<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security on Cebulka Blog</title>
    <link>https://cebulka.in/en/tags/security/</link>
    <description>Recent content in Security on Cebulka Blog</description>
    <generator>Hugo</generator>
    <language>en-US</language>
    <lastBuildDate>Tue, 11 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://cebulka.in/en/tags/security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Popular Messengers Compared by OpSec Profiles</title>
      <link>https://cebulka.in/en/posts/messengers-compared-opsec-profiles/</link>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://cebulka.in/en/posts/messengers-compared-opsec-profiles/</guid>
      <description>&lt;p&gt;This article evaluates the OpSec profile of popular messengers designed for anonymous and secure darknet communication where enforced end-to-end encryption and anonymity are expected minimum standards. Each messenger is assessed based on security, privacy features, and anonymity guarantees.&lt;/p&gt;&#xA;&lt;h2&gt;Messenger comparison&lt;/h2&gt;&#xA;&lt;p&gt;The list below compares messengers evaluated by their OpSec profile. Enforced anonymity and enforced E2E encryption are considered the expected minimum of a secure-by-default setup.&lt;/p&gt;&#xA;&lt;style&gt;span{font-family:monospace}span.good{color:green}span.bad{color:red}span.minor{color:yellow}&lt;/style&gt;&#xA;&lt;h3&gt;&lt;a href=&#34;https://getsession.org/&#34; target=&#34;_blank&#34; rel=&#34;noreferer&#34;&gt;Session&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Open-source client&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Enforced E2E encryption&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Enforced anonymization (Session network)&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Decentralized&lt;br&gt;&#xA;&lt;h3&gt;&lt;a href=&#34;https://cebxmpp7zrotx57rvlp4iip4uejlbh4l3tygoeou2sdvdjkowker5eqd.onion/&#34; target=&#34;_blank&#34; rel=&#34;noreferer&#34;&gt;OnionXMPP&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Open-source client&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Enforced E2E encryption&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Enforced anonymization (Tor network)&lt;br&gt;&#xA;&lt;span class=&#34;minor&#34;&gt;-&lt;/span&gt; Centralized&lt;br&gt;&#xA;&lt;h3&gt;Cwtch, Ricochet Refresh, Briar&lt;/h3&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Open-source client&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Enforced E2E encryption&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Enforced anonymization (Tor network)&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Decentralized&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; High risk of Guard Discovery attack &lt;span class=&#34;ref-tag&#34;&gt;[1]&lt;/span&gt;&lt;br&gt;&#xA;&lt;h3&gt;Bitmessage&lt;/h3&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Open-source client&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Enforced E2E encryption&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Enforced anonymization (Bitmessage network)&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Decentralized&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; High risk of Sybil attack &lt;span class=&#34;ref-tag&#34;&gt;[2]&lt;/span&gt;&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; Unmaintained since 2018&lt;br&gt;&#xA;&lt;h3&gt;Matrix (Clearnet)&lt;/h3&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Open-source client&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Enforced E2E encryption&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Decentralized&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; No enforced anonymization&lt;br&gt;&#xA;&lt;h3&gt;SimpleX&lt;/h3&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Open-source client&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Enforced E2E encryption&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Decentralized&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; No enforced anonymization &lt;span class=&#34;ref-tag&#34;&gt;[3]&lt;/span&gt;&lt;br&gt;&#xA;&lt;h3&gt;Threema&lt;/h3&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Open-source client&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Enforced E2E encryption&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; No enforced anonymization&lt;br&gt;&#xA;&lt;span class=&#34;minor&#34;&gt;-&lt;/span&gt; Payment linked to identity &lt;span class=&#34;ref-tag&#34;&gt;[4]&lt;/span&gt;&lt;br&gt;&#xA;&lt;span class=&#34;minor&#34;&gt;-&lt;/span&gt; Centralized&lt;br&gt;&#xA;&lt;h3&gt;Signal&lt;/h3&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Open-source client&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Enforced E2E encryption&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; No enforced anonymization&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; SMS verification