Cointime

Download App
iOS & Android

Telegram's Pavel Durov is wrong about Signal — and has been for years

Validated Media

Telegram founder Pavel Durov put the encrypted messaging application Signal on blast this month, arguing in a May 8 post that its privacy mechanisms amounted to a “circus trick.” His commentary was purpose-built to undermine the rival messaging app, but Durov’s history with Signal and Telegram's own privacy credentials make it hard to take his comments seriously.

Durov has been throwing stones at Signal for years. In 2017, he predicted we'd find a backdoor in their protocol within five years. Seven years later, that prediction has missed the mark. A few years later, Signal founder Moxie Marlinspike posted a thread suggesting we should stop calling Telegram an encrypted messaging app.

Signal and Telegram do not like each other.

Pavel Durov took aim at Signal in a May 8 post. Source: Telegram

In the context of historical beef between the two products, this latest post looks more like an opportunistic potshot at a market competitor than a legitimate PSA about backdoored software.

Malice in the messaging apps

Signal was already under heavy scrutiny after comments made by Signal Foundation Chair Katherine Maher, who said Wikipedia's "free and open" nature promoted a "white male Westernized construct." It was a story that received a lot of traction on social media, and drew comments from Jack Dorsey, Vitalik Buterin, and Elon Musk on X.

As people picked up their pitchforks over Maher's politics, it was all too easy for Durov to redirect the angry mob toward Signal itself.

Signal got to work dispelling the claims about their app and protocol, with President Meredith Whittaker providing important context in the replies to throw some ice on the story.

Signal Foundation President Meredith Whittaker addressed the controversy involving Maher in a May 8 post on X. Source: X

For now, things have settled down. However, this beef isn't over — if anything, it's just getting started. This row has the potential to become cybersecurity's version of Kendrick v. Drake.

The anti-Signal movement

It was easy to whip people into a frenzy about Signal. There's an anti-Signal undercurrent emerging in certain circles — a surprising sensitivity for one of the most respected messaging apps in the world.

Perhaps it started when ex-Fox News anchor Tucker Carlson appeared on Lex Fridman's Podcast earlier this year. Speaking about messaging security, Carlson said, "we all have theories about secure communications channels. Like Signal is secure, Telegraph [sic] isn't, or WhatsApp, [which] is owned by Mark Zuckerberg — you can't trust it."

In the same conversation, Carlson claimed the NSA managed to obtain and Signal messages related to his efforts to interview Russian President Vladimir Putin and subsequently leak them to the media. This may have planted the original seed of doubt, and it certainly feels like the precursor to the latest controversy.

Connecting some dots, Carlson sat down for an interview with Pavel Durov back in April. One month later, Durov's post to Du Rove's Channel said key figures had revealed to him that their "private" Signal messages had been exploited."

In case you aren't a natural Sherlock, Carlson is one of the "important people" Durov is talking about. Building from these claims, Durov says Telegram provides "the only popular method of communication that is verifiably private."

Telegram has always tried to hang with the encrypted messaging crowd, but Telegram is not a suitable Signal alternative. Telegram doesn't have end-to-end encryption by default and it doesn't have end-to-end encrypted group chats at all. Having opt-in privacy features — especially necessities like end-to-end encryption — means the vast majority of users will be left without protection.

But none of this will stop Durov from amplifying people's doubts about Signal to give Telegram a leg-up. Further conflict is likely. (Wouldn't it be nice if we could all just get along?)

As for this round of the bout, it's notable that Signal hasn't backed up Maher's comments. Their line is that Maher's politics don't really matter — you don't need to trust the people running Signal, you just need to trust the code.

It's a good line to take. With highly audited, open source code, Signal has a relatively trustless model. Maher's politics have no bearing on a PQXDH key exchange. But a decentralized model could be more trustless — and it already exists.

The anti-Signal movement 

I work on an end-to-end encrypted messaging app called Session. It runs on a decentralized network operated by ordinary community members who contribute compute resources to route and store messages.

Not only is the client and server code open source, you can verify the open source code is what's actually running on the network — you can join and run it yourself. Session does what it says on the box, no trust required whatsoever.

However, this is not a cure-all. The quirks of a decentralized network make it difficult to pull off the complex key ratcheting involved in the Signal Protocol. This ratcheting provides unique cryptographic properties, but keeping key-states updated doesn't mix with a decentralized network of community nodes which can enter and leave the network at will.

If you remove encryption entirely, you can have an awesome UX like Telegram's, where messages appear instantly as though they're rabbits out hats.

There's always a trade off. Nobody has it all — and if they say they do, they've probably got something to sell you.

