Say what you want about their security; they have the absolute best UX of any (primarily 1-on-1) messaging app, bar none.
Discord is a close second. But the quality and polish of telegram blows me away to this day.
And it’s lots of small features and details such as built in translation for messages in a foreign language, all the smooth animations, quick look and summaries of channels with aggregated links media etc, a super fast and responsive UI etc. And their stickers are actually ridiculously fun to play with (I used to not be into that, telegram converted me).
Just yesterday I accidentally found out that it’s possible to replace a picture you have sent, with a new or different one - I sent a photo, realised it would have been better cropped, and just edited the message as I normally would have.
And with all that it’s the only popular messenger that is actually easy to programmatically interact with. (And cheap! WhatsApp has a business offering and it’s ridiculously expensive)
> Say what you want about their security; they have the absolute best UX of any (primarily 1-on-1) messaging app, bar none.
That is precisely because they don't give a shit about security. While others like Whatsapp bother with e2ee and resulting device sync problems and inability to do server-side search, Telegram just stores everything on a server without (meaningful) encryption and boldly claims that 'it is the most secure messenger'. And, imagine that, users just believe that it is the most secure! (I did talk to MANY people who repeated this word for word, 'Telegram is the most secure and encrypted messenger app!', and yes, nobody of them used Secret chats, - it doesn't nicely sync, and nobody needs disappearing messages anyway.
Pretty much no one does any sort of identity verification anyway on any E2EE messaging system. So that means that the people running the servers can MITM if they feel like it to get the content. So in practice Telegram might be the best of something or another for all it matters. It's sort of a con. Yes our E2EE encryption app is perfectly secure assuming you do this thing that we know you won't bother with and will not be able to figure out anyway.
Study based on Signal, but applicable to pretty much all of them:
> Pretty much no one does any sort of identity verification anyway on any E2EE messaging system. So that means that the people running the servers can MITM if they feel like it to get the content.
The fact that anybody can verify keys raises the stakes of attempting a MITM attack significantly and thus protects the majority that doesn't verify keys themselves.
Sure it is a good feature to have, but this sort of attack is going to be targeted. You don't do it to everyone. In the unlikely event you do get caught then you can act dumb in almost all cases. Blame Pegasus or whatever...
I have no illusions about being able to keep a nation state attacker off my devices, but not having all of my correspondence shared with all kinds of third parties by default sure feels nice.
Except that if your target finds out, it would undoubtedly increase their paranoia level, making future attacks against him harder and compromising future operations. There's a reason why law enforcement keeps wiretap warrants sealed.
> Pretty much no one does any sort of identity verification anyway on any E2EE messaging system.
Even my tech-illiterate mother asked if I was hacked or just got a new phone (I got a new phone). The study you link is from 2018, I think it's not a bad assumption to say that people have had some education since then. In 2018 I just started using Signal, nowadays everybody is on it, in my various circles.
> Pretty much no one does any sort of identity verification anyway on any E2EE messaging system. So that means that the people running the servers can MITM if they feel like it to get the content.
Signal makes some cruddy decisions that makes identity verification happen way more often than necessary. Keybase did it better, too bad Zoom bought them just to kill them. Here's their blog post: https://keybase.io/blog/chat-apps-softer-than-tofu . TL;DR:
> Is there a good solution, one that doesn't involve trusting servers with private keys? At Keybase, we think yes: true multi-device support. This means that you control a chain of devices, which are you. When you get a new device (a phone, a laptop, a desktop, an iPad, etc.), it generates its own key pair, and your previous device signs it in. If you lose a device, you "remove" it from one of your remaining devices. Technically this removal is a revocation, and there's also some key rotation that happens automatically in this case.
> The net result is that you don't need to trust the server or meet in person when a partner or teammate gets a new device. Similarly, you don't need to trust the server or meet in person when they remove a device, unless it was their last. The only time you need to see a warning is when someone truly loses access to all their installs. And in that case, you're met with a serious warning, the way it should be:
The problem is that these messengers don't encourage it.
People are more likely to do verification if the app has an inbuilt process giving visual incentives for verification, see Element and Threema.
People care about these features. Tell you what: I care about these features! And I also care about e2ee but I care more about all the things I can’t do with e2ee enabled.
When it matters, I enable secret chats. In the early weeks of the war I used secret chats a ton to organise things (and I echo your observation that most people don’t know about them).
