Unlike WhatsApp, criticized for data‑sharing practices, Telegram keeps its promises. But the privacy of your data depends solely on Telegram's own goodwill. After Telegram began moving away from some of its original principles promised to users, compliance with other principles also begins to be questioned.
Just as there is a claim about Signal being unsafe on iPhone, we are entitled to assume there may be an insufficient level of security for our Telegram messages, since we cannot independently audit this.
To clarify what kinds of encryption we are even talking about, consider this list:
- Telegram (Secret Chats): DH
- Signal: X3DH
- TON Blockchain: ECDH
Notice the similarity? Exactly.
Diffie–Hellman (DH) is a cryptographic key‑exchange protocol. On top of it, X3DH and ECDH were developed to improve security.
We chose to adapt PQXDH for our needs.
By this we mean that messengers use protocols from the same family.
But none of them meet all the rules of end-to-end encrypted chats.
We respect and value Pavel Durov's fight for free speech, so we believe our personal chats on Telegram's servers are kept safe.
But trust alone is not enough to prove that this is actually the case.
Secret Chats are limited in functionality. Private groups and channels still lack E2E encryption.
Back to the original problem, which is simple in essence: how to make cloud backups safe?
Our solution is to store private keys on the server in encrypted form.
At the user's discretion this option can be disabled, in which case access to a chat remains on a single device.
The robustness of this approach is comparable to the security of encrypted transaction comments in the TON Blockchain.
We have tried in this post to stick to facts, but please verify them independently. If you spot any error, you can notify us by tapping the "chat" button below.
We decided to create not just another messenger, but a messenger that truly adheres to these principles. If we say a messenger is private, it means it has end-to-end encryption for all chat types, open source, reproducible build and synchronization between devices with cross-platform client support.
This isn't the only reason, but it's a basic one.
Users shouldn't be misled.
Users should have privacy.
Post #25
176