Telegram
Official website (opens in a new tab)
A “cloud” platform whose conversations are, by default, readable by the operator — the only one in the benchmark that fails the end-to-end encryption criterion, despite its reputation for security.
At a glance
• End-to-end encryption — ❌ Poor
• End-to-end authentication — ❌ Poor
• End-to-end security — ❌ Poor
• No identity substitution — ❌ Poor
• Open source client — ✅ Good
• End-to-end multi-device — ❌ Poor
• Minimal personal data — ❌ Poor
• No contact discovery and spam — ❌ Poor
• Post-quantum encryption — ❌ Poor
Telegram is one of the most widely used messaging apps in the world, and that success rests on real qualities: fast, polished applications, a wealth of features (giant groups, channels, bots), and open source clients with reproducible builds, including on iOS, where Telegram is the only app in the benchmark to offer them. That said, Telegram is not a secure messaging app as defined in this benchmark. It is a “cloud” communication platform, where conversations are, by default, readable by the operator. Its reputation for security rests on a misunderstanding, for the reasons discussed below.
Telegram is the only messaging app in this benchmark that fails the End-to-end encryption criterion. This led us to wonder whether it made sense to include Telegram in the list of messaging apps considered. We have, however, very often seen it wrongly regarded as secure, notably by users unaware of this lack of end-to-end encryption. That is why we decided to include it.
Where, then, does the reputation for security come from?
Neither from encryption (absent by default) nor from the architecture. It comes from relentless self-promotion (“focus on speed and securityarchived”) and, above all, from a historical stance: Telegram did not cooperate with the authorities. Its privacy policy provided for disclosure only in the case of terrorism suspects, upon a court order, adding: “So far, this has never happened.”
Let us make clear from the start that the problem is not cooperation with the courts, since responding to judicial requests is a legal obligation that applies to every operator. The problem lies elsewhere. Without end-to-end encryption, Telegram holds everything: content, contacts, histories. The only thing separating that data from the authorities, as from anyone else, was its policy. Users’ confidentiality therefore rested not on a technical impossibility, but on an operator’s refusal. That refusal, moreover, proved untenable. In August 2024, Telegram’s founder was placed under formal investigation in France, notably for refusing to cooperate with the authoritiesarchived. A month later, Telegram changed its policy: the IP addresses and phone numbers of suspects in criminal cases are now disclosed in response to judicial requestsarchived, and quarterly transparency reportsarchived document these disclosures, numbering in the thousands from the very first months.
The lesson is not that Telegram “betrayed” its users by complying with the law. The lesson is that confidentiality based on an operator’s promise is only worth as much as that promise: it gives way the day the operator changes its mind, or no longer has a choice. A messaging app that is secure by design puts no one in that position: its operator can cooperate fully with the courts, and hand over everything it holds, without affecting the confidentiality of exchanges, because it never held any of their content. Confidentiality then depends neither on its goodwill nor on its legal situation.
End-to-end encryption ❌ Poor
By default, Telegram conversations (the “cloud chats”) are not end-to-end encrypted. They are protected between the device and the server (point-to-point encryption), then stored on Telegram’s servers, and Telegram holds the keysarchived: the operator can read messages, attachments and media. End-to-end encryption exists only in “secret chats,” which are optional, limited to one-to-one chatsarchived (all group conversations and channels are “in the clear” on the servers), unavailable in the official desktop client, Telegram Desktop (the official macOS client does offer them), and tied to a single device. Since the vast majority of users stick to the default configuration, end-to-end encryption is, in practice, marginal on Telegramarchived.
End-to-end authentication ❌ Poor
A Telegram account is identified by a phone number, and connecting with a contact goes through the operator’s central directory, which the application trusts. Secret chats offer a visual key verification, but it is entirely optional.
End-to-end security ❌ Poor
A direct consequence of the two previous criteria: neither systematic encryption nor end-to-end authentication.
No identity substitution ❌ Poor
Not met, with an aggravating factor. The account is tied to the phone number and can be recovered with a code received by SMS, so everything the criterion describes applies. But on Telegram, the consequences of an account takeover are more serious than elsewhere: where taking over a Signal or WhatsApp account only yields future communications, taking over a Telegram account also yields the complete history, since it is stored on the servers and delivered to any new device that registers. A password option (two-step verificationarchived) protects against this scenario; it is off by default.
Open source client ✅ Good
Telegram’s clients are open source, with reproducible builds on both Android and iOSarchived. Licenses vary by client: GPLv2 for Androidarchived, GPLv3 with an OpenSSL exception for the desktop clientarchived; the repository of the iOS clientarchived does not state its license explicitly. The server code, on the other hand, is closed source, and Telegram’s FAQ argues that publishing it would prove nothingarchived, an argument we partly share (see the Open source client criterion). But the argument cuts both ways: it is precisely because nothing can be verified about a server that security must not depend on it. Yet on Telegram, security depends on the server entirely!
End-to-end multi-device ❌ Poor
Telegram’s multi-device support is remarkably smooth, and for good reason: it follows exactly the “trivial” model described in the criterion, where the server holds the conversations and distributes them to any authenticated device. In fact, the simple test proposed in that criterion applies: you can open your Telegram chats in a plain browser by authenticating with the server. As for secret chats, the only end-to-end encrypted ones, they are tied to a single device: convenience and security do not coexist on Telegram.
Minimal personal data ❌ Poor
A phone number is mandatory, access to the address book is encouraged, and the operator holds both the social graph and the content of conversations. No minimization at all.
No contact discovery and spam ❌ Poor
Any user can be found by their number or username, and anyone can write to them directly. A setting reserved for Premium subscribersarchived makes it possible to limit incoming messages to contacts and other Premium subscribers: paid and off by default, this barrier also remains open to anyone who pays, and therefore never offers complete protection in the criterion’s sense. A setting does make it possible to restrict discovery by number, but username search, open to all, is at the heart of how Telegram works (public channels and groups): unlike Signal, the application cannot be configured to make a user undiscoverable while remaining normally usable. There is, moreover, no contact-request confirmation, and a stranger’s first message lands directly in the inbox. Spam and scams are a documented, large-scale phenomenonarchived on Telegram.
Post-quantum encryption ❌ Poor
No post-quantum encryption: secret chats rely on a classical Diffie-Hellman key exchangearchived, and cloud chats, which are the default, are not end-to-end encrypted anyway.