Advertisement

Here’s why you should leave WhatsApp for Signal, not Telegram

When WhatsApp updated its privacy policy to allow it to share its users’ data with Facebook, which bought WhatsApp in 2014, users began abandoning the platform for Telegram and Signal.

While this update doesn’t affect EU and UK users, those in the US, Australia, Asia, etc. will be forced to agree to this new data sharing or lose access to WhatsApp on February 8.

Telegram reported that 25 million people joined its service in just 72 hours, bringing its total active users to half a billion.

Signal has also seen a huge boost in numbers. After Elon Musk tweeted “Use Signal” – which Edward Snowden retweeted – the app has seen a huge boost in new users as well, becoming the number one downloaded app on iOS.

Snowden went further, claiming “I use it every day and I’m not dead yet.”

But for those who are considering leaving WhatsApp, what is the better choice: Signal or Telegram? Our recent research into secure messaging apps is conclusive: Signal has better privacy and security features out of the box than Telegram does

Signal vs. Telegram

In order to assess the privacy and security aspects of Signal and Telegram, we looked at the various technical aspects of these secure messaging apps.

Here are the results:

Signal

Telegram

Platforms

Windows, Android, iOS, macOS, Linux

Windows, Android, iOS, macOS, Linux

Default security?

Secure by default

Not secure by default

Transfer protocols

Https/SIP over WebSockets

Https/SIP over WebSockets

Encryption used

Signal protocol (X3DH + Double ratchet + AES-256)

MTProto 2.0 (AES-256, AES IGE IV 256)

Keys-Exchange & Cryptographic primitives

Pre-keys + Curve25519, HMAC-SHA256

Persistent shared key generated via DH, KDF, Double SHA-256

As you can see, both platforms are matched in most aspects, with the biggest variety in the encryption they use and their keys exchange and cryptographic primitives. These platforms used variations of RSA and AES for encryption and key hashes – which are some of the most secure encryption algorithms available today.

But the biggest reason that Signal beats Telegram is that Telegram is not secure by default.

To be fair: this is not to say that Telegram as a product lacks security in any major way, but rather that Telegram doesn’t provide its important features out of the box.

This feature is the crucial end-to-end encryption that, bizarrely, WhatsApp uses by default.  In end-to-end encryption, only the sender and the receiver is able to view the messages. Without end-to-end encryption, the messaging app server that sits between the sender and receiver might be able to read the messages.

This means that, if the user is using the app out of the box, without changing the settings, they’d still have more protections on WhatsApp than they would on Telegram. This is bad, of course, since one study showed that roughly 5% of people changed their settings in a given app, while the other 95% kept the default settings.

While we can’t be sure how that number looks for Telegram specifically, we also have to assume that most people are not as privacy- and security-minded as we’d all like. Telegram has at least 500 million active users now, and its end-to-end encrypted messages feature, called Secret Chat, is most likely glossed over by most of its users.

Signal and Telegram’s history of vulnerabilities

There are of course many good reasons why people should be abandoning WhatsApp for more secure messaging apps. One of those reasons is that WhatsApp has had many more critical vulnerabilities than either Signal or Telegram.

For example, there’s the time when attackers were able to install Israeli spyware on a target’s phone by simply calling them through WhatsApp.

While not as bad, Signal has had its fair share of problems too: it was victim to a rather complex attack where someone could listen in on your surroundings by making a sort of ghost call – calling you through Signal and then pressing mute without the call being seen, to eavesdrop on your conversations.

Telegram for its part had a vulnerability where attackers could replace audio and image files sent on its platform.

And that’s not to mention access to these apps for the government which, depending on where you are in the world, could be a problem. In Hong Kong, a Telegram bug was reportedly exploited by the Chinese government to leak users’ phone numbers. German researchers also discovered that WhatsApp, Signal and Telegram were exposing users’ personal data via contact discovery.

But let’s be level-headed here: every single app or program or website you’re using will have its vulnerabilities or bugs, and that’s an inescapable fact.

However, the major takeaway here is this:

  1. Signal and Telegram, as alternatives to WhatsApp, will both have various vulnerabilities
  2. If you have end-to-end encryption, those vulnerabilities can be mitigated
  3. All else being equal, because most people are likely to keep the default settings, most people will be better off with Signal

Of course, if you’re more of a Telegram person than a Signal person, this is easily fixable: use only Secret Chats on Telegram.

