show Screenshot | |||||||||||||
Developer(s) | Telegram FZ LLC Telegram Messenger Inc. | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Initial release | 14 August 2013 | ||||||||||||
Stable release(s) [±] | |||||||||||||
| |||||||||||||
Preview release(s) [±] | |||||||||||||
| |||||||||||||
Repository | github | ||||||||||||
Written in | C++ | ||||||||||||
Platform | Android, iOS, Windows, macOS, GNU / Linux, Web platform | ||||||||||||
Available in | 19 languages[3][11] | ||||||||||||
show List of languages | |||||||||||||
Type | Instant messaging | ||||||||||||
License | GNU GPLv2 or GPLv3 (clients),[12] proprietary (server) | ||||||||||||
Website | telegram |
Founded | March 2013 |
---|---|
Headquarters | London, United Kingdom (legal domicile) Dubai, United Arab Emirates (operational center) |
Area served | Global |
Founder(s) | |
CEO | Pavel Durov |
Industry | Software |
Employees | 351 (2019)[13] |
URL | telegram |
Telegram is a freeware, cross-platform, cloud-based instant messaging (IM) software and application service. The service also provides end-to-end encrypted video calling,[14] VoIP, file sharing and several other features. It was initially launched for iOS on 14 August 2013 and Android in October 2013. The application servers of Telegram are distributed worldwide to decrease data load, while the operational center is currently based in Dubai.[15][16][17][18] Various Telegram client apps are available for desktop and mobile platforms including official apps for Android, iOS, Windows, macOS and Linux, as well as for the now-discontinued Windows Phone. There is also an official web interface and numerous unofficial clients that make use of Telegram's protocol. All of Telegram's official apps are open source.[19]
Telegram provides end-to-end encrypted voice and video calls[20] and optional end-to-end encrypted "secret" chats. Cloud chats and groups are encrypted between the app and the server, so that ISPs and other third-parties on the network can’t access data, but the Telegram server is in possession of the decryption key. Users can send text and voice messages, animated stickers, make voice and video calls, and share an unlimited number of images, documents (2 GB per file), user locations, contacts, and music. In January 2021, Telegram surpassed 500 million monthly active users.[21] It was the most downloaded app worldwide in January 2021.[22]
History
Development:
Telegram was launched in 2013 by brothers Nikolai and Pavel Durov. Previously, the pair founded the Russian social network VK, which they left in 2014 after it was taken over by President Putin's allies. Pavel Durov sold his remaining stake in VK and left Russia after resisting government pressure.[23][24] Nikolai Durov created the MTProto protocol that is the basis for the messenger, while Pavel Durov provided financial support and infrastructure through his Digital Fortress fund, with partner Axel Neff joining as a second co-founder. The company and the app were started in Russia in 2013 and later moved to Germany.[25][26] Telegram Messenger states that its end goal is not to bring profit,[27][28] but it is not currently structured as a non-profit organization.[29]
Telegram is registered as both an English LLP[30] and an American LLC.[31] It does not disclose where it rents offices or which legal entities it uses to rent them, citing the need to "shelter the team from unnecessary influence" and protect users from governmental data requests.[32] Pavel Durov said that the service was headquartered in Berlin, Germany, between 2014[33] and early 2015, but moved to different jurisdictions after failing to obtain residence permits for everyone on the team.[34] After Pavel Durov left Russia, he is said to be moving from country to country with a small group of computer programmers consisting of 15 core members.[23][35] According to press reports, Telegram had employees in Saint Petersburg.[34] The Telegram team is currently based in Dubai.[36]
Usage numbers:
In October 2013, Telegram announced it had 100,000 daily active users.[24] On 24 March 2014, Telegram announced that it had reached 35 million monthly users and 15 million daily active users.[37] In October 2014, South Korean governmental surveillance plans drove many of its citizens to switch to Telegram.[33] In December 2014, Telegram announced that it had 50 million active users, generating 1 billion daily messages, and that it had 1 million new users signing up on its service every week,[38] traffic doubled in five months with 2 billion daily messages.[39] In September 2015, Telegram announced that the app had 60 million active users and delivered 12 billion daily messages.[40]
In February 2016, Telegram announced that it had 100 million monthly active users, with 350,000 new users signing up every day, delivering 15 billion messages daily.[41] In December 2017, Telegram reached 180 million monthly active users.[36] In March 2018, Telegram reached 200 million monthly active users.[42] On 14 March 2019, Pavel Durov claimed that "3 million new users signed up for Telegram within the last 24 hours."[43] Durov did not specify what prompted this flood of new sign-ups, but the period matched a prolonged technical outage experienced by Facebook and its family of apps, including Instagram.[44]
According to the U.S. Securities and Exchange Commission, the number of monthly Telegram users as of October 2019 is 300 million people worldwide.[45]
On 24 April 2020, Telegram announced it had reached 400 million monthly active users.[21] On 8 January 2021, Durov announced in a blog post that Telegram was at "about 500 million" monthly active users.[46]
Features[edit]
This section relies too much on references to primary sources. (March 2021) (Learn how and when to remove this template message) |
Account[edit]
Telegram accounts are tied to telephone numbers and are verified by SMS.[47] Users can add multiple devices to their account and receive messages on all of them. Connected devices can be removed individually or all at once. The associated number can be changed at any time and when doing so, the user's contacts will receive the new number automatically.[47][48][49] In addition, a user can set up a username as an alias that allows them to send and receive messages without exposing their phone number.[50] Telegram accounts can be deleted at any time and they are deleted automatically after six months of inactivity by default, which can optionally be changed from 1 month at the shortest up to 12 months at most with a range between. Users can replace exact "last seen" timestamps with broader messages such as "last seen recently".[51]
The default method of authentication that Telegram uses for logins is SMS-based single-factor authentication.[52][53] All that is needed to log into an account and gain access to that user's cloud-based messages is a one-time passcode that is sent via SMS to the user's phone number.[53][54] This can be prevented by creating a password as a form of two-step verification.[55]
Cloud-based messages[edit]