But it doesn’t matter all the time.
Messenger also has e2ee secret chats; they’re awful and don’t have 1/10th the features telegram’s chats have. Hell even telegram’s secret chats are more featureful than WhatsApp chats (which are all e2ee)
I care more that my intimate chats and pictures aren't stored plaintext in corporate and government servers for them to do god knows what than I care about some (cue soyjak face) heckin' stickerinos. But to each his own.
I can't use secret chats because they're only available on mobile, possibly macOS (and Unigram if you use Windows 10), not Windows or Linux, and I like accessing my chats across devices and typing on a physical keyboard.
Telegram is not a tool for sensitive communications, there are far better options if you don't trust some company or have serious adversaries (Signal comes to mind).
But it does aggressively surface the P2P AES256 text chat feature, it does P2P AES256 encrypt voice and video by default (unless I'm badly mistaken), it's got the cute emoji key-verification affordance in voice and video, it does aggressively surface features for allowing people to contact you or not, which is the exact opposite of what a "growth-hacker" PM would do.
How it stands up to a serious security audit is beyond my pay-grade, Moxie seems to think it's weak-ish, and again, that makes it a bad choice if you have credible adversaries.
But I've worked in privacy-hostile settings. Telegram is not privacy-hostile.
Still seems like a good thing. I can use the same app with the same contacts for e2e chats too. Also the calls are e2e encrypted. For now: Telegram is fast with good UX, many contacts, works just fine and is reasonably secure (with their own "credo"). The mentioned above WhatsApp is a closed source client program that can do whatever it wants on your phone, who said that it is not secretly sending any word you type to some telemetry address, while e2e encrypting your chat traffic...
If I were a dissident then given the choice between whatsapp and telegram, telegram wins
"Secret chats use end-to-end encryption, thanks to which we don't have any data to disclose.
To protect the data that is not covered by end-to-end encryption, Telegram uses a distributed infrastructure. Cloud chat data is stored in multiple data centers around the globe that are controlled by different legal entities spread across different jurisdictions. The relevant decryption keys are split into parts and are never kept in the same place as the data they protect. As a result, several court orders from different jurisdictions are required to force us to give up any data."
https://telegram.org/faq#q-do-you-process-data-requests
Telegram is more convenient by default and it can provide security for those who need it.
You must have missed all the very suspicious information about Durov's close ties with Russian authorities, and that Telegram developers worked from the same office with VK in Saint-Petersburg when he claimed that they are in Germany. [1]
I quickly skimmed through the article (it's pretty long) and its main gist is that the author had a conflict with Pavel Durov's brother about his girlfriend, can you elaborate why you think Durov has ties to authorities? I don't see why working in St.Petersburg makes you a Putin ally.
Only two things matters in the security communication business: is the security verifiable, and the reputation of the service provider.
Of these two, Telegram is hardly verifiable: its clients are open-source, BUT the sources in the public repository are updated very rarely, so if T. wants to slip in some malicious code aimed at a specific user to compromise their Secret messages, they can very well do it in a number of ways.
But, given that the vast majority of Telegram users do not even user the secret chats, they can just accest all their chat history without any efforts. Since you can log in to your chat history with just a login and password, the even if chat history is indeed encrypted 'in storage', it is clear that Telegram can decrypt your messages for you. Consequently, they can decrypt it for themselves or for anyone else. (I personally think that they don't even bother, what's the point of doing extra work if nobody sees that anyway?)
Thus, the only thing that users can rely on is Durov's reputation, as a fearless modest person with few material possessions, who was pressured by Russian government to sell his business to Putin's cronies. And here is the problem:
Rosenberg in his series of posts alleges a lot of things. First, that Durov has quite a few material possessions, of which he lied (not a big deal in itself, but it adds up). Then, Durov has lied that once he launched Telegram, T's developers were located in Germany. But they turned out to be working from the same office as his old business, which was taken from him in a rather hostile way. These allegations were never addressed by Durov, the only comment he made was the attack on Anton's personality ('This man is a jerk', basically), and Rosenberg has even won his case in court, proving that his claims for payments, etc were solid and he really did work for Telegram in Russia. Do you have a feeling that Durov's reputation is kinda besmirched by now?
