{"id":2273,"date":"2026-04-02T13:47:24","date_gmt":"2026-04-02T13:47:24","guid":{"rendered":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/"},"modified":"2026-04-02T13:47:24","modified_gmt":"2026-04-02T13:47:24","slug":"a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless","status":"publish","type":"post","link":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/","title":{"rendered":"A Secure Chat App\u2019s Encryption Is So Bad It Is \u2018Meaningless\u2019"},"content":{"rendered":"<p>TeleGuard, an app that markets itself as a secure, end-to-end encrypted messaging platform which has been downloaded more than a million times, implements its encryption so poorly that an attacker can trivially access a user\u2019s private key and decrypt their messages, multiple security researchers told 404 Media. TeleGuard also uploads users\u2019 private keys to a company server, meaning TeleGuard itself could decrypt its users\u2019 messages, and the key can also at least partially be derived from simply intercepting a user\u2019s traffic, the researchers found.The news highlights something of the wild west of encrypted messaging apps, where not all are created equal.\u201cNo storage of data. Highly encrypted. Swiss made,\u201d the website for TeleGuard reads. The site also says, \u201cThe chats as well as voice and video calls are end-to-end encrypted.\u201d\ud83d\udca1Do you know anything else about this app or other security issues? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.In March an anonymous security researcher, who didn\u2019t provide their name, told 404 Media about a series of vulnerabilities in TeleGuard. They included the fact the TeleGuard app uploads users\u2019 private encryption keys to the company\u2019s server upon account registration.\u00a0Often when implementing encrypted messages, apps will assign users a public and private key. The public key is what other users use to encrypt messages for them, and the private key is what a user uses to decrypt messages meant for them. If this key falls into someone else\u2019s hands, they may be able to read a users\u2019 messages.In true end-to-end encryption, this encryption happens on a user\u2019s phone, and the key should never leave that device. With TeleGuard, the app is transmitting that highly sensitive key to the company\u2019s servers. Technically, the app uploads an encrypted version of the private key, but it also transmits other information that allows the server to decrypt it, the researcher explained. That includes the user\u2019s unique ID, which is also uploaded along with the key; a hardcoded salt (which in cryptography is supposed to be a random string of characters, but in this case is constant); and a hardcoded nonce (which is also supposed to be random for every communication to stop certain attacks, but is constant with TeleGuard). \u201cThe server can decrypt every user&#8217;s private key. It has everything,\u201d the researcher wrote in their findings shared with 404 Media.<\/p>\n<p>That series of design decisions means TeleGuard, the company, receives users\u2019 private keys. But the keys are also accessible to other attackers. The researcher found it\u2019s possible to retrieve a specific user\u2019s private key by simply plugging their user ID into TeleGuard\u2019s API.\u00a0Many people share their user ID publicly so they can be contacted, opening them up to this attack.404 Media asked Dan Guido, CEO and co-founder of cybersecurity firm Trail of Bits, whether his team was able to verify the findings. Guido said the company found much the same thing, and added the app\u2019s encryption \u201cis meaningless,\u201d because of the app uploading the private keys and the server\u2019s ability to decrypt them.Trail of Bits then found multiple other security issues with TeleGuard, including being able to at least partially extract users\u2019 private keys from simply intercepting their traffic. Trail of Bits said it then successfully decrypted one of the shoddily encrypted private keys from that capture.Guido sent 404 Media this meme:\u00a0Image: meme via Trail of Bits.The researcher who initially reached out also said TeleGuard\u2019s metadata\u2014when someone sent a message, and to whom\u2014is in plaintext, meaning that could be exposed to attackers too.TeleGuard launched in around 2021, according to archives of the app\u2019s page on the Wayback Machine. It is made by Swisscows, a company that also makes what it describes as an anonymous search engine, a VPN, and an email service. In a promotional video, TeleGuard claims to have \u201cone of the strongest encryptions available.\u201dNeither TeleGuard nor Swisscows responded to multiple requests for comment, nor gave any indication or timeline of when they might fix the issues.\u00a0TeleGuard has been recommended to cam models as a way to communicate, according to a post on a\u00a0 subreddit for models. The app has also repeatedly been linked to child abusers, with one local media outlet reporting TeleGuard is \u201cnotorious\u201d among prosecutors for child sexual abuse material. The FBI previously obtained data about a TeleGuard user through push notifications sent to their phone. A foreign law enforcement agency had TeleGuard hand over push notification-related data, which the FBI then took to Google to obtain email addresses linked to that alleged pedophile, The Washington Post reported.<\/p>\n","protected":false},"excerpt":{"rendered":"<div>TeleGuard is an app downloaded more a million times that markets itself as a secure way to chat. The app uploads users\u2019 private keys to the company\u2019s server, and makes decryption of messages trivial.<\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-container-style":"default","site-container-layout":"default","site-sidebar-layout":"default","disable-article-header":"default","disable-site-header":"default","disable-site-footer":"default","disable-content-area-spacing":"default","footnotes":""},"categories":[1,13,11],"tags":[3],"class_list":["post-2273","post","type-post","status-publish","format-standard","hentry","category-ai-and-ml","category-news","category-privacy","tag-ai"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>A Secure Chat App\u2019s Encryption Is So Bad It Is \u2018Meaningless\u2019 - Imperative Business Ventures Limited<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"A Secure Chat App\u2019s Encryption Is So Bad It Is \u2018Meaningless\u2019 - Imperative Business Ventures Limited\" \/>\n<meta property=\"og:description\" content=\"TeleGuard is an app downloaded more a million times that markets itself as a secure way to chat. The app uploads users\u2019 private keys to the company\u2019s server, and makes decryption of messages trivial.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/\" \/>\n<meta property=\"og:site_name\" content=\"Imperative Business Ventures Limited\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-02T13:47:24+00:00\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\"},\"headline\":\"A Secure Chat App\u2019s Encryption Is So Bad It Is \u2018Meaningless\u2019\",\"datePublished\":\"2026-04-02T13:47:24+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/\"},\"wordCount\":805,\"keywords\":[\"AI\"],\"articleSection\":[\"AI and ML\",\"News\",\"Privacy\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/\",\"url\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/\",\"name\":\"A Secure Chat App\u2019s Encryption Is So Bad It Is \u2018Meaningless\u2019 - Imperative Business Ventures Limited\",\"isPartOf\":{\"@id\":\"https:\/\/blog.ibvl.in\/#website\"},\"datePublished\":\"2026-04-02T13:47:24+00:00\",\"author\":{\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.ibvl.in\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"A Secure Chat App\u2019s Encryption Is So Bad It Is \u2018Meaningless\u2019\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.ibvl.in\/#website\",\"url\":\"https:\/\/blog.ibvl.in\/\",\"name\":\"Imperative Business Ventures Limited\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.ibvl.in\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/blog.ibvl.in\"],\"url\":\"https:\/\/blog.ibvl.in\/index.php\/author\/admin_hcbs9yw6\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"A Secure Chat App\u2019s Encryption Is So Bad It Is \u2018Meaningless\u2019 - Imperative Business Ventures Limited","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/","og_locale":"en_US","og_type":"article","og_title":"A Secure Chat App\u2019s Encryption Is So Bad It Is \u2018Meaningless\u2019 - Imperative Business Ventures Limited","og_description":"TeleGuard is an app downloaded more a million times that markets itself as a secure way to chat. The app uploads users\u2019 private keys to the company\u2019s server, and makes decryption of messages trivial.","og_url":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/","og_site_name":"Imperative Business Ventures Limited","article_published_time":"2026-04-02T13:47:24+00:00","author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/#article","isPartOf":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/"},"author":{"name":"admin","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02"},"headline":"A Secure Chat App\u2019s Encryption Is So Bad It Is \u2018Meaningless\u2019","datePublished":"2026-04-02T13:47:24+00:00","mainEntityOfPage":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/"},"wordCount":805,"keywords":["AI"],"articleSection":["AI and ML","News","Privacy"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/","url":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/","name":"A Secure Chat App\u2019s Encryption Is So Bad It Is \u2018Meaningless\u2019 - Imperative Business Ventures Limited","isPartOf":{"@id":"https:\/\/blog.ibvl.in\/#website"},"datePublished":"2026-04-02T13:47:24+00:00","author":{"@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02"},"breadcrumb":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/04\/02\/a-secure-chat-apps-encryption-is-so-bad-it-is-meaningless\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.ibvl.in\/"},{"@type":"ListItem","position":2,"name":"A Secure Chat App\u2019s Encryption Is So Bad It Is \u2018Meaningless\u2019"}]},{"@type":"WebSite","@id":"https:\/\/blog.ibvl.in\/#website","url":"https:\/\/blog.ibvl.in\/","name":"Imperative Business Ventures Limited","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.ibvl.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g","caption":"admin"},"sameAs":["https:\/\/blog.ibvl.in"],"url":"https:\/\/blog.ibvl.in\/index.php\/author\/admin_hcbs9yw6\/"}]}},"_links":{"self":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts\/2273","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/comments?post=2273"}],"version-history":[{"count":0,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts\/2273\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/media?parent=2273"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/categories?post=2273"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/tags?post=2273"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}