Comments

All Comments

Recommended for you

  • Putin: Russia "supports" Harris, calls her smile "contagious"

    According to foreign media such as TASS and Russia's Sputnik News, Jinse Finance reported that on the afternoon of September 5th local time, Russian President Putin said at the plenary session of the Eastern Economic Forum 2024 that Russia will "support" the US Democratic Party presidential candidate and vice president Harris as recommended by the US President Biden in the upcoming US presidential election. When asked how he viewed the 2024 US election, Putin said it was the choice of the American people. The new US president will be elected by the American people, and Russia will respect the choice of the American people. Putin also said that just as Biden suggested his supporters to support Harris, "we will do the same, we will support her." The report said that Putin also joked that Harris' laughter is "expressive and infectious," which shows that "she is doing everything well." He added that this may mean that she will avoid further sanctions against Russia.

  • An ETH whale repurchased 5,153 ETH with 12.23 million USDT 20 minutes ago

    A certain high-frequency trading ETH whale monitored by on-chain analyst Yu Jin bought 5,153 ETH with 12.23 million USDT 20 minutes ago.

  • CFTC: Uniswap Labs has actively cooperated with the investigation and only needs to pay a fine of US$175,000

    The CFTC has filed a lawsuit against Uniswap Labs and reached a settlement. It was found that Uniswap Labs illegally provided leveraged or margined retail commodity transactions of digital assets through a decentralized digital asset trading protocol. Uniswap Labs was required to pay a civil penalty of $175,000 and cease violations of the Commodity Exchange Act (CEA). The CFTC acknowledged that Uniswap Labs actively cooperated with law enforcement agencies in the investigation and reduced the civil penalty.

  • Federal Reserve Beige Book: Respondents generally expect economic activity to remain stable or improve

    The Federal Reserve's Beige Book pointed out that economic activity in three regions has slightly increased, while the number of regions reporting flat or declining economic activity has increased from five in the previous quarter to nine in this quarter. Overall employment levels remain stable, although some reports indicate that companies are only filling necessary positions, reducing working hours and shifts, or reducing overall employment levels through natural attrition. However, reports of layoffs are still rare. Generally speaking, wage growth is moderate, and the growth rate of labor input costs and sales prices ranges from slight to moderate. Consumer spending has declined in most regions, while in the previous reporting period, consumer spending remained stable overall.

  • Puffpaw Completes $6 Million Seed Round with Lemniscap Ventures as Participant

    Puffpaw has announced the completion of a $6 million seed round of financing, with participation from Lemniscap Ventures. The Puffpaw project plans to launch a blockchain-enabled electronic cigarette aimed at helping users reduce nicotine intake through token incentives. The project encourages users to quit smoking by recording their smoking habits and rewarding them with tokens. Puffpaw's token economics aims to cover 30% of the cost of users' first month of using their product and provide social rewards. The project also considers possible system abuse, but the issue of users potentially reporting smoking habits dishonestly is not yet clear.

  • Affected by Ethervista and others, Ethereum Gas temporarily rose to 33gwei

    According to Etherscan, due to the influence of contracts such as Ethervista, Ethereum Gas has temporarily risen to 33gwei, with the top three being EthervistaRouter, UniswapRouter, and BananaGun.

  • The probability of the Fed cutting interest rates by 25 basis points in September is 55%.

    The probability of the Federal Reserve cutting interest rates by 25 basis points in September is 55.0%, while the probability of a 50 basis point cut is 45.0%. The probability of the Federal Reserve cutting interest rates by a cumulative 50 basis points by November is 32.1%, by 75 basis points is 49.2%, and by 100 basis points is 18.8%.

  • Deep-Dive into Move-based Blockchains

    Move is a new programming language for smart contract development. Originating from Facebook’s discontinued Diem and Novi projects, Move aims to revolutionize smart contract development by addressing the limitations of existing languages like Solidity – used for the EVM – and Rust – found in alternative L1 ecosystems such as Solana and Near. Move’s design philosophy focuses on improving security and enhancing developer experience. This approach aims to make smart contract development not only safer and more efficient but also more accessible to developers outside of the crypto space.

  • Ethereum centralization: a single builder accounts for over half of August blocks

    One of the many goals of the 2022 Ethereum Merge was to make Ethereum more decentralized. From a validator perspective, it’s not doing badly. Statistics show Coinbase is the largest, controlling almost 12% of staked ETH (although some claim it’s closer to 30%). However, validators don’t create the content of the blocks. Block builders are the ones who include transactions, decide on their order and then bid in the auction to get their block included. This month a single block builder, Beaverbuild, has built more than half of Ethereum’s blocks.

  • Ethereum discv5 DHT Network Health Weekly Reports

    The ProbeLab team has developed and deployed infrastructure to monitor several critical metrics for Ethereum’s CL discv5 DHT network. In particular, we have adapted the Nebula crawler (GitHub - dennis-tra/nebula: 🌌 A network agnostic DHT crawler, monitor, and measurement tool that exposes timely information about DHT networks.) to be compatible with discv5-based networks and are gathering results that reflect the health of the P2P network at the DHT level.