Then, this famous case when Russian censorship agency, Roscomnadzor, has tried to ban it in Russia, and couldn't. For some reason, the most obvious thing you do when banning an app was not done: Telegram had remained on Google Play and Apple's AppStore. We know that Google and Apple have previously complied with Russian government requests to ban apps (as proven in the case of Linkedin), but with Telegram it wasn't done - and all sources claiming that Roscomnadzor has demanded the ban were sourced to Roscomnadzor's own post (I have personally verified about 40 news articles, they all linked either each other or RCN's post) - and it is unclear if this demand was ever officially sent to Google/Apple, neither of them have ever confirmed or denied it. (btw if somebody has a congressman or district attorney pal, it would be good to send an official inquiry to Google and Apple to put this question to rest! Anyone?)
And then we have the 'unban' of Telegram by Russian authorities. This is in itself is unprecedented, for a russian government agency to back down from earlier demands 'because they were unable to make it stick'. Nothing like this has never ever happened, russian government officials just don't function like that, under no circumstances! And the week after the ban, Telegram's top manager sat on the same board with russian government officials! This alone makes me think that all this 'telegram's ban' was a successful special PR operation to build up Telegram's reputation, at the expense of Roscomnadzor reputation, which is below the lowest anyway.
So we have questionable reputation by Durov whom we know to lie about vital things, and we have very suspicious block-unblock story, and nobody really knows anything about Telegram the company and where it is incorporated, etc.
> To protect the data that is not covered by end-to-end encryption
No data (so Signal) is better than whatever legal hoops you're going through to supposedly avoid giving out the data you have. Plus if you look up "telegram data germany", it's not clear that it's actually working and that they're actually true to their word.
Pretty much none of the features mentioned here have anything to do with E2EE security. How did you even try to get to such conclusion (besides really really trying to use it as a segway into your encryption rant)?!
I'm actually very opposing this e2ee everywhere crowd, because we're developing an XMPP app and we're annoyed to death by people who demanding us (ordering even!) to deliver them encryption above anything else and always asking this as a first question.
The comment was more related to a puzzling observation that a reallyseriouspromise of security makes people more happy than actual security. Why bother with providing safety to people if all they need is to feel safe?
> The comment was more related to a puzzling observation that a really serious promise of security makes people more happy than actual security. Why bother with providing safety to people if all they need is to feel safe?
It's called security theater. The TSA is my favorite example of this phenomenon.
While it may not be the most secure, for many casual users the level of encryption provided in cloud chats is good enough for the convenience of smooth cloud sync, which generally doesn't work with E2E messengers and I frequently lose messages when I restore my phone or get a new one. At least they say the encryption keys for cloud chats are scattered across multiple jurdistictions so they wouldn't be able to hand over anything (other than public chats) unless someone got a court order in bunch of different countries at the same time. I would definitely trust them more than WhatsApp even though the latter uses the Signal protocol, but I don't trust Meta to not collect metadata or possibly have other backdoors as well.
Smooth is not the word I would use for them. Though it may very well be only a “frontend” problem and the underlying tech/theory is probably good. But the current implementations are not yet there unfortunately.
The most secure messenger...that just so happens to be developed by a Russian company headquartered in the same building as VK, a known Kremlin-controlled social media network!
WhatsApp is not e2ee. When Facebook displays advertising based on conversations in what’s app. You will never convince me it’s e2ee. It’s fake privacy.
Before being bought by Facebook I would believe it was e2ee. But believe it’s not e2ee between the client and Facebook. They just decrypt analysis and reencypt and forward. Since communication is not peer to peer and goes via FB the key exchange is prob with Facebook not the users.
>They just decrypt analysis and reencypt and forward. Since communication is not peer to peer and goes via FB the key exchange is prob with Facebook not the users.
Do you have any evidence for this, or is this your "better safe than sorry" assumption for every e2e messenger that doesn't allow you to verify keys?
After FB bought WhatsApp I’ve had multiple occasions where shortly after having conversations with people about products I haven’t searched for. The only place I’ve discussed it. Is in a whats app conversation. I got advertising in Facebook for those products.
For example when looking for an apartment I told my agent (non business account) that I wanted safety catches on the windows. I immediately got advertising for safety catches and window gates.
I don’t own cats but in a conversation with a friend who owns cats I said she should get one of those cat tree things and scratch poles. Right away Facebook starts showing me adverts for cat toys.