Telegram's default messages are cloud-based and can be accessed on any of the user's connected devices. Users can share photos, videos, audio messages and other files (up to 2 gigabytes per file). Users can send messages to other users individually or in groups of up to 200,000 members.[56] Sent messages can be edited up to 48 hours after they have been sent and can be deleted at any time on both sides. Messages in all chats, including groups and channels, can be set to auto-delete after 24 hours or 7 days, although this will only apply to messages sent after the auto-delete timer is enabled.[57][58] Telegram offers drafts which sync across user devices, such as when a user starts typing a message on one device and can later continue on another. The draft will persist in editing area on any device until it is sent or removed.[59] All chats, including groups and channels, can be sorted into custom folders set by the user. Users have the option to schedule messages in personal chats to be sent when the other side comes online.[60] Users can also import chat history, including both messages and media, from WhatsApp, Line and Kakaotalk due to data portability, either making a new chat to hold the messages or adding them to an existing one.[61][62]
The transmission of cloud messages to Telegram's servers is encrypted with the service's MTProto protocol, while 'Secret Chats' use end-to-end encryption based on the same protocol.[63][64] According to Telegram's privacy policy, "all data is stored heavily encrypted and the encryption keys in each case are stored in several other data centers in different jurisdictions. This way local engineers or physical intruders cannot get access to users' data".[65] Telegram's local message database is not encrypted by default.[66] Some Telegram clients allow users to encrypt the local message database by setting a passphrase.[67]
Secret chats[edit]
Messages can also be sent with client-to-client encryption in so-called secret chats. These messages are encrypted with the service's MTProto protocol.[68] Unlike Telegram's cloud-based messages, messages sent within a secret chat can be accessed only on the device upon which the secret chat was initiated and the device upon which the secret chat was accepted; they cannot be accessed on other devices.[24][63][69] Messages sent within secret chats can, in principle, be deleted at any time and can optionally self-destruct.[70]
Secret chats have to be initiated and accepted by an invitation, upon which the encryption keys for the session are exchanged. Users in a secret chat can verify that no man-in-the-middle attack has occurred by comparing pictures that visualize their public key fingerprints.[71]
According to Telegram, secret chats have supported perfect forward secrecy since December 2014. Encryption keys are periodically changed after a key has been used more than 100 times or has been in use for more than a week.[66] Old encryption keys are destroyed.[48][49][72]
Windows and GNU/Linux users are still not able to use secret chats using the official Telegram Desktop app while the official macOS-only client supports them.[73]
Secret chats are not available for groups or channels.
Channels[edit]
In September 2015, Telegram added channels.[74] Channels are a form of one-way messaging where admins are able to post messages but other users are not. Any user is able to create and subscribe to channels. Channels can be created for broadcasting messages to an unlimited number of subscribers.[75] Channels can be publicly available with an alias and a permanent URL so anyone can join. Users who join a channel can see the entire message history. Users can join and leave channels at any time. Depending on a channel's settings, messages may be signed with the channel's name or with the username of the admin who posted them. Non-admin users are unable to see other users who've subscribed to the channel. Furthermore, users can mute a channel, meaning that the user will still receive messages, but won't be notified. Admins can give permission to post comments on the Telegram channel with help of bots. The admin of the channel can obtain general data about the channel. Each message has its own view counter, showing how many users have seen this message, this includes views from forwarded messages. As of May 2019, the creator of a channel can add a discussion group, a separate group where messages in the channel are automatically posted for subscribers to communicate.[76]
In December 2019, Bloomberg moved their messenger-based newsletter service from WhatsApp to Telegram after the former banned bulk and automated messaging.[77][78] The news service is attempting to grow its audience outside the U.S.[78] Channel comment was added on October 1, 2020 via threads in discussion groups.[79]
Video and voice calls[edit]
At the end of March 2017, Telegram introduced its own voice calls. The calls are built upon the end-to-end encryption. Connection is established as peer-to-peer whenever possible, otherwise the closest server to the client is used. According to Telegram, there is a neural network working to learn various technical parameters about a call to provide better quality of the service for future uses. After a brief initial trial in Western Europe, voice calls are now available for use in most countries.[80]
Telegram announced in April 2020 that they would include group video calls by the end of the year.[81] On 15 August 2020, Telegram added video calling with end-to-end encryption like Signal and WhatsApp, which Zoom does not have yet.[82] Currently offering one-to-one video calls, Telegram has plans to introduce secure group video calls later in 2020.[83] Picture-in-picture mode is also available so that users have the option to simultaneously use the other functions of the app while still remaining on the call and are even able to turn their video off.[84]
Telegram's video and voice calls are secure and end-to-end encrypted.[85]
Telegraph[edit]
Telegraph is a publishing tool used to create formatted posts with photos and embedded media.[86]
Telegraph is designed in a minimalist style, the article pages do not contain any controls. Each article on the website is separate, there is no possibility to merge articles into groups or hierarchies. For each article, the author specifies a title and optionally a subtitle, usually used for the author's name. In addition, the title of the article indicates the date of the first publication, which the author of the article cannot influence.
Text formatting options are also minimal: two levels of headings, single-level lists, bold, italics, quotes, and hyperlinks are supported. Authors can upload images and video to the page, with a limit of 5mb. When an author adds links to YouTube, Vimeo, or Twitter, the service allows you to embed their content directly in the article.[87]
When an article is first published, the URL is generated automatically from its title. Non-Latin characters are transliterated, spaces are replaced with hyphens, and the date of publication is added to the address. For example, an article titled "Telegraph (blog platform)" published on November 17 would receive the URL /Telegraph-blog-platform-11-17
.
Instant View 2.0[edit]
Instant View is a way to view web articles with zero pageload time. With Instant View, Telegram users can read articles from mass media or blogs in a uniform and readable way. Instant View pages support text and media of any type and work even if the original website was not optimized for mobile devices.