required&lt;br&gt;&#xA;&lt;span class=&#34;minor&#34;&gt;-&lt;/span&gt; Centralized&lt;br&gt;&#xA;&lt;h3&gt;Tox, Skred&lt;/h3&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Open-source client&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Enforced E2E encryption&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Decentralized&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; No enforced anonymization&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; P2P leaks IP to recipients &lt;span class=&#34;ref-tag&#34;&gt;[5]&lt;/span&gt;&lt;br&gt;&#xA;&lt;h3&gt;Wire&lt;/h3&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Open-source client&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Enforced E2E encryption&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; No enforced anonymization&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; Phone number (if used) and IP shared with authorities&lt;br&gt;&#xA;&lt;span class=&#34;minor&#34;&gt;-&lt;/span&gt; Leaks device and user IDs in push notifications&lt;br&gt;&#xA;&lt;span class=&#34;minor&#34;&gt;-&lt;/span&gt; Collects telemetry and crash reports data&lt;br&gt;&#xA;&lt;span class=&#34;minor&#34;&gt;-&lt;/span&gt; Centralized&lt;br&gt;&#xA;&lt;h3&gt;XMPP (Clearnet)&lt;/h3&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Open-source client&lt;br&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Decentralized&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; No enforced E2E encryption&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; No enforced anonymization&lt;br&gt;&#xA;&lt;h3&gt;Zangi&lt;/h3&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Decentralized&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; Closed-source client&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; Proprietary E2E encryption &lt;span class=&#34;ref-tag&#34;&gt;[6]&lt;/span&gt;&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; No enforced anonymization&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; P2P leaks IP to recipients&lt;br&gt;&#xA;&lt;h3&gt;Telegram&lt;/h3&gt;&#xA;&lt;span class=&#34;good&#34;&gt;+&lt;/span&gt; Open-source client&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; No enforced E2E encryption &lt;span class=&#34;ref-tag&#34;&gt;[7]&lt;/span&gt;&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; No enforced anonymization&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; SMS verification required, bans for virtual numbers &lt;span class=&#34;ref-tag&#34;&gt;[8]&lt;/span&gt;&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; Phone number and IP shared with authorities &lt;span class=&#34;ref-tag&#34;&gt;[9]&lt;/span&gt;&lt;br&gt;&#xA;&lt;span class=&#34;minor&#34;&gt;-&lt;/span&gt; Collects telemetry and crash reports data&lt;br&gt;&#xA;&lt;span class=&#34;minor&#34;&gt;-&lt;/span&gt; Centralized&lt;br&gt;&#xA;&lt;h3&gt;WhatsApp&lt;/h3&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; Closed-source client&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; Snake-oil E2E encryption &lt;span class=&#34;ref-tag&#34;&gt;[10]&lt;/span&gt;&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; No enforced anonymization&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; SMS verification required, bans for virtual numbers&lt;br&gt;&#xA;&lt;span class=&#34;bad&#34;&gt;-&lt;/span&gt; Transparent phone number, IP shared with authorities&lt;br&gt;&#xA;&lt;span class=&#34;minor&#34;&gt;-&lt;/span&gt; Collects telemetry and crash reports data&lt;br&gt;&#xA;&lt;span class=&#34;minor&#34;&gt;-&lt;/span&gt; Centralized&lt;br&gt;&#xA;&lt;h2&gt;Notes&lt;/h2&gt;&#xA;&lt;p&gt;&lt;span class=&#34;ref-tag&#34;&gt;[1]&lt;/span&gt; &lt;strong&gt;&#34;High risk of Guard Discovery attack&#34; (Cwtch, Ricochet Refresh, Briar).&lt;/strong&gt; These messengers communicate over locally hosted Onion Services. While this design has advantages in terms of decentralization, hosting long-lived Onion Services gives an attacker greater opportunities for probing and for various Bandwidth and Rendezvous Point overuse attacks. Hosting an Onion Service has a different threat model than being a Tor client connecting to a server; the chances of a successful Guard Discovery attack and subsequent deanonymization of the Onion Service location are higher. A few experienced administrators who are aware of this risk apply additional mitigations to their Onion Services, but Cwtch, Ricochet Refresh, Briar do not include them. Tor ships with built-in vanguards-lite, which is of limited use and is not designed for hosting long-lived Onion Services. The Tor Project is aware of this but has not yet included the full &#34;vanguards&#34; addon functionality; vanguards-full is planned for Arti, their new experimental Tor client.