@Hyolobrika @kravietz @feld
Not what you ask for, but my reason not to trust it:
https://social.librem.one/@m0xee/112529843691683740
No hard proof, it's only indirect, but after that PR-stunt campaign of attempting to block it and failing to do so, Telegram is one IM that I, being Russian, trust the least.
@feld
Yes, I'm aware of presence leak in multi-user rooms, I think this existed for years — would be great if they fixed that, but I'm not really concerned as I'm not using them 🤷
@Hyolobrika @feld
They are, but whom would it leak the status to in this case? There is your server and the server the other party is on — both are already aware of your presence 😆
The way I understand it, it sends out your status to all participants of group chats even to the sessions that no one verified explicitly or implicitly — if one of the participants is compromised, it could be used to track when you go online.
@Hyolobrika @feld
The problem was already blown out of proportion as it is, but in case with 1 on 1 chats it's not even relevant.
Besides, I think they have already implemented a "sort of" fix for that: "Never send encrypted messages to unverified sessions in this room from this session" in room settings is just that, but it's not perfect as you have to enable it for each of your sessions individually.
@Hyolobrika @kravietz @feld
To be fair — I don't trust Signal either, anything that uses phone numbers is a hard pass in my book as I can never trust cell carrier in Russia.
But double-ratchet that was pioneered in Signal was adopted in Matrix, XMPP with OMEMO and plethora of other messengers, there is no reason to use Signal itself 🤷