Live data from Hacker News

Telegram founder: US intelligence tried to bribe us to weaken encryption

news.fastcompany.com

21–30 of 220 posts

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#21
post #13

Earlier quoted context omitted.

Even wikipedia say it's founded by the governement ... As of October 2016, the project has received an unknown amount of donations from individual sponsors via the Freedom of the Press Foundation.[100] Open Whisper Systems has received grants from the Knight Foundation,[101] the Shuttleworth Foundation,[102] and the Open Technology Fund,[103] a U.S. government funded program that has also supported other privacy proj…

Funded by the government != The government has their hands all over it

Exactly, the government is extremely large and not all the NSA. Sometimes the left hand doesn't know what all the thousands of right hands are doing and can't possibly care.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#22
post #13
post #11

Earlier quoted context omitted.

Bingo. The CEO of Telegram likes to spread conspiracy theories that are good for business. In a recent tweet he claimed that Signal is "funded by the US government", [1] citing a ridiculous hit piece on OWS and Moxie. [2] [1] https://twitter.com/durov/status/872891017418113024 [2] https://surveillancevalley.com/blog/government-backed-privac...

Even wikipedia say it's founded by the governement ... As of October 2016, the project has received an unknown amount of donations from individual sponsors via the Freedom of the Press Foundation.[100] Open Whisper Systems has received grants from the Knight Foundation,[101] the Shuttleworth Foundation,[102] and the Open Technology Fund,[103] a U.S. government funded program that has also supported other privacy proj…

Supporting Cryptocat only makes sense if they don't do due diligence or if they're trying to subvert security.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#23

This is pretty alarming stuff. Especially considering how that competitors like Signal are US based. Signal is owned by twitter which by no means is a small player, so it isn't likely to fly under anyones radar.

Signal is not owned by Twitter. Moxie works there, but that doesn't mean his code is owned by Twitter.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#24
post #19
post #13

Earlier quoted context omitted.

Even wikipedia say it's founded by the governement ... As of October 2016, the project has received an unknown amount of donations from individual sponsors via the Freedom of the Press Foundation.[100] Open Whisper Systems has received grants from the Knight Foundation,[101] the Shuttleworth Foundation,[102] and the Open Technology Fund,[103] a U.S. government funded program that has also supported other privacy proj…

The tweet he was replying to said: "I've heard various reports from people I trust that Signal is compromised. Any comments/thoughts/reliable rumors?" With his reply, Durov is implicitly claiming that Signal must be compromised because it received some funding that can be traced back to the US government. This is the same kind of FUD that has often been used to smear Tor in the past (and indeed, the piece he cites de…

That fits the profile of a conspiracy theory.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#25
Hmmmm.... A Russian peddling undocumented crypto warez implies US crypto is untrustworthy despite the obvious open source code. Don't suppose this would be one of Putin's patriotic citizen artists spreading fake news do you?

Edit: thanks to all the replies. I am smarter now.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#26
The problem I have as an end user is that I want the infrastructure protecting me to be invisible. Let's return to this after the following paragraphs. I will make some pretty far-reaching conclusions.

I think we can all agree that if some totally below-the-radar crypto anarchist who happens to have a few million dollars from bitcoins figured out that they actually have enough access via the dark web to bribe a few Russian generals and long story short detonate a nuclear bomb a few miles outside New York City, just for shits and giggles, then they should be stopped at some point along the way. This will seem like a made-up example to you but I purposefully don't want to confuse the issue with practical examples. We can all agree that at some point this should be stopped.

A reasonable time to stop it might be if intelligence agencies get a literal screenshot from a darkweb chatroom (from a concerned participant, where the participant thinks they're really going too far) where this is being planned in exacting detail but more information is needed to be precise. (For example, suppose the source of the nuclear bomb were not Russia but not enough information was given to identify it. There are actually quite a few nuclear states and many of them are quite corrupt. A short list includes India, North Korea, Pakistan.)

I would think that this kind of actionable urgent intelligence should unlock whatever privacy safeguards are in place, but the issue is that if there is a correct "technical" solution (if cryptography works 'correctly' and is not broken, in an academic sense), then there is no technical possibility to unlock anything. If Tor, crypto currencies, and encryption "work" (in a binary, yes it works, or no, it's broken sense) then following the receipt of such a screenshot there is no technical means of any further step.

Here I'm going to be philosophical for a second. The future of technology is nearly infinite human power. You can already in the next few seconds initiate a crypto currency transfer to anyone anywhere in the world, who can receive it without any banking infrastructure or oversight.

The arc of technology has been personal human enablement. When individuals become nearly God-like and all-powerful, it is dangerous to be in a position where, like the Muslims reporting the madman banned from his U.K. mosque for radical insanity, the status quo is that if you report your friend to the authorities saying, "My online friend, God-like in his powers, is planning to murder a million people just for shits and giggles, and he's kind of insane. Unfortunately, I don't know where he is or what he's doing, but I'm pretty concerned. He has a lot of money from a few ponzi schemes he ran. It's pretty credible for the following specific reasons (screenshots, quotes, etc)." And the only response from the authorities is, "Thanks for all this. We don't know where he is either, in the grand scheme of things a million deaths isn't that much and if it happens we will look at preventing another such case."

