Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I can't open the telegram.com links, blocked at work :/

But the Arxiv paper says:

"We stress that peer clients never communicate directly: messages always go through a server, where they are stored to permit later retrieval by the recipient. Cloud chat messages are kept in clear text, while secret chat messages are encrypted with the peers’ session key, which should be unknown to the server."

So it doesn't appear to be encrypted-at-rest, but without reading the telegram documentation I can't verify that.



Yeah that feels pretty cut and dry. But even if it was encrypted at rest, it sounds like the server has the key to everything anyway so it’s not E2E.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: