{"id":107133,"date":"2024-06-24T20:04:02","date_gmt":"2024-06-24T20:04:02","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2024\/06\/24\/telegram-says-it-has-about-30-engineers-security-experts-say-thats-not-good-techcrunch\/"},"modified":"2024-06-24T20:04:02","modified_gmt":"2024-06-24T20:04:02","slug":"telegram-says-it-has-about-30-engineers-security-experts-say-thats-not-good-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2024\/06\/24\/telegram-says-it-has-about-30-engineers-security-experts-say-thats-not-good-techcrunch\/","title":{"rendered":"Telegram says it has &#8216;about 30 engineers&#8217;; security experts say that&#8217;s . . . not good | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Over the weekend, a clip from a recent interview with <a href=\"https:\/\/techcrunch.com\/tag\/telegram\/\" target=\"_blank\" rel=\"noopener\">Telegram\u2019s<\/a> founder <a href=\"https:\/\/techcrunch.com\/tag\/pavel-durov\/\" target=\"_blank\" rel=\"noopener\">Pavel Durov<\/a> went semi-viral on X (previously Twitter). <a href=\"https:\/\/x.com\/trungtphan\/status\/1780794237426323918?s=51&amp;t=lLf2YRXhv7kG_Tw6dp_nCA\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">In the video<\/a>, Durov tells right-wing personality Tucker Carlson that he is the only product manager at the company, and that he only employs \u201cabout 30 engineers.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Security experts say that while Durov was bragging about his Dubai-based company being \u201csuper efficient,\u201d what he said was actually a red flag for users.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWithout end-to-end encryption, huge numbers of vulnerable targets, and servers located in the UAE? Seems like that would be a security nightmare,\u201d Matthew Green, a cryptography expert at Johns Hopkins University, told TechCrunch.<\/p>\n<p class=\"wp-block-paragraph\">Green was referring to the fact that \u2014 by default \u2014 chats on Telegram are not end-to-end encrypted like they are on Signal or WhatsApp. A Telegram user has to start a \u201cSecret Chat\u201d to switch on end-to-end encryption, making the messages unreadable to Telegram or anyone other than the intended recipient. Also, over the years, many people have cast doubt over the quality of Telegram\u2019s encryption, given that the company uses its own proprietary encryption algorithm, created by Durov\u2019s brother, as he said in an extended version of the Carlson interview.\u00a0\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Eva Galperin, the director of cybersecurity at the Electronic Frontier Foundation and a longtime expert in the security of at-risk users, said that it\u2019s important to remember that Telegram, unlike Signal, is a lot more than just a messaging app.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhat makes Telegram different (and much worse!) is that Telegram is not just a messaging app, it is also a social media platform. As a social media platform, it is sitting on an enormous amount of user data. Indeed, it is sitting on the contents of all communications that are not one-on-one messages that have been specifically [end-to-end] encrypted,\u201d Galperin told TechCrunch. \u201c\u2018Thirty engineers\u2019 means that there is no one to fight legal requests, there is no infrastructure for dealing with abuse and content moderation issues.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cAnd I would even argue that the quality of those 30 engineers isn\u2019t that great,\u201d Galperin continued. \u201cAlso, if I was a threat actor, I would definitely consider this to be encouraging news. Every attacker loves a profoundly understaffed and overworked opponent.\u201d<\/p>\n<p class=\"wp-block-paragraph\">In other words, it\u2019s unlikely for Telegram to be very effective fighting hackers, especially government-backed ones, with such a small staff.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Lemme guess, none of these 30 staff include privacy or compliance people, and zero third-party audit is ever done to review potential security controls restricting access to users&#8217; data. &#8220;Please trust us&#8221; is not how security works. <a rel=\"nofollow\" href=\"https:\/\/t.co\/w7PBkU0TJR\" target=\"_blank\">https:\/\/t.co\/w7PBkU0TJR<\/a><\/p>\n<p>\u2014 JP Aumasson (@veorq) <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/veorq\/status\/1804614728573981117?ref_src=twsrc%5Etfw\" target=\"_blank\">June 22, 2024<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p class=\"wp-block-paragraph\">Telegram did not respond to a request for comment, which included questions on whether the company has a chief security officer, and how many of its engineers work full time on securing the platform.<\/p>\n<p class=\"wp-block-paragraph\">Last week, the well-known cybersecurity expert SwiftOnSecurity <a href=\"https:\/\/x.com\/SwiftOnSecurity\/status\/1803155936359350783\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">wrote on X<\/a> that \u201cThe cost to run a company that has all the right cyber security tools and staff is absolutely obscene.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt\u2019s hard to describe the numbers I\u2019ve seen. Even saying this is a gray area. But it is [an] incredible headcount and spend,\u201d SwiftOnSecurity wrote.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">All to say, even the biggest companies on the planet probably don\u2019t spend enough money, time and energy on securing themselves. Telegram has almost one billion users, according to Durov. It\u2019s one of the most popular platforms for people working in crypto (who move millions of dollars), extremists, hackers and disinformation peddlers.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">That makes it an incredibly interesting target for both criminal and government hackers. And it has \u2014 at most \u2014 just a handful of people dedicated to cybersecurity.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">For years, <a href=\"https:\/\/www.vice.com\/en\/article\/mg7jq3\/encryption-app-telegram-probably-isnt-as-secure-for-terrorists-as-isis-thinks\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">security<\/a> <a href=\"https:\/\/threadreaderapp.com\/thread\/1789687898863792453.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">experts<\/a> <a href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2024\/05\/14\/telegram-warning-switch-to-whatsapp-and-signal-for-iphone-and-android\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">have<\/a> <a href=\"https:\/\/www.wired.com\/story\/telegram-encryption-whatsapp-settings\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">warned<\/a> that people should not see Telegram like a truly secure messaging app. Given what Durov said recently, it may be even worse than experts thought.\u00a0<\/p>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2024\/06\/24\/experts-say-telegrams-30-engineers-team-is-a-security-red-flag\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Over the weekend, a clip from a recent interview with Telegram\u2019s founder Pavel Durov went semi-viral on X (previously Twitter). In the video, Durov tells right-wing personality Tucker Carlson that he is the only product manager at the company, and that he only employs \u201cabout 30 engineers.\u201d\u00a0 Security experts say that while Durov was bragging [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":107134,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-107133","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/107133","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=107133"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/107133\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/107134"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=107133"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=107133"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=107133"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}