But think about this: if everything are only encrypted in-transit, then for what purpose does the decryption key have if it’s not going to decrypt anything since “all data are stored unencrypted”? And how do you know that server-client only applies in-transit only? All data are encrypted in-transit, yes, but how can you know that the data are not encrypted at-rest (you know, on the server)? Only Pavel + his team knows and since he is very open on how Telegram is working, he wrote the following in January this year:

It took us a few years to create the technology to instantly sync encrypted data between our datacenters and to encrypt local storage in each of them in a way that would make breaking into any data-center and seizing servers useless.

Source: https://t.me/durovschat/544164

MTProto aren’t open sourced so we can’t verify who between you and me are speaking the truth (or even Pavel himself for that matter), but I do trust Pavel after reading a lot of his texts. Hopefully Pavel will release the source code of MTProto once the Russian government are more humane (or something like that) (source).

Telegram do encrypt group chats! And please, focus on the post in hand.

Telegram encrypts everything by default (groups included), so I don’t find that article trustworthy. They say bounch of things without linking to the sources of the claims. I trust Telegram more than an article that almost saying that Telegram are lying to their users with no evidence to support their claims.

MTProto are not open sourced yet, so where is the proof that Telegram only encrypt your data in transit? Show me evidence about this from a trustworthy source that also includes sources and I will be sceptic.

My proofs: https://telegram.org/faq#q-so-how-do-you-encrypt-data https://telegram.org/faq#q-do-you-process-data-requests

If Signal now are fully E2EE where nothing is logged, not even metadatas, then why do Signal use Firebase?

Oh, I know what Google Firebase are. Maybe you don’t know what Firebase are?

“This includes things like analytics, authentication, databases, configuration, file storage, push messaging, and the list goes on. The services are hosted in the cloud, and scale with little to no effort on the part of the developer.” Source: https://medium.com/firebase-developers/what-is-firebase-the-complete-story-abridged-bcc730c5f2c0

Well. What do you expect when you use a service that are based in USA, have closed their source code (or have they re-opened it again?), are using mainly Google as a server provider, and have zero privacy regarding your phone number (which are visible for everyone who see you within the app and you can’t do anything about it… today)?

Alright. Now I understand the title :) And I totally agree with you, but Windows 7 do contain spyware too (source), since Microsoft have added spyware techniques since Windows XP Service Pack 2 (what I’ve heard). If you want to use a operating system with less/no spywares, I would recommend Linux Mint Cinnamon as a start.