On iOS, simply open the profile of the user you want to contact. Tap on ‘…’, then “Start Secret Chat.” For Android, you should tap on the pencil icon on the bottom right, then select “Secret chat.” Unfortunately, you’ll have to do this on a conversation-by-conversation basis.

Here’s why you should leave WhatsApp for Signal, not Telegram

Bernard Meyer is the Senior Researcher at CyberNews.

Bernard focuses his investigations on popular online tools that can impact users’ privacy and/or security. This includes mobile apps, as well as desktop programs and online services. He also writes editorials on significant news events of the day related to cybersecurity.

With four years’ experience in the fields of online tech and cybersecurity, Bernard has helped uncover significant online privacy and security issues affecting companies like PayPal, Tesco, Hotels.com, Santander and more. His work has been featured in Wired, Fortune, Forbes, The Telegraph, Express, Daily Mirror, Lifehacker and more.

When Bernard is not investigating online tools, he’s working on the perfect roast pork or canepes. Either that, or he’s busy thinking of further places to travel, having spent two years in Asia, including Taiwan and Mongolia. He is a firm believer in modern civil rights and works to empower marginalized communities in the STEM fields.

Please scroll down for comment(s) on this publication.
You may have to read this publication again; you may click here to see why.

Other very interesting publications are further below. Kindly share this publication, and scroll down for readers' comments and / or to comment...
Advertisement
Specially selected items from our online shop

Here’s why you should leave WhatsApp for Signal, not Telegram

DISCLAIMER

This publication was culled. And only uploaded to this platform, by…

David K Egyir

David K Egyir

EGYIR is passionate about helping serious people like you to escape the most dangerous — common but avoidable — problem most people (rich, poor, educated, uneducated, religious, and non-religious alike) face in life. Also, he designs and builds beautiful, cost-effective and functional buildings, and graphics. And he helps executives, marketers, and business owners to make effective presentations; what you may call winning presentations. He is an Architect, a Designer, and a Life Coach. And an Entrepreneur. Especially as a life-coach, he has been popularly adjudged the best coach for excelling in education, increasing wealth, eliminating stress, and enjoying true fulfillment in life! Egyir understands life thoroughly and shares amazingly liberating insights from a uniquely empowering perspective. He has a firm conviction that, “The greatest tragedy in life is that majority of people have accepted to be less than they were born to be and are thus accomplishing far less than their true capabilities.” To that end, he authored (wrote) Purpose Compass, the exceptional life-coaching book that reveals 4 habits that are currently making your life difficult, or otherwise may soon make your life difficult, but which your parent, teacher, or pastor would dare not talk about; how to escape them and get to live a stress-free life of purpose faster! And 13 other equally amazing books that constitute the Zing4Life! Series. Egyir is also lead promoter of the electronic, trendy and amazing Smart Business Card, the only business card you’ll ever need, for the executive in you! He is a husband, and a father of two. Positionally, he is the Lead Founder and CEO of Seers, Associate of Arthro Synergeio, Lay Preacher of The Methodist Church Ghana, Global Lead Advocate of Zing4Life! and Volunteer Mentor with iMentor Ghana. To see more about him you may click here. #WeAreSeers | To get in touch with Egyir or to follow him on social media you may click here. #EgyirGuidesDaily | To support his writing & life-coaching social ministry you may click here. #SeersFoundation | To be part of Egyir's live sessions online at 20.30 GMT on Sundays you may click here. #TimeWithSeers |

Here’s why you should leave WhatsApp for Signal, not Telegram

To comment you first have to log in below…

Leave a Reply

You may click the button below to send a message

Publications that are in the same category as the one above...

#SeersVoice

Most recent publications from our community members...

Provide the applicable details below and click the ‘Subscribe‘ button; that’s it. By the way, it’s FREE! And we do not spam; also, you can easily unsubscribe anytime…

We truly respect your privacy; you may click here to see our privacy policy

Already registered? Log in to dismiss this invite.
Not sure what registration is about? Click here.

Advertisement

Here’s why you should leave WhatsApp for Signal, not Telegram