&lt;/p&gt;&#xA;&lt;p class=&#34;sources&#34;&gt;Sources: &lt;a href=&#34;https://spec.torproject.org/vanguards-spec/full-vanguards.html&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;1&lt;/a&gt;, &lt;a href=&#34;https://blog.torproject.org/announcing-vanguards-add-onion-services/&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;2&lt;/a&gt;, &lt;a href=&#34;https://blog.torproject.org/announcing-vanguards-for-arti/&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;3&lt;/a&gt;, &lt;a href=&#34;https://gitlab.torproject.org/tpo/core/arti/-/raw/main/doc/OnionService.md&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;4&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;span class=&#34;ref-tag&#34;&gt;[2]&lt;/span&gt; &lt;strong&gt;&#34;High risk of Sybil attack&#34; (Bitmessage).&lt;/strong&gt; While Tor has its guard node mechanism and actively seeks and removes malicious nodes based on various characteristics, and while the Session network makes Sybil attacks expensive through a financial barrier, Bitmessage is an example of an open peer-to-peer network with free node entry, highly vulnerable to large-scale Sybil attacks.&lt;/p&gt;&#xA;&lt;p class=&#34;sources&#34;&gt;Sources: &lt;a href=&#34;https://spec.torproject.org/path-spec/guard-nodes&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;1&lt;/a&gt;, &lt;a href=&#34;https://blog.torproject.org/malicious-relays-health-tor-network/&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;2&lt;/a&gt;, &lt;a href=&#34;https://docs.getsession.org/session-network&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;3&lt;/a&gt;, &lt;a href=&#34;https://wiki.bitmessage.org/index.php/Peer_to_Peer_Network&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;4&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;span class=&#34;ref-tag&#34;&gt;[3]&lt;/span&gt; &lt;strong&gt;&#34;No enforced anonymization&#34; (SimpleX).&lt;/strong&gt; SimpleX does not enforce the use of any anonymization network at the network level. Moreover, its authors falsely claim to have implemented &#34;2-hop onion message routing&#34;, which is merely an option for the sender to choose an SMP router and does not differ from using a proxy. This has nothing to do with Tor onion routing and gives users a false sense of security. The SimpleX authors also demonstrate a lack of technical knowledge about anonymity networks; therefore, using SimpleX is discouraged.&lt;/p&gt;&#xA;&lt;p class=&#34;sources&#34;&gt;Sources: &lt;a href=&#34;https://simplex.chat/blog/20240604-simplex-chat-v5.8-private-message-routing-chat-themes.html&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;1&lt;/a&gt;, &lt;a href=&#34;https://simplex.chat/blog/20230204-simplex-chat-v4-5-user-chat-profiles.html#transport-isolation&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;2&lt;/a&gt;, &lt;a href=&#34;https://news.ycombinator.com/item?id=41353555&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;3&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;span class=&#34;ref-tag&#34;&gt;[4]&lt;/span&gt; &lt;strong&gt;&#34;Payment linked to identity&#34; (Threema).&lt;/strong&gt; Although Threema is not a free app and requires a one-time payment, a user can obtain a license through their store using Tor Browser, without an email address, without filling in billing address details, and pay either in cash or in Bitcoin. Although Bitcoin is not a transparent, trackable coin, a payment can be made through an instant swap service from Monero. Moreover, the generated Threema ID is not associated with the payment details. However, this is not anonymous by default, and if done incorrectly, the payment processor may gather the true identity and reveal Threema use upon a law enforcement request. It is therefore considered a minor flaw.&lt;/p&gt;&#xA;&lt;p class=&#34;sources&#34;&gt;Sources: &lt;a href=&#34;https://threema.com/en/pricing&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;1&lt;/a&gt;, &lt;a href=&#34;https://shop.threema.ch/en&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;2&lt;/a&gt;, &lt;a href=&#34;https://threema.com/en/blog/downside-of-user-accounts&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;3&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;span class=&#34;ref-tag&#34;&gt;[5]&lt;/span&gt; &lt;strong&gt;&#34;P2P leaks IP to recipients&#34; (Tox, Skred).&lt;/strong&gt; Tox makes no attempt to cloak your IP address when communicating with others, as the whole point of a peer-to-peer network is to connect you directly to your recipients. It therefore allows IP discovery by law enforcement without a subpoena, if no additional setup with Tor is made. The same weakness applies to Skred messenger as well.&lt;/p&gt;&#xA;&lt;p class=&#34;sources&#34;&gt;Sources: &lt;a href=&#34;https://tox.chat/faq.html#tox-leak-ip&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;1&lt;/a&gt;, &lt;a href=&#34;https://www.skred.app/skred-peer-to-peer-secure-communications-using-webrtc/&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;2&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;span class=&#34;ref-tag&#34;&gt;[6]&lt;/span&gt; &lt;strong&gt;&#34;Proprietary E2E encryption&#34; (Zangi).