my work.

      • rysiek@szmer.infoOP
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        18 days ago

        I would most definitely not recommend Matrix for private or sensitive communication, no.

        https://soatok.blog/2024/07/31/what-does-it-mean-to-be-a-signal-competitor/
        https://soatok.blog/2024/08/14/security-issues-in-matrixs-olm-library/

        Matrix is fine as IRC replacement, it might also be a decent replacement for Telegram’s channels thingy, sure. But I would not trust my family photos to it. Much less anything actually important.

        • arsCynic@beehaw.org
          link
          fedilink
          arrow-up
          0
          ·
          edit-2
          18 days ago

          I would most definitely not recommend Matrix for private or sensitive communication, no.
          https://soatok.blog/2024/07/31/what-does-it-mean-to-be-a-signal-competitor/
          https://soatok.blog/2024/08/14/security-issues-in-matrixs-olm-library/
          Matrix is fine as IRC replacement, it might also be a decent replacement for Telegram’s channels thingy, sure. But I would not trust my family photos to it. Much less anything actually important.

          Regarding Soatok, I am prone to completely ignore impolite individuals. As far as my experience goes, and for most of the general populace, Matrix is fine. And it is likely to continue improving. Compared to Signal and Telegram, who both incentivize crypto"currencies", a.k.a. tech bro multi-level marketing pyramid schemes, enshittification has already begun.

          Roy says: August 6, 2024 at 4:28 pm
          Interesting post! I would be really interested in knowing your opinion on SimpleX Chat.

          Soatok says: August 6, 2024 at 4:55 pm
          See, this is exactly the fucking problem. I never invited anyone to query me to look at YET ANOTHER fucking chat app. Yet this still keeps happening. Doing security reviews is labor. You’re asking me to work for free to satisfy your curiosity. This is annoying to do. I don’t have a fucking opinion about SimpleX. I don’t have an opinion about a lot of apps. If I want to share my opinion, I’ll blog about it WITHOUT being prompted. Until then, please stop asking.
          By Post Author

          • rysiek@szmer.infoOP
            link
            fedilink
            arrow-up
            1
            ·
            edit-2
            18 days ago

            Regarding Soatok, I am prone to completely ignore impolite individuals.

            Please feel free to ignore me as well then, because saying that technical analysis by an expert can be outright ignored just because the expert happened to be impolite that one time might make me become somewhat impolite.

            Imagine getting dozens of randos in your replies asking about dozens of random chat apps. At some point I am pretty sure you’d also reach a breaking point. Some would call that kind of behaviour a bit impolite, I’d wager.

        • Avatar of Vengeance@lemmy.ml
          link
          fedilink
          English
          arrow-up
          0
          arrow-down
          1
          ·
          15 days ago

          That guy again lmao why do “security researchers” keep recommending signal with that softheaded blog. Get real