Comment by crossroadsguy
11 hours ago
One of the challenges with Telegram is - they regularly re-enable settings inside the app/account that you had specifically disabled. So at any point you don't know what is happening and what is not. Meaning, even if you didn't see a thing, a malicious file might be sitting all warm and fuzzy on your computer - among possible other things. I used to like the snappiness of this app (and it is still snappier than almost all other IM apps combined, by a margin), but after a while I realised it was a ticking time-bomb (to keep it installed on the desktop) and possibly a scammer safe haven, nothing else.
A lot of companies do this but I always get a ton of hate for saying this: Telegram is the worst offender I've seen. If you start digging through their apps, you see a ton of security practices that are anything but secure. And one of the hundreds of reasons I treat Telegram as the plague: get it away from me and burn it with fire.
I've never seen a legit good hearted person ever use Telegram. It's usually what grifters and scammers prefer to use. Or Signal.
My family uses it to communicate on devices that don't support iMessage (mainly Windows and Linux installs) because it's one of the precious few cross-platform messengers that doesn't treat desktop users as second class or as an afterthought.
Signal is legit. The entire stack is open source, and messages are E2EE.
Telegram is connected to Eastern European and the Middle Eastern countries and not in a good way, and the server-side components are closed source. There is no E2EE by default.
1 reply →
There's a few communities that use Telegram because it seems to be one of the few that is both generally usable by the average person and by default has at least a little respect for separating your online identity from your real life identity. Which is sad because I agree it's a bit of a dumpster fire when it comes to security and privacy beyond that.
Counterpoint: I have. Although Telegram is less popular in the US. I try to get all my friends using Signal.
I prefer to keep the contents of my message secure from the panopticon.
> Or Signal
It's kind of hard to hash out what you're saying here
There's at least millions of such persons
> I've never seen a legit good hearted person ever use Telegram. It's usually what grifters and scammers prefer to use. Or Signal.
TIL I'm not a legit good hearted person.
Guess I'll remove myself from the organ donation registry.
All big companies pull these kind of tricks. Another variation is to retire the old setting and introduce a new one with a deceptive name that is default on again.
Can you please tell me what settings get auto re-enabled? I use Telegram as my primary messenger app. I just want to make a more informed decision if I should switch to Signal or something.
>if I should switch to Signal or something.
Yes
https://news.ycombinator.com/item?id=48923935
Note there’s no info on that page on which settings get reenabled, only general list of grievances with telegram, mainly from a privacy/security perspective.
1 reply →
You absolutely should use Signal instead.
Is not Signal inferior? In Telegram you can communicate with strangers without disclosing a phone number, in Western messengers until recently you had to disclose it so that your contacts can conveniently find you and punch you in the face if you are a man or just annoy you with indecent messages if you are a woman (probably not scary in a country where everyone has a gun and every home is a castle, but not all world is like this). What Western genius thought of such a feature, displaying a phone number in a group chat?
Telegram also allows to delete any chat in one click. Telegram has support for HTTP, SOCKS, MTPROTO and WEB proxies to evade censorship, Western messengers do not. Telegram is written in C++. Although it is a piece of proprietary garbage and might be connected to the government, at least it is well made piece.
Also it became difficult to register in Telegram, it often asks for 1 euro when trying to register with a fake number. And with a real number the OTP code simply doesn't get delivered to Russia.
1 reply →
This hasn’t happened to me absolutely ever in 10+ years.
In the distant past this meant more. Vendors shipped one option for everyone. Now with things like A/B testing and other application 'smart' behavior which ends up meaning we all have different experiences.
Presumably the risk is mitigated somewhat with the Flatpak version (`org.telegram.desktop`)?
Flatpak has "classic mode" which means no sandbox, which you will never guess if you did not read the docs, because why tell the users the truth when you can use marketing speak. Also, Flatpak allows reading identifiers from /proc and /sys.
Not on Linux. But if that is a safe variant then yeah great. Also, I see https://flatpak.org (is this the one you meant?) has Telegram has one of the showcases apps on the homepage so I guess they would have done their due dilligence.
For example?