Telegram responds to WhatsApp allegations

Telegram spokesperson Remi Vaughn reached out to us to refute claims made by Wired and WhatsApp head Will Cathcart about the security of the popular chat app. Wired’s article contained many errors, Vaughn said, and the editorial team ignored her comments and responses from Telegram, misleading Cathcart.

Telegram compiled a list of nine errors in a Wired article. It can be found at telegra.ph (a minimal public tool by Telegram). The post ends with “This list is being expanded”.

This post addresses various claims in the Wired article, including those regarding location tracking. This is only possible if the user explicitly publishes their location and only 0.01% of her users do this and write Telegram.


Visualization of the MTProto 2.0 protocol

Visualization of the MTProto 2.0 protocol

Regarding private chat privacy, Vaughn points out that Cathcart is wrong about Telegram’s End To End Encryption (E2EE) protocol not being independently verified. A team from the University of Udine in Italy validated his MTProto 2.0 protocol, which Telegram uses to secure chats. The paper can be viewed here (PDF).

Note that this is a protocol validation, not a specific implementation. However, Telegram’s app is open source and uses reproducible builds since version 5.13. A “reproducible build” is one that compiles the publicly available source code and the resulting machine code is identical to that hosted on the Apple App Store, Google Play Store, and Telegram’s own website. It means that you can check Telegram servers are not open source, but the Udine team has also verified the MTProto 2.0 protocol in the presence of malicious servers.

They point to one problem that can compromise the security of secret chats. When initiating a secret chat, it is important that the user verifies the fingerprint of the authentication key through a secure external channel. Otherwise, man-in-the-middle attacks are possible (that is, a third party can eavesdrop on the message and possibly even modify it). Researchers point out that such user errors can also occur when using the Signal app.


Creating secret chats and verifying encryption keys
Creating secret chats and verifying encryption keys
Creating secret chats and verifying encryption keys

Creating secret chats and verifying encryption keys

Always check your fingerprints properly when using any of the apps. A secret chat isn’t completely secret until you actually do it, and you can’t use the same chat or other insecure chats to verify that your fingerprints match.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *