Cointime

Download App
iOS & Android

Telegram's Pavel Durov is wrong about Signal — and has been for years

Validated Media

Telegram founder Pavel Durov put the encrypted messaging application Signal on blast this month, arguing in a May 8 post that its privacy mechanisms amounted to a “circus trick.” His commentary was purpose-built to undermine the rival messaging app, but Durov’s history with Signal and Telegram's own privacy credentials make it hard to take his comments seriously.

Durov has been throwing stones at Signal for years. In 2017, he predicted we'd find a backdoor in their protocol within five years. Seven years later, that prediction has missed the mark. A few years later, Signal founder Moxie Marlinspike posted a thread suggesting we should stop calling Telegram an encrypted messaging app.

Signal and Telegram do not like each other.

Pavel Durov took aim at Signal in a May 8 post. Source: Telegram

In the context of historical beef between the two products, this latest post looks more like an opportunistic potshot at a market competitor than a legitimate PSA about backdoored software.

Malice in the messaging apps

Signal was already under heavy scrutiny after comments made by Signal Foundation Chair Katherine Maher, who said Wikipedia's "free and open" nature promoted a "white male Westernized construct." It was a story that received a lot of traction on social media, and drew comments from Jack Dorsey, Vitalik Buterin, and Elon Musk on X.

As people picked up their pitchforks over Maher's politics, it was all too easy for Durov to redirect the angry mob toward Signal itself.

Signal got to work dispelling the claims about their app and protocol, with President Meredith Whittaker providing important context in the replies to throw some ice on the story.

Signal Foundation President Meredith Whittaker addressed the controversy involving Maher in a May 8 post on X. Source: X

For now, things have settled down. However, this beef isn't over — if anything, it's just getting started. This row has the potential to become cybersecurity's version of Kendrick v. Drake.

The anti-Signal movement

It was easy to whip people into a frenzy about Signal. There's an anti-Signal undercurrent emerging in certain circles — a surprising sensitivity for one of the most respected messaging apps in the world.

Perhaps it started when ex-Fox News anchor Tucker Carlson appeared on Lex Fridman's Podcast earlier this year. Speaking about messaging security, Carlson said, "we all have theories about secure communications channels. Like Signal is secure, Telegraph [sic] isn't, or WhatsApp, [which] is owned by Mark Zuckerberg — you can't trust it."

In the same conversation, Carlson claimed the NSA managed to obtain and Signal messages related to his efforts to interview Russian President Vladimir Putin and subsequently leak them to the media. This may have planted the original seed of doubt, and it certainly feels like the precursor to the latest controversy.

Connecting some dots, Carlson sat down for an interview with Pavel Durov back in April. One month later, Durov's post to Du Rove's Channel said key figures had revealed to him that their "private" Signal messages had been exploited."

In case you aren't a natural Sherlock, Carlson is one of the "important people" Durov is talking about. Building from these claims, Durov says Telegram provides "the only popular method of communication that is verifiably private."

Telegram has always tried to hang with the encrypted messaging crowd, but Telegram is not a suitable Signal alternative. Telegram doesn't have end-to-end encryption by default and it doesn't have end-to-end encrypted group chats at all. Having opt-in privacy features — especially necessities like end-to-end encryption — means the vast majority of users will be left without protection.

But none of this will stop Durov from amplifying people's doubts about Signal to give Telegram a leg-up. Further conflict is likely. (Wouldn't it be nice if we could all just get along?)

As for this round of the bout, it's notable that Signal hasn't backed up Maher's comments. Their line is that Maher's politics don't really matter — you don't need to trust the people running Signal, you just need to trust the code.

It's a good line to take. With highly audited, open source code, Signal has a relatively trustless model. Maher's politics have no bearing on a PQXDH key exchange. But a decentralized model could be more trustless — and it already exists.

The anti-Signal movement 

I work on an end-to-end encrypted messaging app called Session. It runs on a decentralized network operated by ordinary community members who contribute compute resources to route and store messages.

Not only is the client and server code open source, you can verify the open source code is what's actually running on the network — you can join and run it yourself. Session does what it says on the box, no trust required whatsoever.

However, this is not a cure-all. The quirks of a decentralized network make it difficult to pull off the complex key ratcheting involved in the Signal Protocol. This ratcheting provides unique cryptographic properties, but keeping key-states updated doesn't mix with a decentralized network of community nodes which can enter and leave the network at will.

If you remove encryption entirely, you can have an awesome UX like Telegram's, where messages appear instantly as though they're rabbits out hats.

There's always a trade off. Nobody has it all — and if they say they do, they've probably got something to sell you.

Comments

All Comments

Recommended for you

  • Zhipu Launches and Open Sources GLM-5.3-Flash

    On August 26, Zhipu launched and open-sourced GLM-5.3-Flash (320B-A18B), the first native multimodal model in the GLM-5 series. It features a total of 320 billion parameters and surpasses GLM-5.2, achieving a score of 57 on the globally recognized Artificial Analysis Intelligence Index (AA Comprehensive Intelligence Index), placing it among the leading models worldwide, on par with Anthropic's popular model Claude Opus 4.8. In the self-developed Z.ai Code Bench evaluation, its programming performance is comparable to that of Claude Opus 4.8. Additionally, GLM-5.3-Flash is priced at 1/10 of GLM-5.3, and during a limited-time discount, it is priced at 1/20 of GLM-5.3, which is 1/40 of Opus 4.8. The same intelligence at 1/40 the price, cutting-edge capabilities without the need to hold back.

  • Zhipu Launches and Open Sources GLM-5.3-Flash

    On August 26, Zhipu launched and open-sourced GLM-5.3-Flash (320B-A18B), the first native multimodal model in the GLM-5 series. It has a total of 320 billion parameters and surpasses GLM-5.2, achieving a score of 57 in the globally recognized Artificial Analysis Intelligence Index (AA Comprehensive Intelligence Index), placing it among the leading models worldwide, on par with Anthropic's popular model Claude Opus 4.8. In the self-developed Z.ai Code Bench evaluation, its programming performance is comparable to that of Claude Opus 4.8. Meanwhile, GLM-5.3-Flash is priced at 1/10 of GLM-5.3, and during a limited-time discount, it is available for 1/20 of GLM-5.3's price, which is 1/40 of Opus 4.8's price. The same intelligence, at 1/40 the cost, provides cutting-edge capabilities without the need to hold back.

  • Ethereum Developers Propose Restructuring Validator Staking Contract to Prepare for Quantum Attacks

    On August 26, Ethereum researchers proposed a draft to rebuild the validator deposit contract in preparation for the future introduction of quantum-resistant signature mechanisms, allowing for a gradual phase-out of the existing BLS signature format. This proposal enables the deposit contract to support keys of different sizes and public key types, assigning labels for each cryptographic scheme, with the current BLS signature labeled as 0 and potential future quantum-resistant schemes receiving new labels. Currently, approximately 42.4 million ETH, worth around $10.4 billion, are staked in Ethereum, all relying on BLS validator keys. This draft is still in its early stages and must be implemented alongside subsequent consensus layer upgrades, with the Ethereum Foundation's overall quantum resistance roadmap targeting around 2029.

  • Ethereum Developers Propose Restructuring Validator Staking Contract to Prepare for Quantum Attacks

    On August 26, Ethereum researchers proposed a draft to rebuild the validator deposit contract in preparation for the future introduction of quantum-resistant signature mechanisms, allowing for a gradual phase-out of the existing BLS signature format. This proposal enables the deposit contract to support keys of different sizes and public key types, assigning labels for each cryptographic scheme, with the current BLS signature labeled as 0, and future quantum-resistant schemes to be assigned additional labels. Currently, approximately 42.4 million ETH, valued at around $10.4 billion, are staked in Ethereum, all relying on BLS validator keys. The draft remains in its early stages and must be implemented alongside subsequent consensus layer upgrades, with the Ethereum Foundation's overall quantum resistance roadmap targeting around 2029.

  • Spot Gold Falls Below $4600/Ounce

    On August 26, spot gold fell below $4600 per ounce, declining by 1.30% during the day.

  • Spot Gold Falls Below $4600/Ounce

    On August 26, spot gold fell below $4600 per ounce, declining by 1.30% during the day.

  • SEC Submits New Crypto Custody Regulations Proposal to White House

    On August 26, Bloomberg reported that the U.S. Securities and Exchange Commission (SEC) has submitted a proposal to the Office of Management and Budget (OMB) regarding new regulations for investment advisors holding client digital assets. The rule aims to 'clarify the framework for investment advisors and investment companies to custody crypto assets,' addressing inquiries from institutions on how to comply with the custody of digital assets. It plans to eliminate certain existing custody requirements that are considered 'outdated' due to market evolution and current trading and custody practices. This proposal is seen as a step by financial regulators to advance the current administration's crypto agenda while relevant legislation remains stalled in the Senate. It will take effect after review by the OMB, a vote by SEC commissioners, and a public comment period.

  • BTC Falls Below $78,000

    Market data shows that BTC has fallen below $78,000, currently priced at $77,983.75, with a 24-hour decline of 1.03%. The market is experiencing significant volatility, so please ensure proper risk management.

  • BTC Falls Below $78,000

    Market data shows that BTC has fallen below $78,000, currently priced at $77,983.75, with a 24-hour decline of 1.03%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Alibaba Qwen Releases Qwen 3.8-Flash Model

    On August 26, Alibaba Qwen launched the Qwen 3.8-Flash model, which is a multimodal MoE model and an early preview of the Qwen 4 architecture. The production version of Qwen 3.8-Flash will soon be available through the Qwen Cloud API, priced at just $0.16 per million input tokens and $0.47 per million output tokens. The model features 125 billion parameters plus 51 billion N-gram embedding parameters, but activates only 6 billion parameters per token, achieving high cost-effectiveness.