On top of this, Instant View pages are extremely lightweight and cached on the Telegram servers, so they load instantly on pretty much any connection. [86][88][89]
Bots and IFTTT[edit]
In June 2015, Telegram launched a platform for third-party developers to create bots.[90] Bots are Telegram accounts operated by programs. They can respond to messages or mentions, can be invited into groups and can be integrated into other programs. It also accepts online payments with credit cards and Apple Pay.[91] Dutch website Tweakers reported that an invited bot can potentially read all group messages when the bot controller changes the access settings silently at a later point in time. Telegram pointed out that it considered implementing a feature that would announce such a status change within the relevant group.[92] There are also inline bots, which can be used from any chat screen. In order to activate an inline bot, user needs to type in the message field a bot's username and query. The bot then will offer its content. User can choose from that content and send it within a chat.[93] Bots can also handle transactions provided by Paymentwall, Yandex.Money, Stripe, Ravepay, Razorpay and QiWi, Google Pay for different countries.[94] Bots also power Telegram’s gaming platform, which utilizes HTML5, so games are loaded on-demand as needed, like ordinary webpages. Games work on iPhones 4 and newer and on Android 4.4 devices and newer.[95] People can use Internet Of Things (IoT) services with two-ways interaction for IFTTT implemented within Telegram.[96]
Stickers[edit]
Telegram has more than 20,000 stickers. Stickers are cloud-based, high-resolution images intended to provide more expressive emoji. When typing in an emoji, the user is offered to send the respective sticker instead. Stickers come in collections called "packs", and multiple stickers can be offered for one emoji. Telegram comes with one default sticker pack,[97] but users can install additional sticker packs provided by third-party contributors. Sticker sets installed from one client become automatically available to all other clients. Sticker images use WebP file format, which is better optimized to be transmitted over internet.
Group voice chats[edit]
Telegram added group voice chats in December 2020.[98] Any group admin can launch a chat, which will be open to all group members and ongoing even if no one is currently using it. Admins can mute members by default or selectively. A push-to-talk option is available on mobile versions, as well as key shortcuts to mute and unmute oneself on Telegram Desktop.
Video messages[edit]
Since version 4.1, released in May 2017, Telegram offers a dedicated video hosting platform called Telescope.[99] The round videos can be up to one minute long and autoplay. When posted in a public channel on Telegram, the videos are also uploaded to and viewable without an account. However, Telegram video messages and "Telescope" videos sent within non-public chats or groups are not published.
Live locations[edit]
For either 15 minutes, one hour, or eight hours, Telegram users can share their live location in a chat since version 4.4 released in October 2017.[100] If multiple users share their live location within a group, they are shown on an interactive map. Sharing the 'live location' can be stopped at any time.
Social login[edit]
In February 2018, Telegram launched their social login feature to its users, named Telegram Login.[101] It features a website widget that could be embedded into websites, allowing users to sign into a third party website with their Telegram account. The gateway sends users' Telegram name, username, and profile picture to the website owner, while users' phone number remains hidden. The gateway is integrated with a bot, which is linked with the developer's specific website domain.[102]
Real-life Identification[edit]
In July 2018, Telegram introduced their online authorisation and identity management system, Telegram Passport, for platforms that require real-life identification.[103] It asks users to upload their own official documents such as passport, identity card, driver license, etc. When an online service requires such identification documents and verification, it forwards the information to the platform with the user's permission. Telegram stated that it does not have access to the data, while the platform will only share the information to the authorised recipient.[104] However, the service was criticised for being vulnerable to online brute force attacks.[105]
Polls[edit]
Polls are available on Android, iOS, and the desktop applications. Polls have the option to be anonymous or visible. A user can enter multiple options into the poll. Quiz mode can also be enabled where a user can select the right answer for their poll and leave it to the group to guess. Quiz bots can also be added to track correct answers and even provide a global leaderboard.[106]
Comments.App[edit]
Comments.App, is a tool for commenting on pages, channel posts, it lets you add a comments widget to your website. With the widget in place, Telegram users will be able to log in with just two taps and leave comments with text and photos, as well as like, dislike and reply to comments from others. They can also subscribe to comments and get notifications from @DiscussBot.[107] Widgets are configurable. Developers can change the color theme, use different colors for names, change the design to a dark theme, change the maximum number of comments on the page, change the height, assign moderators, and block user spam; the mode of filled and outlined icons is also supported.
People Nearby and Groups Nearby[edit]
People Nearby can help users meet new friends by turning on phone GPS location and opting-in in contacts and through Groups Nearby people can create a local group by adding location data to groups.[108][109]
Verification[edit]
Telegram allows groups, bots and channels with a verified social media or Wikipedia page to be verified but not user accounts.[110][111]
Native file format support[edit]
The official Telegram clients support sending any file format extensions. Natively supported in their viewer/player in mobile and desktops versions of Telegram are the common media formats - JPEG, PNG, WebP for images and H.264 and HEVC in videos in MP4 container and MP3, FLAC, Vorbis, Opus and AAC for audio.
Architecture[edit]
Encryption scheme[edit]
Telegram uses a symmetric encryption scheme called MTProto. The protocol was developed by Nikolai Durov and other developers at Telegram and is based on 256-bit symmetric AES encryption, 2048-bit RSA encryption and Diffie–Hellman key exchange.[68]
Servers[edit]
As with most instant messaging protocols, Telegram uses centralized servers. Telegram Messenger LLP has servers in a number of countries throughout the world to improve the response time of their service.[112] Telegram's server-side software is closed-source and proprietary.[113] Pavel Durov said that it would require a major architectural redesign of the server-side software to connect independent servers to the Telegram cloud.[114]
For users who signed in from the European Economic Area (EEA) or United Kingdom, the General Data Protection Regulations (GDPR) are supported by storing data only on servers in the Netherlands, and designating a London based company as their responsible data controller.[115][116][117]
Client apps[edit]
Telegram has various client apps, some developed by Telegram Messenger LLP and some by the community. Most of them are free and open-source and released under the GNU General Public Licence version 2 or 3.
