That's absolutely true, but I think the reason this seems so devastating for Telegram is not necessarily because there was a vulnerability, but because they were so dismissive of the feedback they got and so willing to immediately make such strong claims.
The way I hope TextSecure can be different from Telegram is not by having an absolutely perfect security record forever (although that'd be great), but by publicly talking about the protocol choices we've made, employing constructions with proofs where possible, and actively soliciting feedback. Thanks for being involved!
To be fair, no one actually discovered the bridge was made of rotting wood. They seemed focused on the fact that math PhDs design it with no civil engineering background and stated plastic had no known defects.
No. They saw that the bridge was made of such a material, that it would collapse if the material turns out to be anything but steel-reinforced concrete. Which it was pretty likely to be, because it was designed by people who have been, up until now, building igloos.
I think that is incorrect. This is a problem with the protocol which is the main thing people were raising as having a distinct smell and being novel for no good reason so while most of the comments were not about specific flaws they were not unrelated. IGE and SHA1 were the obvious red flags that people involved were not up to date with the latest crypto research.
[Edit: I can't find the comment so I withdraw this claim:
There was at least one comment possibly from moxie mentioning odd use of nonces that may have been in this area, if so it was right on target.]
To make a harsh analogy it's like using a colander for a boat and then complaining that a particular hole wasn't pointed out to them.