Security

Telegram says it has ‘about 30 engineers’; security experts say that’s . . . not good

Comment

The logo for Telegram Signal messenger application arranged on a smartphone.
Image Credits: Lam Yik/Bloomberg / Getty Images

Over the weekend, a clip from a recent interview with Telegram’s founder Pavel Durov went semi-viral on X (previously Twitter). In the video, Durov tells right-wing personality Tucker Carlson that he is the only product manager at the company, and that he only employs “about 30 engineers.” 

Security experts say that while Durov was bragging about his Dubai-based company being “super efficient,” what he said was actually a red flag for users.

“Without end-to-end encryption, huge numbers of vulnerable targets, and servers located in the UAE? Seems like that would be a security nightmare,” Matthew Green, a cryptography expert at Johns Hopkins University, told TechCrunch.

Green was referring to the fact that — by default — chats on Telegram are not end-to-end encrypted like they are on Signal or WhatsApp. A Telegram user has to start a “Secret Chat” to switch on end-to-end encryption, making the messages unreadable to Telegram or anyone other than the intended recipient. Also, over the years, many people have cast doubt over the quality of Telegram’s encryption, given that the company uses its own proprietary encryption algorithm, created by Durov’s brother, as he said in an extended version of the Carlson interview.  

Eva Galperin, the director of cybersecurity at the Electronic Frontier Foundation and a longtime expert in the security of at-risk users, said that it’s important to remember that Telegram, unlike Signal, is a lot more than just a messaging app. 

“What makes Telegram different (and much worse!) is that Telegram is not just a messaging app, it is also a social media platform. As a social media platform, it is sitting on an enormous amount of user data. Indeed, it is sitting on the contents of all communications that are not one-on-one messages that have been specifically [end-to-end] encrypted,” Galperin told TechCrunch. “‘Thirty engineers’ means that there is no one to fight legal requests, there is no infrastructure for dealing with abuse and content moderation issues.”

“And I would even argue that the quality of those 30 engineers isn’t that great,” Galperin continued. “Also, if I was a threat actor, I would definitely consider this to be encouraging news. Every attacker loves a profoundly understaffed and overworked opponent.”

In other words, it’s unlikely for Telegram to be very effective fighting hackers, especially government-backed ones, with such a small staff.

Telegram did not respond to a request for comment, which included questions on whether the company has a chief security officer, and how many of its engineers work full time on securing the platform.

Last week, the well-known cybersecurity expert SwiftOnSecurity wrote on X that “The cost to run a company that has all the right cyber security tools and staff is absolutely obscene.”

“It’s hard to describe the numbers I’ve seen. Even saying this is a gray area. But it is [an] incredible headcount and spend,” SwiftOnSecurity wrote. 

All to say, even the biggest companies on the planet probably don’t spend enough money, time and energy on securing themselves. Telegram has almost one billion users, according to Durov. It’s one of the most popular platforms for people working in crypto (who move millions of dollars), extremists, hackers and disinformation peddlers. 

That makes it an incredibly interesting target for both criminal and government hackers. And it has — at most — just a handful of people dedicated to cybersecurity. 

For years, security experts have warned that people should not see Telegram like a truly secure messaging app. Given what Durov said recently, it may be even worse than experts thought. 

More TechCrunch

Banking-as-a-service (BaaS) platforms are instrumental in driving access to digital financial services by introducing fintech capabilities to non-bank businesses. Multiple businesses are tapping these platforms to circumvent the need to…

Connect Money scores $8M to enable non-bank businesses to offer embedded finance services

Days after the Wall Street Journal reported that Apple and Meta were in talks to integrate the latter’s AI models, Bloomberg’s Mark Gurman said that the iPhone maker was not…

Apple shelved the idea of integrating Meta’s AI models over privacy concerns, report says

TechWolf has built an AI engine that ingests data from internal workflows to learn about the people doing that work.

TechWolf raises $43M to take an AI-sized bite out of the internal recruiting game

The Gurugram-based startup works with Indian factories to help them manufacture fashion wear for global brands.

India’s Zyod raises $18M to expand its tech-enabled fashion manufacturing to more countries

It’s becoming a habit to open each TechCrunch Space newsletter with a bit of an update on Boeing’s Starliner mission, so bear with me.

TechCrunch Space: Building (and testing) for the future

Featured Article

A comprehensive list of 2024 tech layoffs

The tech layoff wave is still going strong in 2024. Following significant workforce reductions in 2022 and 2023, this year has already seen 60,000 job cuts across 254 companies, according to independent layoffs tracker Layoffs.fyi. Companies like Tesla, Amazon, Google, TikTok, Snap and Microsoft have conducted sizable layoffs in the…

8 hours ago
A comprehensive list of 2024 tech layoffs

Telegram’s founder Pavel Durov says his company only employs around 30 engineers. Security experts say that raises serious questions about the company’s cybersecurity.

Telegram says it has ‘about 30 engineers’; security experts say that’s . . . not good
Image Credits: Lam Yik/Bloomberg / Getty Images

Emergence on Monday emerged from stealth with $97.2 million in funding.

Emergence thinks it can crack the AI agent code

The Multi deal seems to fit into OpenAI’s broader recent strategy of investing heavily in enterprise solutions.

OpenAI buys a remote collaboration platform

Car dealerships and auto shops around the U.S. enter a second week of disruption following cyberattacks at software maker CDK.

Car dealership outages drag on after CDK cyberattacks

Consumer technology is hard, but few people have mastered it as well as Matt Rogers, co-founder of Nest and now Mill, his new startup that promises to turn your table…

Matt Rogers, Nest and Mill co-founder, talks mastering consumer tech at Disrupt 2024

Google announced on Monday that it’s bringing its AI technology Gemini to teen students using their school accounts, after having already offered Gemini to teens using their personal accounts. The company…

Google is bringing Gemini access to teens using their school accounts

Shopify merchants can now sell their items to Target’s millions of shoppers, thanks to a new partnership. The companies announced on Monday that sellers on the commerce platform can apply…

Target and Shopify team up to expand Target’s third-party marketplace

A few months after opening a non-compliance case on Apple and the Digital Markets Act (DMA), the European Commission has shared its preliminary findings with Apple. And the bottom line…

Apple’s App Store breaches EU’s Digital Markets Act

Mixhalo Translate couples the startup’s ultra-low latency in-person streaming with AI-generated audio translations.

Mixhalo’s latest feature uses AI to beam real-time translation to phones at events

Prosus, the largest external investor in Byju’s, has written off its 9.6% stake in Indian edtech firm.

Prosus zeroes out its 9.6% stake in Byju’s

Vinod Khosla, the Sun Microsystems co-founder turned prominent investor, talks about how AI is changing tech and the risks of government regulation.

​​What Vinod Khosla says he’s ‘worried about the most’

After a few months of testing during the general elections, Meta is making its Llama 3-powered AI chatbot available to all users in India. However, Meta AI currently only supports…

Meta makes its AI chatbot available to all users in India

We’re at a transitional moment in streaming — user growth is slowing and major players are looking to consolidate, but the long-promised dream of profitability finally seems within reach (especially…

Streaming execs think TV’s future looks a lot like its past

Anika Collier Navaroli is working to shift the power imbalance. She is known for her research and advocacy work within technology.

Women in AI: Anika Collier Navaroli is working to shift the power imbalance

If all goes to plan, Europeans will be able to download and use a free EU Digital Identity Wallet to access a wide range of public and private services.

The EU Digital Identity Wallet: Everything you need to know about the EU’s plans for a universal digital identity system

Featured Article

Silicon Valley leaders are once again declaring ‘DEI’ bad and ‘meritocracy’ good — but they’re wrong

Scale AI founder Alexandr Wang set off another debate with an anti-DEI post. It revealed a lot about the current state of DEI in tech.

2 days ago
Silicon Valley leaders are once again declaring ‘DEI’ bad and ‘meritocracy’ good — but they’re wrong

As Apple enters the AI race, it’s also looking for help from partners. During the announcement of Apple Intelligence earlier this month, Apple said it would be partnering with OpenAI…

Apple might partner with Meta on AI

18-year-olds Christopher Fitzgerald and Nicholas Van Landschoot have founded APIGen, a platform to build custom APIs from natural language prompts.

How 2 high school teens raised a $500K seed round for their API startup (yes, it’s AI)

Welcome back to TechCrunch’s Week in Review — TechCrunch’s newsletter recapping the week’s biggest news. Want it in your inbox every Saturday? Sign up here. This week, Ilya Sutskever launched…

Ilya Sutskever isn’t done working on AI safety

OmniAI is a set of tools that transform unstructured enterprise data into a something that data analytics apps and AI can understand.

OmniAI transforms business data for AI

Charlette N’Guessan is the Data Solutions and Ecosystem Lead at Amini, a deep tech startup leveraging space technology and artificial intelligence to tackle environmental data scarcity in Africa and the…

Women in AI: Charlette N’Guessan is tackling data scarcity on the African continent

Featured Article

‘What’s in it for us?’ journalists ask as publications sign content deals with AI firms

Journalists understand the basic structure of the deals, but they still have questions. 

2 days ago
‘What’s in it for us?’ journalists ask as publications sign content deals with AI firms

Featured Article

This is your brain on Pink Floyd

The human brain has long been a subject of fascination for art and science, which are now both mixed into “Brainstorms: A Great Gig in the Sky,” a new live interactive experience to the tune of Pink Floyd. Interactivity is optional, but memorable. Exhibition visitors can opt in (and pay…

3 days ago
This is your brain on Pink Floyd