&lt;/strong&gt; Zangi&#39;s encryption is not open-source and has not been independently audited. There is no public peer review from security researchers. The handshaking mechanism could contain exploitable flaws, whether by mistake or intentional.&lt;/p&gt;&#xA;&lt;p class=&#34;sources&#34;&gt;Sources: &lt;a href=&#34;https://zangiapp.org/does-zangi-use-end-to-end-encryption&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;1&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;span class=&#34;ref-tag&#34;&gt;[7]&lt;/span&gt; &lt;strong&gt;&#34;No enforced E2E encryption&#34; (Telegram).&lt;/strong&gt; All communication is transparent to Telegram by default, and E2E encryption is only available in their &#34;Secret Chats&#34;, which are supported only in the mobile apps. Meanwhile, Telegram markets its messaging platform with a focus on security. In this context, it is worth mentioning that they openly claim to use AI moderation tools for &#34;proactive monitoring&#34;. An OCCRP investigation revealed that Telegram&#39;s network infrastructure is managed by a Russian engineer linked to the FSB. Telegram denies these claims.&lt;/p&gt;&#xA;&lt;p class=&#34;sources&#34;&gt;Sources: &lt;a href=&#34;https://tsf.telegram.org/manuals/e2ee-simple&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;1&lt;/a&gt;, &lt;a href=&#34;https://telegram.org/safety&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;2&lt;/a&gt;, &lt;a href=&#34;https://www.occrp.org/en/investigation/telegram-the-fsb-and-the-man-in-the-middle&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;3&lt;/a&gt;, &lt;a href=&#34;https://www.occrp.org/en/news/telegram-responds-to-investigation-that-links-its-infrastructure-to-russian-security-services&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;4&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;span class=&#34;ref-tag&#34;&gt;[8]&lt;/span&gt; &lt;strong&gt;&#34;SMS verification required, bans for virtual numbers&#34; (Telegram).&lt;/strong&gt; There are many user reports of Telegram banning entire ranges of virtual number operators, which can lead to losing an account later when Telegram is registered through an SMS activation service. Without 2FA enabled, many users of such SMS activation services also have their accounts hijacked, as their chosen phone number is later reassigned to another user.&lt;/p&gt;&#xA;&lt;p class=&#34;sources&#34;&gt;Sources: &lt;a href=&#34;https://gologin.com/blog/telegram-account-banned/&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;1&lt;/a&gt;, &lt;a href=&#34;https://t9gram.com/p/cloud-telegram-password&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;2&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;span class=&#34;ref-tag&#34;&gt;[9]&lt;/span&gt; &lt;strong&gt;&#34;Phone number and IP shared with authorities&#34; (Telegram).&lt;/strong&gt; Telegram changed its policies in 2024 and has agreed to actively cooperate with law enforcement since then. Telegram does not publish transparency reports on its website; they remain obscured in the @transparency bot and are limited to the country in which the Telegram account requesting data is registered.&lt;/p&gt;&#xA;&lt;p class=&#34;sources&#34;&gt;Sources: &lt;a href=&#34;https://thehackernews.com/2024/09/telegram-agrees-to-share-user-data-with.html&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;1&lt;/a&gt;, &lt;a href=&#34;https://te-k.github.io/telegram-transparency/&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;2&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;span class=&#34;ref-tag&#34;&gt;[10]&lt;/span&gt; &lt;strong&gt;&#34;Snake-oil E2E encryption&#34; (WhatsApp).&lt;/strong&gt; Your contact&#39;s encryption key can change legitimately when they reinstall the app, switch devices, or restore a backup. It can also happen when a centralized messaging platform is forced to conduct a Man-in-The-Middle attack and snoop on conversations, and Meta Platforms was accused of doing so in a 2026 lawsuit. WhatsApp automatically re-encrypts and sends your message with the new key without asking for approval. Even if key change notifications are enabled, you will be notified after the message has been sent, therefore a data leak is in such case unavoidable.&lt;/p&gt;&#xA;&lt;p class=&#34;sources&#34;&gt;Sources: &lt;a href=&#34;https://faq.whatsapp.com/1524220618005378/?cms_platform=android&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;1&lt;/a&gt;, &lt;a href=&#34;https://archive.org/download/gov.uscourts.cand.463150/gov.uscourts.cand.463150.1.0.pdf&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;2&lt;/a&gt;, &lt;a href=&#34;https://www.schneier.com/blog/archives/2017/01/whatsapp_securi.html&#34; rel=&#34;noreferrer nofollow&#34; target=&#34;_blank&#34;&gt;3&lt;/a&gt;&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
