Robin
← All writing

August 31, 2024

How secure is Telegram, really?

With Telegram's CEO arrested in France, I got curious: how secure is Telegram, really? Let's unpack the tech behind those "private" chats.

Telegram's chat types

When you start a new chat on Telegram, here's what you get by default:

  • Regular private messages
  • Group chats
  • Channels

None of these are end-to-end encrypted. To get true end-to-end encryption, you have to manually choose a Secret Chat — and that's only available for one-on-one conversations.

Most users never switch to Secret Chats. Here's why that matters.

Two encryption methods

Default encryption — what most people use:

  • Uses MTProto, Telegram's custom protocol
  • Messages are encrypted... but Telegram holds the keys
  • Telegram can read your messages if they want to

Secret Chats encryption:

  • Uses MTProto 2.0
  • True end-to-end encryption
  • Only you and the recipient hold the keys
  • Telegram can't read these messages

The takeaway: unless you're actively using Secret Chats, your Telegram messages aren't really private.

So what's wrong with server-side encryption? It's still encryption, right?

The problem with default encryption

With Telegram's default, messages are encrypted between you and Telegram's servers — but Telegram holds the keys. That means:

  • Telegram can decrypt and read your messages at any time
  • Your privacy relies on trusting Telegram won't abuse that access

Compare that to true end-to-end encryption, where even the service provider can't read your messages. Your chats are private, period.

Bottom line: with Telegram's default, you're trusting them with your privacy. With true E2E, you don't have to trust anyone.

Why this matters

  1. Government requests — Telegram could be compelled to hand over your messages. With true E2E, that wouldn't be possible.
  2. Data breaches — if attackers breach Telegram's servers, your chats could be exposed. E2E would protect you even if the servers were compromised.
  3. Trust — you're betting Telegram won't misuse your data. Why take that risk when other apps offer real privacy?

The big question: do you trust Telegram with your private conversations? Let's look at the alternatives.

How other messaging apps compare

Signal

  • Open-source protocol built by cryptographer Moxie Marlinspike
  • The protocol behind WhatsApp, Messenger's secret conversations, and Google's encrypted RCS
  • E2E by default for all chats
  • Minimizes metadata collection
  • Run by a non-profit focused on privacy

WhatsApp

  • Uses the Signal Protocol for E2E
  • E2E by default since 2016
  • Owned by Meta, which raises some trust concerns

iMessage

  • Apple's proprietary E2E encryption
  • E2E by default since 2011
  • Limited to Apple devices

The key point: these apps use E2E by default, unlike Telegram. But remember — even with E2E, apps may still collect metadata (who you talk to, when, and so on). That's a privacy concern of its own.

Conclusion

Telegram's security isn't as straightforward as it seems:

  • Default chats aren't truly private
  • Only Secret Chats offer real E2E encryption
  • Other major apps (Signal, WhatsApp, iMessage) use E2E by default

About that arrest

Pavel Durov faces charges in France for failure to moderate illegal content, with allegations around the hosting of drug trafficking, child sexual abuse material, and fraud on the platform.

The case highlights the complex balance between user privacy and platform accountability. It also raises hard questions: how much access should governments have to our communications? Can strong encryption coexist with effective moderation?

What now?

  • Check your Telegram settings — are you using Secret Chats when it matters?
  • Consider alternatives like Signal for sensitive conversations
  • Stay informed about the privacy policies of the apps you use

Sources