This is not stuff I’ve searched or googled or anything. Just mentioned in WhatsApp. Maybe WhatsApp whats differently in America but in Singapore I get advertising in Facebook from conversations.
That's... not really good evidence. Your story sounds almost identical to the "facebook/google is eavesdropping on me" stories that frequently make the rounds on popular discourse. Unfortunately, that's basically the Sasquatch of the privacy world (ie. there are many people with anecdotes claiming it exists, but very little in the way of actual evidence like network captures or decompiled binaries). If anything, it's worse than Sasquatch because at least with Sasquatch you could claim that there aren't many of them and/or they're actively avoiding humans so they're hard to photograph, but the "facebook/google is eavesdropping on me" stories implies it's happening to everyone so capturing an instance should only be a matter of technical skill rather than luck.
Can you explain why advertising shows only in facebook, for keywords only used inside an apparently private conversation?
Unless WhatsApp is audited completely, not just looking at some source code but also how all information passes through facebook and back to a receiver. Then we can only assume the e2ee is just marketing fluff and not something that is done in favour of privacy.
> Can you explain why advertising shows only in facebook, for keywords only used inside an apparently private conversation?
obvious explanations:
1. coincidence/luck + confirmation bias. this can also be aided by demographic/interest factors. For instance, suppose there are 10,000 "interests" that facebook tracks. You'd think that for a given conversation that contained such a topic, the chance that you'd see ads for it was 1 in 10,000. However, if the conversation topic was "mechanical keyboards", and facebook knew that you were male, 18-35, and are interested in video games, then it might be able to infer that you're much more likely to be interested in mechanical keyboards and therefore show you ads for mechanical keyboards 1 in 50 times rather than 1 in 10,000 times.
2. the other side ended up leaking the information to facebook (eg. through a search or clicking on an ad)
1. So it's coincidence luck that I get advertising for 'window safty latch for children', as an 'interest' for '18-35'? They knew that I was looking for an apartment and had a kid that was 1yo and thought 'oh you know what that guy needs, window safty latch for his kid'
2. So facebook leaked information that a conversation happened between me and a friend and they thought, oh you know what, Phillip had a conversation with X, and X just search for 'cat toys' so Phillip must want cat toys right now!
> 1. So it's coincidence luck that I get advertising for 'window safty latch for children', as an 'interest' for '18-35'? They knew that I was looking for an apartment and had a kid that was 1yo and thought 'oh you know what that guy needs, window safty latch for his kid'
It seems doubtful that you can hide the fact that you had a 1 year old kid from facebook, unless you're a very sporadic/careful user. Besides, it's not too hard to imagine one of your friends outed you to facebook (eg. posted photo of you with a baby, or mentioning the fact that you have a baby on a post/comment somewhere). From there it doesn't seem too implausible that "had 1 year old kid" was a targeting factor for "window safty latch for children". As for the "looking for an apartment" part, I don't really think that's necessary for sending you ads for safety latches. Even if you live in a house you'd need latches to secure room windows that are on the second floor.
>2. So facebook leaked information that a conversation happened between me and a friend and they thought, oh you know what, Phillip had a conversation with X, and X just search for 'cat toys' so Phillip must want cat toys right now!
e2e provides zero assurances about metadata/social graph. that's been the case since PGP days.
1. I was never hiding that fact. But if those ads showed without any pre-discussion on whats app, i wouldn't care. The point is. Those ad's did not show until shortly after the whats app conversation. That suggests that Facebook is aware of the conversations that occur on whats app that are not business accounts. So e2ee is false.
2. Again, those ad's never showed until shortly after the conversation occurred. I'm talking within ~30m of the discussion.
Majority of people I talk to are Messenger, LINE, and Telegram. So I only have a few people on Facebook. The Business accounts 100% cause me to get advertising on facebook. For example last week the butcher I used to purchase from in Singapore messaged me from his business account advertising arrival of new meat. Boom I get advertising for meat products in Singapore and Taiwan.
The issue is, I have only 3 chats happening in WhatsApp in the last 2 years that are non-business chats. And all 3 have had conversations resulting in advertising.
Business account chat logs are read by Facebook because the chats are sent via other means than WhatsApp. I don’t believe you can verify identity on business accounts either anyway so that’s moot.