Common specifications:
- No cloud backup option for secret chat
Name | Platform(s) | Official | Source code license | Support for secret chats | Notes |
---|---|---|---|---|---|
Telegram | Android 2.3 or later | Yes | GPLv2 or later[118][119] | Yes | Supports tablets[120] and Android Wear smart watches.[121] Support synchronisation between multiple devices. |
Telegram Messenger | iOS 9.0 or later, watchOS 5.0 or later | Yes | GPLv2 or later[118][122] | Yes | Launched in August 2013 for iPhone and iPod Touch and relaunched in July 2014 with support for iPad and Apple Watch.[123] |
Telegram X | Android[124] | Yes[125] | Proprietary | Yes | An alternative Telegram client written from scratch, with higher speed, slicker animations, themes and more efficient battery use. iOS version is written with Swift. Android version based on TDLib. The iOS version was discontinued, with its code merged with the main Telegram app. |
Telegram Messenger | Windows Phone | Yes | GPLv2 or later[118] | Yes | Provide synchronization between all platforms |
Telegram Desktop | Windows, macOS, and GNU/Linux | Yes | GPLv3 with OpenSSL exception[126] | No | Qt-based desktop client. The Windows client is a traditional desktop app published in three flavors: With installer, portable, Windows Store app. |
Telegram | macOS | Yes | GPLv2[127] | Yes | Native macOS client. |
Telegram Web / Webogram | Web | Yes | GPLv3[128] | No | Web-based version of Telegram. Also published on the Chrome Web Store. |
Unigram[129] | Windows 10, HoloLens, Surface Hub, Xbox One, Xbox Series X/S,[130] Windows 10 Mobile[131] | No | GPLv3[132] | Yes | Based on TDLib. |
APIs[edit]
Telegram has public APIs with which developers can access the same functionality as Telegram's official apps to build their own messaging applications.[133] In February 2015, creators of the unofficial Whatsapp+ client released the Telegram Plus app, later renamed to Plus Messenger, after their original project got a cease-and-desist order from WhatsApp.[134][135] In September 2015, Samsung released a messaging application based on these APIs.[136]
Telegram also offers an API that allows developers to create bots, which are accounts controlled by programs.[137][138] In February 2016, Forbes launched an AI-powered news bot that pushes popular stories to subscribers and replies to search queries with relevant articles.[139] TechCrunch launched a similar bot in March 2016.[140] (Both of them are down)
In addition, Telegram offers functions for making payments directly within the platform, alongside an external service such as Stripe.
Monetization[edit]
Advertising[edit]
Telegram has openly stated, that the company will never sell advertisement.[141] Despite that, in late 2020, Durov announced that the company was working on its own Ad Platform, and will integrate ads in public one-to-many channels, that already sell and display ads in form of regular messages.[142]
Paid features[edit]
Durov announced that Telegram will also consider adding paid features aimed at enterprise clients. According to him, these features will require more bandwidth and the added cost will be covered by the feature prices, in addition to covering some of the costs incurred by regular users.
Telegram Open Network ICO[edit]
According to documents related to U.S. Securities and Exchange Commission (SEC) v. Telegram case, that took place in 2020, by 2017 Telegram needed money to pay for servers and services. The company considered attracting venture capital, but decided against it at least until the time the cash requirements were solved.[143] In mid-December 2017 Bloomberg interview Durov announced that Telegram will start monetization in early 2018.[144] Later that month cryptocurrency blog Cointelegraph reported that Telegram was going to launch a blockchain platform dubbed either “The Open Network” or “Telegram Open Network” (TON) and native cryptocurrency “Gram”.[145] In January 2018, TechCrunch confirmed the news, referring to multiple sources.[146]
The company put together an Initial Coin Offering (ICO)[147] to fund development of a new blockchain platform. The offering was organized as a SAFT (Simple Agreement for Future Tokens), selling futures on tokens to be called Gram.[146] A 23-page white paper[148] and a detailed 132-page technical paper[149] for the plan were released.
The offering ran in two rounds, each taking in $850 million. Russian tech news site calculated the first round as offering 2.25 billion tokens at $0.38 each, with a minimum purchase of $20 million, and the second as offering 640 million tokens at $1.33 each, with a minimum purchase of $1 million.[150][151]
As of April 2018, the firm had reported raising $1.7 billion through the ongoing ICO.[152] Company officials have not made any public statements regarding the ICO. As of spring 2018, the only official sources of information were the two Forms D that Telegram filed with the U.S. Securities and Exchange Commission.[153]
Only the pre-ICO rounds were conducted; the public ICO was cancelled.[154]
The development of TON took place in a completely isolated manner and was intransparent for the whole time.[155] The launch of test network was initially scheduled for Q2 2018 with a main network launch in Q4, but the milestones were postponed several times. The testnet was apparently launched in January 2019 with a half a year deviation from the plan.[156] In May the company released the simplified version of TON blockchain network client, that allowed to connect to full node on testnet, part of the TON libraries, and tools for smart contract development.[157] On September the company released the complete source code for TON nodes on GitHub, making it possible to launch a full node and a validator node, and the block explorer on the testnet.[158]
SEC had concerns about Gram private sale and contacted Telegram shorty after, but over the 18 months of communication the sides didn't come to understanding.[159] On October 11, 2019, a couple of weeks before the planned TON launch, SEC obtained a temporary restrictive order to prevent the distribution of Grams. The regulator contended that initial Gram purchasers would be acting akin to underwriters, and the resale of Grams, once distributed, will be an unregistered distribution of securities.[160]
After a lengthy legal battle between Telegram and the SEC, Judge P. Kevin Castel of the U.S. District Court for the Southern District of New York agreed with the SEC's vision[161] that the initial purchase, the distribution to initial purchasers, and the potential future resale should be viewed as a single "scheme" to distribute Grams to secondary market in an unregistered offering. The Judge emphasized that the "security" at issue consisted of the whole set of contracts, expectations and understandings centered around the sale and distribution of tokens to interested public, and not the Grams themselves. In Judge Castel's view, the initial purchasers of Grams acted as underwriters that intended to resell tokens, not to consume them. The restriction on the distribution of Grams remained in force. The Judge clarified, that it applied both to non-U.S.-based initial purchasers as well, because U.S. citizens would highly likely be able to buy tokens on secondary market, and the company has no tools to oversee the deals, as the anonymity of users was one of key features of TON.[162][163][160]