That's a pretty silly response, isn't it? That the only possible response is, sorry, nothing can be done.

Okay, now I've laid out why there should probably be some infrastructure on the back-end.

What I don't like is that this translates to humans literally reading people's private correspondence, web searches, etc. It's not very good.

What is a good middle ground?

Can't the NSA make things that run locally, so that no human is reading your correspondence or web traffic, but as you start researching nuclear weapons and making plans on how to murder a million people, and start making those transactions, all this starts adding up and, to quote the Constitution, its tools can receive instructions "particularly describing the place to be searched, and things to be seized", so that after such a report, its perpetrator can be found, or at least enough information can be collected to stop it if it is actually taking place?

I think that all of us here could be okay with being stopped at some point between purchasing a hundred million dollars in anonymous currency, and detonating a nuclear bomb. It's sensible. That can be part of the social contract.

It's difficult. Nobody wants to live with a judge, jury, and executioner in their home looking at everything they are doing in case they break some law.

I am glad that I personally don't have to answer these questions. But we can all agree on the need for privacy (no human looks at what you're doing), and also on the reasonableness, as each individual online progresses toward infinite personal power, for protecting the rest of society from credible and immediate, specific threats.

I agree with cryptographers who think of cryptography as a tool that is either working or broken. (If it has a back door, it's 'broken').

Perhaps if tools included a certain portion that runs locally they could increase the extent to which the tools are not actually 'broken' (i.e. they are actually working, and actually not backdoored), while also increasing the safety every single person has from other individuals being able to plan or pay for their specific death anonymously, and with impunity.

I realize that my suggestions here are not specific enough to be actionable, they are not clear recommendations. But I don't even see these possibilities being discussed (at least publicly), so I wanted to at least move the conversation a bit in this direction.

EDIT:

---

I'm getting downvoted pretty heavily. Let me ask point-blank: are you okay with someone being able to spend two weeks on the dark-web researching how to make and detonate a bomb using totally innocent chemical purchases, and then your spouse, parents, relatives, or you, being an innocent victim of my exploding the results, or would you want that person to be stopped at some point after they started doing that? The future of information is that it is ubiquitous and easy to access [I edited this paragraph edited from first to third person.]

Actually secure communications would mean that it is technically impossible to see if someone has started communicating with people at ISIS who have overseen and helped people explode themselves. I am not saying communication should be weak and insecure, but should I really practically be able to start doing that if I want?

This is not some kind of false example, either.

Also, for downvoters: I think it is easier for you to agree with the other half of my statement, that nobody should be looking at our web traffic and correspondence, and that it should be actually secure, and also actually private.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#27
post #8

Assuming this isn't just PR, in some ways this is scary and disheartening. But my first reaction was "Cool, our government really cares, is creative and has the necessary power to get things done." For those of you who've worked with government, you've seen how insanely difficult the procurement process is. Being as specific as needing to get competitive bids for toilet paper purchases, etc. So the fact that they cou…

> Cool, our government really cares I wonder what they really care about? Liberty, individual rights, security, or more power? They're people too, so I'm sure they believe in the first three, but the last one is a more seductive and drives a lot more of the bad we see governments do; worse is that the drive for more power is frequently justified as "we need this power to protect our nation". > has the necessary power…

One... to see if you are for sale. If you can be bought, other state actors will try and may succeed, whether US actually bribes you or not. US needs to know if a successful App is up for taking bribe, including top developers individually, or not, because millions of Americans including persons in position of power might be using that app.

Two... essentially, this is power of people applied. Lot of interest in keeping status quo of power, of narrative, of money. They want to have dirt on everyone and then choose to use it when needed. Putting pressure or not can be decided later, dirt will be collected by default. No point in digging the well when you are thirsty, you need to do it well upfront the need arising.

>What checks and balances are in place to keep this kind of power in check?

Either play the game, or be too big to fail and lobby the government for your needs. I think the best one can do is choose your masters either USA, China, Russia or to some extent India or EU main players.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#28

This is pretty alarming stuff. Especially considering how that competitors like Signal are US based. Signal is owned by twitter which by no means is a small player, so it isn't likely to fly under anyones radar.

Signal is owned by twitter

No. OWS != WS

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#29
post #12

"a few months later i was offered an interview for a position at the fbi office for cyber-warfare in nyc who as well offered to fix my immigration status" and, "before going to monterey and while exploring the beauty of san francisco i was contacted once by a us navy intelligence officer who seemingly unintentionally appeared next to me at the bar" http://mickey.lucifier.net/b4ckd00r.html

Would you mind clarifying what your quotes and the linked wall of text have to do with the story?

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#30

Hmmmm.... A Russian peddling undocumented crypto warez implies US crypto is untrustworthy despite the obvious open source code. Don't suppose this would be one of Putin's patriotic citizen artists spreading fake news do you? Edit: thanks to all the replies. I am smarter now.

> A Russian

Russophobia seems to be the only acceptable form of Xenophobia these days. And a wildly popular one, at that.

Post reply on HN