As for your other examples, as I said, it’s all very circumstantial and coincidental. Not evidence. Your accusation is more serious than you think, and serious accusations need serious evidence.
I have absolutely no problem accusing Facebook. It's not like they will try to prove me wrong or anything. We only assume that WA is using e2ee, but the reality is they have told us. Never proven it.
>Majority of people I talk to are Messenger, [...]
>The issue is, I have only 3 chats happening in WhatsApp in the last 2 years that are non-business chats. And all 3 have had conversations resulting in advertising.
you realize that Messenger is owned by facebook? I find it baffling that you think the leak must be from whatsapp, when in reality both Messenger and whatsapp are both owned by facebook.
My point is because everyone I know uses other messaging apps, not what’s app. My sample size is very small because I’m not having daily conversations on what’s app. Conversations are happening in other apps.
At best it’s circumstantial anecdotes pointing to Facebook extracting topic metadata out of your convos. This can be done clientside, no decryption necessary. (And it’s easy to prove that it’s being done if that’s the case)
E2EE plus arbitrarily invasive clent-side sniffing/reporting should not be considered "E2EE" by any means. Even if reports to the mothership are strongly encrypted (at which point it becomes harder to determine what's in the reports).
I didn't claim they are. But they can. And without transparency, I have very little inclination to trust. I find it plausible that they'd scan for keywords and phone home when they get hits -- advertising businesses are not known for their scruples and fb has not distinguished itself in that regard. Once that machinery is in place, it's ripe for abuse. I don't claim any proof it's happening, but it would be naive to blindly trust that it isn't.
The person you talked about may have searched for the term, and knowing that you are friends facebook can easily assume that you would be also interested in this thing. It may also operate based on metadata of you have talked recently.
What's more is that the quality of UX manages to be mostly consistent across clients with entirely disparate codebases written in different languages with different UI toolkits.
That's awesome. You have your pick of a massive variety of clients… one of them bound to fit your device setup like a glove. No lowest-common-denominator one-size-fits-all compromises like is so common with cross platform software these days.
It's one of the worst Linux desktop programs I use daily. It gets scaling a bit wrong so all the icons look blurry, scrolling in chats regularly breaks (scroll wheel just does nothing but is fine in all other programs), and the one time I tried to video call in it it crashed. Discord's client is much better.
For what it's worth, Telegram's scaling on windows is also broken. Use it with one 100% and one 200% scaling monitor, on the HDPI everything is too small to read.
Yes their API is one of the best. A simple curl request is enough to send a message and it has been so useful (sentry, uptime, door bell notifications(1), etc).
They also publish a fully functional C library that makes building fully (!) featured 3rd party clients easy. They support everything - from Linux, Windows all the way to Tizen. You compile it into your app and it "just works" with all the features of the main client.
As a result, you have a large set of very good clients for pretty much all platforms.
Imagine if the FLOSS darlings like Signal would make something as amazing as this - a library any plaform (from RPi, watches, etc.) to implement the best possible secure client that fits the user.
Signal's stance on third party clients is so disappointing. Telegram really has them beat there, although it has to be pointed out that Signal actually publishes server source, while Telegram doesn't.
Honestly I found their API one of the worst ones I've ever used. The documentation is lacking, and they have some unintuitive quirks like posting messages with http GET requests and randomly concatenating strings in params (botNAMEOFBOT anyone?).
I didn't enjoy using it without a third party library [1].
Sending a single message is easy, but using the rest of telegram's features is "meh" when using pure API calls.
If you want to see a well designed API, you should take a look at FTX or Stripe. I love those two :)
Of course. Telegram seems to be the clear winner here at convincing the masses to move off of WhatsApp and have them stick around in Telegram. 700M tells us that it is a viable alternative for many users.
Signal on the other hand seems to have failed to stick with the rest of the users and instead of trying to attract users from WhatsApp, not only they can't get backing up messages working properly, they instead were focused on introducing a scam cryptocurrency and wallet only usable on their app that no-one wants, and probably scared everyone off.
Perhaps Signal is only good for getting users to keep using WhatsApp or Telegram, since there are too many missing basic features that the end users keep complaining about when trying it out.
I use Discord for public communications and I don't mind plaintext storage at all - on the contrary, on public chats, I personally value public history.
The last time I've used Matrix actually, usability was a disaster; took me a while to figure out even just how to login, and that wasn't the only problem.