Following the court decision, the Telegram Open Network (TON) team announced that they would be unable to launch the project by the expected 30 April 2020 deadline. On 12 May 2020, Pavel Durov announced the end of Telegram's active involvement with TON.[164] "Sadly, the US judge is right about one thing: we, the people outside the US, can vote for our presidents and elect our parliaments, but we are still dependent on the United States when it comes to finance and technology (luckily not coffee). The US can use its control over the dollar and the global financial system to shut down any bank or bank account in the world. It can use its control over Apple and Google to remove apps from the App Store and Google Play. So yes, it is true that other countries do not have full sovereignty over what to allow on their territory. Unfortunately, we – the 96% of the world’s population living elsewhere – are dependent on decision makers elected by the 4% living in the US," said Pavel Durov.[165]
On June 11, Telegram reached a settlement with SEC U.S. Securities & Exchange Commission and agreed to return $1.22 billion as "termination amounts" in Gram purchase agreements, and pay $18.5 million penalty to SEC. The company obliged to notify SEC of any plans to issue digital assets in over the next three years. The judge approved the settlement on June 26.[166] "New and innovative businesses are welcome to participate in our capital markets but they cannot do so in violation of the registration requirements of the federal securities laws," the SEC spokesperson noted.[167] By August 2020, Telegram shut down the TON test network.[168]
In 2020, Telegram repaid TON investors $770 million and converted $443 million into an one-year debt at 10% interest, raising its total liabilities to $625.7 million. On 10 March 2021, the company made a 5 year bonds placement worth $1 billion to cover the debts it has to return by 30 April 2021. In the future, the company is going to conduct an IPO. Among the public participants who have invested in Telegram: actor Jared Leto, billionaire David Yakobashvili and Adviser to the President of the Russian Federation for domestic policy Sergio Rozenberg.[169][170]
As stated in the early 2018 white paper, once Telegram implements TON's initial vision and architecture, it was supposed to be renamed to "The Open Network", and would be further maintained by TON Foundation.[171] As TON was an open source software with its entire code published on GitHub, it could be launched without Telegram. As Telegram dropped the legal fight against SEC, several independent projects emerged, namely Free TON, NewTON and TON Community Blockchain.[172]
Security breaches[edit]
In 2013, an author on Russian programming website Habr discovered an unexplained modification to the Diffie-Hellman key exchange scheme as described in the first version of MTProto specification that would allow an attacker to mount a man-in-the-middle attack and prevent the victim from being alerted by changed key fingerprint. The bug was fixed by the company shortly after the initial publication without any explanation.[173]
On 2 August 2016, a report by Reuters stated Iranian hackers compromised more than a dozen Telegram accounts and identified the phone numbers of 15 million Iranian users, as well as the associated user IDs. Researches said the hackers belonged to a group known as Rocket Kitten. Rocket Kitten's attacks were similar to ones attributed to Iran's Islamic Revolutionary Guards Corps. The attackers took advantage of a programming interface built into Telegram. According to Telegram, these mass checks are no longer possible because of limitations introduced into its API earlier in 2016.[174]
On 30 March 2020, an Elasticsearch database holding 42 million records containing user IDs and phone numbers was exposed online without a password. The accounts listed in the database were those belonging to users in Iran, extracted from an unofficial government-sanctioned version of Telegram. It took 11 days for the database to be taken down, but the researchers say the data was accessed by other parties, including a hacker who reported the information to a specialized forum.[175][176][177]
In September 2020, it was reported there have been successful large-scale Iranian government phishing and surveillance by RampantKitten targeting dissidents in Telegram.[178] The attack relied on people downloading a malware-infected file from any source, at which point it would replace Telegram files on the device and 'clone' session data. David Wolpoff, a former Department of Defense contractor, has stated that the weak link in the attack was the device itself and not any of the affected apps: "There’s no way for a secure communication app to keep a user safe when the end devices are compromised."[179]
Controversial use[edit]
Telegram has also attracted significant use for illegal or controversial activities such as spreading hate messages, illegal pornography, contact between criminals and trading of illegal goods and services such as drugs, contraband and stolen personal data.[180][181][182][183][184]
Jihadists[edit]
In September 2015, in response to a question about the use of Telegram by Islamic State of Iraq and the Levant (ISIS), Pavel Durov stated: "I think that privacy, ultimately, and our right for privacy is more important than our fear of bad things happening, like terrorism."[185] Durov sarcastically suggested to ban words because terrorists use them for communication.[186] ISIS recommended Telegram to its supporters and members[187][188][189] and in October 2015 they were able to double the number of followers of their official channel to 9,000.[190] In November 2015, Telegram announced that it had blocked 78 public channels operated by ISIS for spreading propaganda and mass communication.[191][192][193] Telegram stated that it would block public channels and bots that are related to terrorism, but it would not honor "politically-motivated censorship" based on "local restrictions on freedom of speech" and that it allowed "peaceful expression of alternative opinions."[194] Telegram's usage for ISIS propaganda reignited the encryption debate and encrypted messaging applications faced new scrutiny.[195][196] It also led to the Daily Mirror describing Telegram as a "jihadi messaging app".[197]
In August 2016, French anti-terrorism investigators asserted that the two ISIS-directed terrorists who fatally cut the throat of a priest in Saint-Étienne-du-Rouvray in Normandy, France, and videoed the murder, had communicated via Telegram and "used the app to coordinate their plans for the attack". ISIS's media wing subsequently posted a video on Telegram, showing the pair pledging allegiance. A CNN news report stated that Telegram had "become known as a preferred means of communication for the terror group ISIS and was used by the ISIS cell that plotted the Paris terror attacks in November" after the attacks.[187]
In June 2017, the Russian communications regulator Roskomnadzor hinted at the possibility of blocking Telegram in Russia due to its usage by terrorists.[198]
In July 2017, Director General of Application and Informatics of the Indonesian Ministry of Communication and Informatics, Semuel Abrijani Pangerapan, said eleven Telegram DNS servers were blocked because many channels in the service "promoted radicalism, terrorism, hatred, bomb assembly, civil attack, disturbing images, and other propaganda contrary to Indonesian laws and regulations."[199] In August 2017, Indonesia lifted the block after countermeasures against negative content were deployed in association with Telegram LLP.[200]
In November 2019, Telegram participated in Europol's Internet Referral Action Day.[201] As a result, Telegram expanded and strengthened its terrorist content detection and removal efforts. Over 43,000 terrorist-related bots and channels were removed from Telegram. According to U.S. officials, the crackdown on Telegram was especially effective and seems to be having lasting impact.[202] According to Europol, Telegram has put forth considerable effort in removing abusers of its platform.[201]
Far-right groups[edit]
An article published by Mother Jones magazine on 19 January 2020, says that the Anti-Defamation League has called Telegram a white supremacist "safe haven" and a valuable tool for right-wing extremists. The article said neo-Nazi and fascist hate groups were using the Telegram app to organize a gun rally in Richmond, Virginia, on 20 January 2020.[203] The neo-Nazi white separatist paramilitary hate group The Base switched over to Telegram after being blocked on most social media platforms, including Twitter, YouTube, and Gab, a favorite among extremists. After a number of arrests of The Base members in January 2020, a note appeared on its official Telegram account warning people to stop posting.[204] In August 2019 white supremacist Christopher Cantwell posted anti-Semitic comments on Telegram.[205]
The Anti-Defamation League notes that Telegram was founded by the same two Russian brothers who founded VKontakte (VK), which is known for its lack of moderation when it comes to white supremacy. While Telegram's terms of service prohibit the promotion of violence, they have allowed violent videos posted by mass shooters Brenton Tarrant (Christchurch, New Zealand) and Stephan Balliet (Halle, Germany), although other social media platforms had removed them. The League also points to the RapeWaffen Division channel, which openly advocates rape and murder as part of a race war.[206]
Telegram has also been used by the alt-right organization Proud Boys to coordinate throughout the United States.[207] In the United Kingdom, Telegram is one of the main platforms for far-right publication TR.news, maintained by Tommy Robinson, and Britain First, whose pages were blocked by major social media platforms.[208] Weblinks related to these channels received more views on Telegram in 2018 and 2019 than some well-known mainstream news outlets, including The Guardian or the Daily Mail.[209] However, with a relatively small user base and no algorithmic timeline, such groups struggle to build a larger audience on Telegram.[209]
In January 2021, Telegram confirmed that it blocked "hundreds" of neo-Nazi and white supremacist channels with tens of thousands of followers for inciting violence.[210][211]
Child and teenage pornography[edit]
Due to its liberal privacy policy, the app is often[quantify] used for distribution of pornographic material, including child and teenage pornography.[212][213]
In January 2021, North Macedonian media outlets reported that a Telegram group, with more than 7,000 members, titled “Public Room” (“Јавна соба”) was used to share nude photos of women, often young teenage girls.[214] Along with the shared photographs, anonymous accounts shared private information of the women, including phone numbers and social media profiles, encouraging members of the group to contact the women and ask for sexual favors.[215] This was done without prior agreement or knowing of the women, causing intense public backlash and demand for the group to be shut down. The President of North Macedonia Stevo Pendarovski, along with the Prime Minister of North Macedonia Zoran Zaev, demanded immediate reaction from Telegram and threatened to completely restrict access to the app in the country if no actions would be taken.[216][217]
Data selling bot[edit]
In 2021 a bot was found selling exploited phone numbers from Facebook.[218]
The chairman of the public organization "Electronic Democracy" Volodymyr Flents on 11 May 2020 announced that a Telegram bot appeared on the Web, which sold personal data of citizens of Ukraine. It is estimated that the bot contains data from 26 million Ukrainians registered in the Dіia application. However, subsequently, Deputy Prime Minister and Minister of Digital Transformation Mikhail Fedorov denied fakes about the sale of data from "Dіia". The criminal activity of 25 people has already been confirmed and copies of 30 databases were seized.[219][220][221]
Censorship[edit]
Azerbaijan[edit]
Starting from 27 September 2020, due to the armed conflict in Nagorno-Karabakh, the "Ministry of transport, communications and high technologies of Azerbaijan" imposed temporary restrictions on the use of the Social Media in the country. Telegram, Facebook, WhatsApp, YouTube, Instagram, TikTok, LinkedIn, Twitter, Zoom, Skype were completely blocked. Many other unrelated services were also blocked due to lack of coordination. The restriction was lifted on November 10.[222]
Bahrain[edit]
In June 2016, it was found that some ISPs in Bahrain had started to block Telegram.[223]
Belarus[edit]
Telegram was a key platform for sharing information and coordinating the 2020 Belarusian protests.[224] Telegram was one of few communication platforms available in Belarus during the three days of internet shutdown that followed the election day.[225] On the evening of 11 August, while the Internet shutdown continued, 45 percent of people using Telegram protest chats in Belarus were online, despite the government’s efforts to block online access.[224]
China[edit]
In July 2015, it was reported that China blocked access to Telegram Messenger. According to state-owned People's Daily, Chinese human rights lawyers used Telegram to criticize the Chinese Government and the Communist Party of China.[226]
Hong Kong[edit]
During the 2019–20 Hong Kong protests, many participants used Telegram to evade electronic surveillance and coordinate their action against 2019 Hong Kong extradition bill. On the evening of 11 June 2019, the Hong Kong police arrested Ivan Ip, the administrator of a Telegram group with 20,000 members on suspicion of "conspiracy to commit public nuisance."[227] He was forced by the police to hand over his Telegram history.[227] The next day, Telegram suffered a "powerful" decentralized denial of service attack. Hackers tried to paralyze the target server by sending a large number of spam requests, most of which came from mainland China.[228][229][230][231][232]
On 28 August 2019 the Hong Kong Internet Service Providers Association announced that the Hong Kong government had plans to block Telegram.[233]
India[edit]
In 2019, it was reported that some internet service providers in India were blocking Telegram traffic, including its official website.[234] Internet Freedom Foundation, an Indian digital liberties organisation filed an RTI on whether Department of Telecommunications (DoT) had banned Telegram or requested ISPs to block traffic. The response from DoT said that it had no information on why the ISPs were blocking Telegram.[235] The High Court of Kerala asked about the central government's view on a plea for banning Telegram for allegedly disseminating child abuse videos and communicating through it.[236]
Indonesia[edit]
On 14 July 2017, eleven domain name servers related to Telegram were banned by the Indonesian Communication and Information Ministry with the possibility of closing all Telegram applications in Indonesia if Telegram did not make a standard operating procedure to maintain content that was considered unlawful in the apps.[237] In August 2017, Indonesian Government has opened full access of Telegram, after Telegram has made self censorship about negative contents mainly radicalism and terrorism. Telegram said that about 10 channels/groups have been deleted from Telegram everyday due to are categorized as negative contents.[238]
Iran[edit]
Telegram was open and working in Iran without any VPN or other circumvention methods in May 2015.[239] In August 2015, the Iranian Ministry of ICT asserted that Telegram had agreed to restrict some of its bots and sticker packs in Iran at the request of the Iranian government.[240] According to an article published on Global Voices, these features were being used by Iranians to "share satirical comments about the Iranian government". The article also noted that "some users are concerned that Telegram's willingness to comply with Iranian government requests might mean future complicity with other Iranian government censorship, or even allow government access to Telegram's data on Iranian users".[240] Telegram has stated that all Telegram chats are private territory and that they do not process any requests related to them. Only requests regarding public content (bots and sticker packs) will be processed.[241] In May 2016, the Iranian government asked all messaging apps, including Telegram, to move all Iranian users' data to Iranian servers.[242] On 20 April 2017, the Iranian government completely blocked Telegram's new voice calls, a service that allows individuals to make calls via secure, end-to-end encryption, and keep their conversations private.[243]Mahmoud Vaezi Chief of Staff of the President of Iran said reason for blocking Telegram free voice calls is so Iranian corporations keep revenue from voice calls.[244]
On 30 December 2017, during anti-government demonstrations across Iran, Telegram has shut down a channel of the Iranian opposition that published calls to use Molotov cocktails against the police, after receiving a complaint from the Iranian government. Pavel Durov explained that the reason for the blocking was a "no calls to violence" policy and confirmed that criticizing local authorities, challenging the status quo and engaging in political debate were seen as "OK" by the platform, while "promoting violence" was not.[245] The opposition group promised to comply with Telegram rules and created a new channel which amassed 700,000 subscribers in less than 24 hours.[246] On December, 31, the Iranian government announced that Telegram has been "temporarily restricted" in order to "ensure calm and security" after the company said it refused to shut down peaceful protesting channels.[247] On January, 13, the app was unblocked by an order of the president Hassan Rouhani, who said that "more than 100,000 jobs had been lost” in Iran as a result of the ban on Telegram. Channels of the opposition remain operational.[248]
In March 2018, Iran's chairman for the Committee for Foreign policy and National Security Alaeddin Boroujerdi announced that Telegram has been targeted to be fully blocked in Iran by 20 April 2018,[249] citing Telegram's role in facilitating the winter protests and the need to promote local apps.[250] President Rouhani agreed with the need to break Telegram's monopoly in Iran, but maintained that he was opposed to a new blockade and did not see it as an effective measure to promote local apps.[251] Iranian MP Mahmoud Sadeghi noted that during the two weeks that Telegram was blocked in January 2018, 30 million Iranians (75% of Telegram's users in Iran) did not start using local messaging apps, but instead turned to VPN services to circumvent the block, rendering the blockade ineffective.[252] Telegram was blocked by the government on May 1, 2018.[253] For until one year from the end of the 2017 riots, the Iranian government made available a customized version of Telegram that was under their domain.[254][255][256][257] In 2019 Mohammad Ali Movahedi Kermani in Tehran Friday prayer declared that Telegram is haram and requested National Information Network deployement like Great Firewall of China.[258][259]
On 27 September 2019, Bijan Ghasemzadeh, the Iranian prosecutor who ordered the block on Telegram, was arrested for charges of corruption. It is unclear whether or not the charges were related to the ban on Telegram.[260]
Pakistan[edit]
In October 2017, Telegram was inaccessible to users in Pakistan,[261] and as of 17 November 2017, it has been completely blocked as per instructions from PTA, Pakistan's largest ISP, PTCL mentioned this in a tweet to a user.[262]
Russia[edit]
On 16 May 2017, Russian media reported that Roskomnadzor was threatening to ban Telegram. On 13 April 2018, Telegram was banned in Russia by a Moscow court, due to its refusal to grant the Federal Security Service (FSB) access to encryption keys needed to view user communications as required by federal anti-terrorism law.[263][264] Enforcement of the ban was attempted by blocking over 19 million IP addresses associated with the service.[265] However they included those used by Amazon Web Services and Google Cloud Platform, due to Telegram's use of the providers to route messages. This led to unintended collateral damage due to usage of the platforms by other services in the country, including retail, Mastercard SecureCode, and Mail.ru's Tamtam messaging service. Users used VPNs to bypass the ban as a result.[266][267] On 17 April 2018, Russian authorities asked Apple and Google to pull the service from their stores as well as APKMirror, however Apple and Google refused the request.[268][269] On 28 March 2018, Roskomnadzor reportedly sent a legally binding letter to Apple asking it to remove the app from the Russian version of its App Store and block it from sending push notifications to local users who have already downloaded the app.[270] On 27 December 2018, the largest search engine in Russia, Yandex, removed telegram.org from their search results.[271] On 18 June, the Russian government lifted its ban on Telegram after it agreed to "help with extremism investigations".[272]
Thailand[edit]
On 19 October 2020, the National Broadcasting and Telecommunications Commission was ordered to block Telegram due to its use in the 2020 Thai protests.[273]
US[edit]
In January 2021, former US ambassador Marc Ginsberg filed a lawsuit to remove the app from Google and Apple appstores claiming it is "being used to intimidate, threaten and coerce members of the public."[274]
Reception[edit]
Security[edit]
Telegram's security model has received notable criticism by cryptography experts. They criticized how the general security model permanently stores all contacts, messages and media together with their decryption keys on its servers by default and that it does not enable end-to-end encryption for messages by default.[275][276] Pavel Durov has argued that this is because it helps to avoid third-party unsecured backups, and to allow users to access messages and files from any device.[277] Cryptography experts have furthermore criticized Telegram's use of a custom-designed encryption protocol that has not been proven reliable and secure.[275][278][279][280] However, in December 2020, a study titled "Automated Symbolic Verification of Telegram’s MTProto 2.0" was published, confirming the security of the updated MTProto 2.0 and reviewing it. The paper provides "fully automated proof of the soundness of MTProto 2.0’s authentication, normal chat, end-to-end encrypted chat, and re-keying mechanisms with respect to several security properties, including authentication, integrity, confidentiality and perfect forward secrecy" and "proves the formal correctness of MTProto 2.0". This partially addresses the concern about the lack of scrutiny while confirming the security of the protocol's latest version.[281]
