August 31, 2024
How secure is Telegram, really?
With Telegram's CEO arrested in France, I got curious: how secure is Telegram, really? Let's unpack the tech behind those "private" chats.
Telegram's chat types
When you start a new chat on Telegram, here's what you get by default:
- Regular private messages
- Group chats
- Channels
None of these are end-to-end encrypted. To get true end-to-end encryption, you have to manually choose a Secret Chat — and that's only available for one-on-one conversations.
Most users never switch to Secret Chats. Here's why that matters.
Two encryption methods
Default encryption — what most people use:
- Uses MTProto, Telegram's custom protocol
- Messages are encrypted... but Telegram holds the keys
- Telegram can read your messages if they want to
Secret Chats encryption:
- Uses MTProto 2.0
- True end-to-end encryption
- Only you and the recipient hold the keys
- Telegram can't read these messages
The takeaway: unless you're actively using Secret Chats, your Telegram messages aren't really private.
So what's wrong with server-side encryption? It's still encryption, right?
The problem with default encryption
With Telegram's default, messages are encrypted between you and Telegram's servers — but Telegram holds the keys. That means:
- Telegram can decrypt and read your messages at any time
- Your privacy relies on trusting Telegram won't abuse that access
Compare that to true end-to-end encryption, where even the service provider can't read your messages. Your chats are private, period.
Bottom line: with Telegram's default, you're trusting them with your privacy. With true E2E, you don't have to trust anyone.
Why this matters
- Government requests — Telegram could be compelled to hand over your messages. With true E2E, that wouldn't be possible.
- Data breaches — if attackers breach Telegram's servers, your chats could be exposed. E2E would protect you even if the servers were compromised.
- Trust — you're betting Telegram won't misuse your data. Why take that risk when other apps offer real privacy?
The big question: do you trust Telegram with your private conversations? Let's look at the alternatives.
How other messaging apps compare
Signal
- Open-source protocol built by cryptographer Moxie Marlinspike
- The protocol behind WhatsApp, Messenger's secret conversations, and Google's encrypted RCS
- E2E by default for all chats
- Minimizes metadata collection
- Run by a non-profit focused on privacy
- Uses the Signal Protocol for E2E
- E2E by default since 2016
- Owned by Meta, which raises some trust concerns
iMessage
- Apple's proprietary E2E encryption
- E2E by default since 2011
- Limited to Apple devices
The key point: these apps use E2E by default, unlike Telegram. But remember — even with E2E, apps may still collect metadata (who you talk to, when, and so on). That's a privacy concern of its own.
Conclusion
Telegram's security isn't as straightforward as it seems:
- Default chats aren't truly private
- Only Secret Chats offer real E2E encryption
- Other major apps (Signal, WhatsApp, iMessage) use E2E by default
About that arrest
Pavel Durov faces charges in France for failure to moderate illegal content, with allegations around the hosting of drug trafficking, child sexual abuse material, and fraud on the platform.
The case highlights the complex balance between user privacy and platform accountability. It also raises hard questions: how much access should governments have to our communications? Can strong encryption coexist with effective moderation?
What now?
- Check your Telegram settings — are you using Secret Chats when it matters?
- Consider alternatives like Signal for sensitive conversations
- Stay informed about the privacy policies of the apps you use
Sources
- Is Telegram really an encrypted messaging app? — a detailed technical breakdown by a cryptography expert
- Telegram's CEO has taken a hands-off approach for years — now his luck might have run out — an in-depth look at Durov's arrest and Telegram's moderation challenges
- Can Tech Executives Be Held Responsible for What Happens on Their Platforms? — the legal implications of holding tech CEOs accountable for platform content