I was asked to login concurrently from two different browsers, every time I wanted to login. It was a very puzzling experience, and took me a while to figure it out, because it was something I've never experienced before in chat systems, and it wasn't spelled clearly, like "you must login from two browsers", in order to compensate for the unusualness.
The UX of communicating with other users was problematic as well. I've tried to establish communications with a certain user, and I have no idea if I succeeded or not (likely not); two separate communications "channels" (I don't know the terminology) were opened with the same user, which is perplexing, since again, this is something I've never experienced before.
I think those two weren't even the only problems I've had.
Did you file a bug? That doesn't happen. Normally you log in. And that's it. On a new device, you can (optionally) verify your account to see previous encrypted comversations. But you don't have to do that.
As for the chat rooms, they work exactly like Discord, which is exactly like every chat client with chat rooms has since the dawn of IRC. You can send a message to one person, or you can join a room and message everyone at the same time.
Do you know how much comments like that help Matrix gain a foothold in the closed source messaging space?
Not all all, that’s how much.
Seriously. Again, huge proponent and financial supporter of matrix efforts here; I think they do an a amazing job. But comments like yours are detrimental to what they do.
People do value that, and they also value a great UX, which Matrix also has. Additionally, matrix, doesn't forcefully associate your plaintext account with your phone number! People with a clue value that.
700,000,000 users disagree with your statements. You can’t make something true by just saying it’s true.
Also your attitude is super toxic. You’re calling people who don’t value the same things you do, “clueless”.
You don’t really get to bullshit people on HN — you can be super smart and skilled in your field, you’ll far too often come across people with vastly more experience than you. I invite you to think about that.
Again, matrix is great, and I see it as the future of messaging. But it’s absolutely not the “present” of messaging; it’s years behind telegram, and the UX of most clients including the more popular ones is garbage.
Its not years behind. That's a lie. In fact Id say it's ahead because you don't need to use a phone number (huge liability), you can choose to use e2e if you want and theyre not storing your data in plaintext!
Oh and all of matrix is totally open source! Wow. That's how you know you can trust it. If they decide to pull a WhatsApp and move to Facebook, you can just fork and get on with your life.
I like that the telegram client is open, but the sever isn't. Which means I don't really trust them. Same problem as Signal.
I used to really like ICQ's floating usernames and email-like modal. A message came in and a little icon appear beside the username (which I used to float in the unused part of my menu bar) along with an audible notification "uh oh!" You double click it, a small chat window opened up with your conversation history and a place to type. You then typed and send your message and the window disappeared until they replied. It was great because you could see who the messages were from without having to use any screen real estate.
Then things like MSN Messenger got popular. Protocols got locked down and screen real estate got consumed. For some reason everyone wanted to use Google Talk (which was horrible but at least spoke XMPP so folks on Pidgin could still chat with their friends). BB messenger taught a few tricks to Apple. Then facebook messenger happened, whatsapp, wechat, etc.
In the background, there were programs like teamspeak and mumble that were trying to do voice chat for gaming reasons. In a way, these were the precursors to Discord who now, for some reason, dominates what people consider a good chat UI. I personally think it's a bloated mess. In my opinion, ICQ had the best chat UI. Because it stayed out of the way.
The translation feature that sends your messages to Google - via an undocumented API and a random selection of User-Agents. This is who you trust your messaging security to?
Who said automatically? You have to enable it. And all it does is save me the round trip to a Google translate prompt anyway so what exactly is the difference?
Seriously, sometimes people are so cynical here it makes my blood boil. Give people some credit, ffs.
Say what you want about their security; they have the absolute best UX of any (primarily 1-on-1) messaging app, bar none.
Discord is a close second. But the quality and polish of telegram blows me away to this day.
And it’s lots of small features and details such as built in translation for messages in a foreign language, all the smooth animations, quick look and summaries of channels with aggregated links media etc, a super fast and responsive UI etc. And their stickers are actually ridiculously fun to play with (I used to not be into that, telegram converted me).
Just yesterday I accidentally found out that it’s possible to replace a picture you have sent, with a new or different one - I sent a photo, realised it would have been better cropped, and just edited the message as I normally would have.
And with all that it’s the only popular messenger that is actually easy to programmatically interact with. (And cheap! WhatsApp has a business offering and it’s ridiculously expensive)