The desktop clients (excluding macOS client) do not feature options for end-to-end encrypted messages. When user assigns a local password in the desktop application, data is locally encrypted also. Telegram has defended the lack of ubiquitous end-to-end encryption by claiming the online-backups that do not use client-side encryption are "the most secure solution currently possible".[282]
Critics have also disputed claims by Telegram that it is "more secure than mass market messengers like WhatsApp and Line",[63] because WhatsApp applies end-to-end encryption to all of its traffic by default and uses the Signal Protocol, which has been "reviewed and endorsed by leading security experts", while Telegram does neither and stores all messages, media and contacts in their cloud.[275][276] Since July 2016, Line has also applied end-to-end encryption to all of its messages by default.[283]
On 26 February 2014, the German consumer organization Stiftung Warentest evaluated several data-protection aspects of Telegram, along with other popular instant-messaging clients. Among the aspects considered were: the security of the data transmission, the service's terms of use, the accessibility of the source code and the distribution of the app. Telegram was rated 'problematic' (kritisch) overall. The organization was favorable to Telegram's secure chats and partially free code, but criticized the mandatory transfer of contact data to Telegram's servers and the lack of an imprint or address on the service's website. It noted that while the message data is encrypted on the device, it could not analyse the transmission due to a lack of source code.[284]
The Electronic Frontier Foundation (EFF) listed Telegram on its "Secure Messaging Scorecard" in February 2015. Telegram's default chat function received a score of 4 out of 7 points on the scorecard. It received points for having communications encrypted in transit, having its code open to independent review, having the security design properly documented, and having completed a recent independent security audit. Telegram's default chat function missed points because the communications were not encrypted with keys the provider didn't have access to, users could not verify contacts' identities, and past messages were not secure if the encryption keys were stolen. Telegram's optional secret chat function, which provides end-to-end encryption, received a score of 7 out of 7 points on the scorecard.[285] The EFF said that the results "should not be read as endorsements of individual tools or guarantees of their security", and that they were merely indications that the projects were "on the right track".[285]
In December 2015, two researchers from Aarhus University published a report in which they demonstrated that MTProto did not achieve indistinguishability under chosen-ciphertext attack (IND-CCA) or authenticated encryption.[286] The researchers stressed that the attack was of a theoretical nature and they "did not see any way of turning the attack into a full plaintext-recovery attack". Nevertheless, they said they saw "no reason why [Telegram] should use a less secure encryption scheme when more secure (and at least as efficient) solutions exist".[287] The Telegram team responded that the flaw does not affect message security[288] and that "a future patch would address the concern".[289] Telegram 4.6, released in December 2017, supports MTProto 2.0, which now satisfied the conditions for IND-CCA.[276][290] MTProto 2.0 is seen by qualified cryptographers as a vast improvement to Telegram's security.[276]
In April 2016, accounts of several Russian opposition members were hijacked by intercepting the SMS messages used for login authorization.[54] In response, Telegram recommended using the optional two-factor authentication feature.[54] In May 2016, the Committee to Protect Journalists and Nate Cardozo, senior staff attorney at Electronic Frontier Foundation, recommended against using Telegram because of "its lack of end-to-end encryption [by default] and its use of non-standard MTProto encryption protocol, which has been publicly criticized by cryptography researchers, including Matthew Green".[275]
Login SMS messages are known to have been intercepted in Iran, Russia and Germany, possibly in coordination with phone companies.[54][291][292] Pavel Durov has said that Telegram users in "troubled countries" should enable two-factor authentication by creating passwords in order to prevent this.[54][291]
In June 2017, Pavel Durov in an interview claimed that U.S. intelligence agencies tried to bribe the company's developers to weaken Telegram's encryption or install a backdoor during their visit to the U.S. in 2016.[293][294]
In 2018 Telegram sent a message to all Iranian users stating that the Telegram Talai and Hotgram unofficial clients are not secure.[295]
Telegram promised since at least March 2014 that "all code will be released eventually", including all the various client applications (Android, iOS, desktop, etc.) and the server-side code.[296] As of December 2020, Telegram still hasn't published their server-side source code.[297][298] In January 2021, Durov explained rationale for not releasing server-side code, citing reasons such as inability for end-users to verify that the released code is the same code run on servers, and a government that wanted to acquire the server code and make a messaging app that would end competitors.[299]
On 9 June 2019, The Intercept released leaked Telegram messages exchanged between current Brazilian Minister of Justice and former judge Sérgio Moro and federal prosecutors.[300] The hypothesis is that either mobile devices were hacked by SIM swap or computers invaded.[301] The Telegram team tweeted that it was either because the user had malware or they were not using 2-step verification.[302]
On 12 June 2019, Telegram confirmed that it suffered a denial-of-service attack which disrupted normal app functionality for approximately one hour. Pavel Durov tweeted that the IP addresses used in the attack mostly came from China.[303]
In December 2019, multiple Russian businessmen suffered account takeovers that involved bypassing SMS single-factor authentication. Security company Group-IB suggested SS7 mobile signalling protocol weaknesses, illegal usage of surveillance equipment, or telecom insider attacks.[304][305]
Cryptography contests[edit]
Telegram has organized two cryptography contests to challenge its own security. Third parties were asked to break the service's cryptography and disclose the information contained within a secret chat between two computer-controlled users. A reward of respectively US$200,000 and US$300,000 was offered. Both of these contests expired with no winners.[306][307] Security researcher Moxie Marlinspike, founder of the competing Signal messenger, and commenters on Hacker News criticized the first contest for being rigged or framed in Telegram's favor and said that Telegram's statements on the value of these contests as proof of the cryptography's quality are misleading. This was because the cryptography contest could not be won even with completely broken algorithms such as MD2 (hash function) used as key stream extractor, and primitives such as the Dual_EC_DRBG that is known to be backdoored.[308][309][310]
2019 Puerto Rico "Telegramgate"[edit]
Telegram was the main subject surrounding the 2019 Puerto Rico riots that ended up in the resignation of then Governor Ricardo Rosselló. Hundreds of pages of a group chat between Rosselló and members of his staff were leaked. The messages were considered vulgar, racist, and homophobic toward several individuals and groups, and discussed how they would use the media to target potential political opponents.
0 Comments