Many don't seem to understand why I object to @Telegram having unsafe, censorable public channels in an app that is promoted as a secure messenger. Some presumed I just don't understand how channels work. So let's talk about it:
236
2,739
351
6,217
Background: @Telegram has a special position in Iran. Its "public channels" are an important source of news for many low-tech users. Competing services are often blocked, but Telegram makes concessions to avoid this (like setting up local CDNs iranhumanrights.org/2017/07/… ).
29
440
19
1,041
This is both a good and bad thing. On one hand, keeping people who don't understand and will never learn what Tor and VPNs connected to a big and difficult-to-moderate communications ecosystem is valuable, when the government largely has but two moves: "block" or "not block."
21
245
4
769
On the other, it means @Telegram will face increasing pressure over time to collaborate with the Iranian government's demands for this or that. Today we saw the communications minister demand a big channel be shut down. And here's where we start getting into complexity.
30
269
7
847
Should Telegram shut one Iranian channel down to preserve access to all the others? Most would say "of course." It's more important to keep that tether to their ecosystem alive, right? They're in something close to a monopoly position, where the fallback for many is unsafe SMS.
25
245
7
756
If we presume @Durov is acting morally, this might sound like an argument for Telegram to do whatever they can to keep their Iranian presence alive. But this is unsustainable, which he should know: after all, he was forced from Russia for not doing enough favors at Vkontakte.
21
239
6
795
You can't keep an independent, destabilizing service from being blocked in authoritarian regimes, you can only delay it. So you need to be thinking about how to continuing protecting people by making the service accessible *even after the block.*
46
461
39
1,402
And this is where we start getting to my core concerns. @Telegram has for years faced criticisms about the basic structure of its security by prominent cryptographers and technologists. Many defenses rely upon unbroken trust in a central authority (the company). "Trust us."
17
245
9
773
Trust us not to turn over data. Trust us not to read your messages. Trust us not to close your channel. Maybe @Durov is an angel. I hope so! But angels have fallen before. Telegram should have been working to make channels decentralized—meaning outside their control—for years.
47
383
32
1,282
We've seen some improvements, and that's not nothing. But not the revolutionary rework it needs. Telegram still seems to encourage dangerous cloud messaging instead of secret chats. Experts ask "why?" And the answer is "convenience." That's unsafe.

9:21 PM · Dec 30, 2017

23
231
4
732
Governments are becoming more abusive, not less, on the internet, especially in places like Iran, China, and Russia. @Durov said @Telegram has 25,000,000 daily users in Iran. He could be converting them all to 2FA. He could be teaching them how to use Tor bridges. I hope he will.
49
481
33
1,480
Governments learn slowly, but they do learn. There comes a day when it will be too late to fix these problems, and I fear it is sooner than we think.
50
439
15
1,479
Replying to @Snowden
I'm so keen to hear your safety tips. First, go to Moscow. Second - ?
1
0
0
0
Replying to @Snowden
You're not going to talk your way out of this one. You've exposed yourself
0
0
0
0
Replying to @Snowden
Too much convenience leads to apathy and greater userbase. Telegram clearly chose the latter. For people are are serious about #privacy there's BSD and GNU/Linux with PGP.
1
1
0
3
yeah but you can't fully separate yourself from society, and telegram is a nice bridge until there is a better solution that is adapted by the public
1
0
0
1
Replying to @Snowden
Amazon has proved that Americans will happily give up their privacy in exchange for convenience.
0
0
0
1
Replying to @Snowden
That's the difference. We have many really secure apps with almost no users. We have a few really insecure apps with many users. And Telegram is trying to offer these insecure users a similar user experience, but more securely. And that is very important.
0
0
0
0
Replying to @Snowden
What can we do !? Tell us
0
0
0
0