• Andromxda 🇺🇦🇵🇸🇹🇼@lemmy.dbzer0.comOP
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    2 days ago

    Telegram literally stores all your messages, metadata, etc. in plain text on their servers. This means that it provides considerably worse security than even proprietary messengers, such as WhatsApp and Facebook Messenger. Telegram has an option for encrypted chats, but it’s not available for groups, lacks support for voice and video calls, and Telegram deliberately goes out of their way to make the experience of using encrypted chats as painful as possible.

    You’re even better off using WhatsApp, but if you actually want a good messenger, switch to Signal. It’s free and open source (both the clients and the backend server), developed by a nonprofit organization, and it’s basically the gold standard for encrypted communications.

        • herseycokguzelolacak@lemmy.ml
          link
          fedilink
          arrow-up
          1
          ·
          16 hours ago

          Just above you said “You’re even better off using WhatsApp”.

          I will use Signal if Signal devs get over their hate of F-Droid.

          • Andromxda 🇺🇦🇵🇸🇹🇼@lemmy.dbzer0.comOP
            link
            fedilink
            English
            arrow-up
            1
            ·
            15 hours ago

            You’re better off using WhatsApp compared to Telegram, but that’s a very low bar, and it absolutely doesn’t mean that anyone should use WhatsApp. Signal, Threema, Wire and SimpleX are far better options. I prefer Signal, because it’s very easy to use, the UI/UX is basically the exact same as on WhatsApp. It’s also free, unlike Threema, and uses either phone numbers or user names as identifiers, unlike SimpleX, which requires you to share a QR code. Signal is also the most popular of these messengers, so there’s a larger chance that someone is already using it.

            As for F-Droid: It’s not a good way of distributing such privacy/security-relevant apps like Signal. F-Droid doesn’t have certificate checks built in, thus the APK could easily be modified without the user ever noticing. Again, I don’t like Google, but you’re better off downloading Signal from the Play Store. The best option is to use Obtainium and automatically fetch the latest version of the Signal APK directly from their website https://signal.org/android/apk/ That way, you’re at least getting the app from an official source, built and signed by the Signal developers, not a random third party.

            You can use AppVerifier to verify the integrity of the downloaded app aginast the certificate fingerprint on the website.