A lot of privacy guides suggest avoiding Telegram. I understand that in its default mode there’s no E2EE (and no E2EE for groups at all). If people I know don’t wanttko use Signal, isn’t Telegram the lesser evil given it’s nicer privacy policy (than other popular ones)?
Say I use the FOSS version of it.
Despite you using the foss client of telegram there is no source for the server, signal has published it’s code.
True. There’s some trust involved there still, but way less trust needed than with a company that simply doesn’t publish its server code.