While Telegram is seen as a "wild west" of free speech by many, its centralization and worrying lack of encryption for most "non-secret" chats is something to keep in mind when reading Durov's passionate claims. - https://www.wired.com/story/telegram-encryption-whatsapp-set... - https://portswigger.net/daily-swig/amp/multiple-encryption-f... Also, the optional E2EE encryption is way more limited (e.g., single-device,…
Why Telegram had to follow Apple and Google when they suspended a voting app
161–170 of 179 posts
Re: Why Telegram had to follow Apple and Google when they suspended a voting app
#162> First, without support from Apple and Google, any fight with a local regulator is lost before it starts. More evidence of the problem plaguing our current era. These two companies simple should not be authorities above all local regulators.
Re: Why Telegram had to follow Apple and Google when they suspended a voting app
#163Earlier quoted context omitted.
I dont think bots have the flags for blocking only in some apps like channels and groups have. The bot runs on someone else machine and telegram most likely just temporary disabled the token to disable the bot from communicating with the telegram bot API. This then ofc affects all front ends/apps.
Client was showing something like "this content is illegal" instead of bot answers. It is now showing the original answers instead of these placeholders, which means the data was always there, it was just replaced on the fly for accounts with Russian registration.
Re: Why Telegram had to follow Apple and Google when they suspended a voting app
#164Earlier quoted context omitted.
arent they building servers in Go and Rust ? https://matrix.org/docs/projects/server/conduit https://github.com/matrix-org/dendrite
Dendrite is their own project. Conduit is the project of another guy they don't get on with it. The Python server is a memory hog, and instead of rewriting it in a more performant language they have decided to scale horizontally instead. How is that feasible for the average guy who wants to run it on the their own server? https://matrix.org/blog/2020/11/03/how-we-fixed-synapses-sca... https://news.ycombinator.com/ite…
Seems you've mixed something up. Dendrite is a matrix.org project, just like Synapse. Conduit is written by Timo Kösters who is currently employed by Famedly and is on good terms with both matrix.org and Element staff. They frequently cooperate.
Re: Why Telegram had to follow Apple and Google when they suspended a voting app
#165Earlier quoted context omitted.
> The average guy likely doesn't host for thousands of people The python server already has trouble if you subscribe to large rooms. I'm all for promoting Matrix (it's a great project), but the default server has warts and nobody is served by trying to hide them.
Trouble in the sense that the most resource intensive room makes Synapse use about 700 mb of RAM
Re: Why Telegram had to follow Apple and Google when they suspended a voting app
#166Earlier quoted context omitted.
> End of TON project, ment an end of telegram's future as a not data harvesting company. Durov can ask any day of the month for a donation and I'll give it as soon as I have money in hand. $10 - $100, no problem, more in 6 months. In fact even if he bust released a dumb sticker collection I'd buy it just to support Telegram even if I don't use stickers. I guess this holds true for many other ex-Whatsapp enthusiasts a…
do you think a lot of people would be willing to donate to telegram? what would be an average annual donation per user? I bet it would be a lot less than what big tech makes, and there is no reason to believe durov would settle for that
Yes.
> what would be an average annual donation per user?
I don't know but if it was entirely voluntarily, somewhere between 0 and $10 yearly.
> I bet it would be a lot less than what big tech makes, and there is no reason to believe durov would settle for that
That doesn't seem to be Durovs goal.
Re: Why Telegram had to follow Apple and Google when they suspended a voting app
#167Earlier quoted context omitted.
But the server code doesn't mean anything the most important thing is E2EE happen on device and the server is just a messenger. Signal is the most trusted app in authoritarian countries.
No it's not. When Belarus had it's internet blackout last summer, Telegram was the only option to communicate to the outside world. Multiple persons asked if Signal is going to do anything about it, like enable censorship circumvention but it was never addressed[1]. PS. Check the comment section of the tweet. [1] https://twitter.com/signalapp/status/1293377583891980293?lan...
Re: Why Telegram had to follow Apple and Google when they suspended a voting app
#168Here is the thing: Durov lies. There is no law in Russia which forces him to ban that channel, and no concept of “silent days” anymore. Russian authorities has NEVER asked Telegram to remove anything. They pushed Google and Apple to remove links to Navalny application from search and from Apple Store (and Apple removes it only for Russia users, btw, unlike Telegram removes it for everyone), and Telegram was absolutel…
Also that law is applicable to certified mass media like TV, radio, magazines, news papers e.t.c., but not social media, chats, apps, forums e.t.c.
Re: Why Telegram had to follow Apple and Google when they suspended a voting app
#169Earlier quoted context omitted.
If your adversary is happy to block arbitrary network requests, why do they need to get the app removed from the app store? Can't they just block all requests it makes?
He mentioned that Telegram used Google and Apple's notifications to push fresh ip addresses to the app. Russian authorities can't block notifications selectively to the Telegram app, only to all apps that use Google's and Apple's infrastructure.
But they can ask Apple and Google to ban it.
Re: Why Telegram had to follow Apple and Google when they suspended a voting app
#170Earlier quoted context omitted.
It's not. It doesn't work with iOS in practice and requires you to verify each single session instead of just a the people to prevent MITM attacks. Afaik it does not have any audit either
> requires you to verify each single session instead of just a the people What do you mean by that? When no new devices are introduced you only have to verify the fingerprint of each contact once (via QR code). > Afaik it does not have any audit either https://conversations.im/omemo/audit.pdf
But you don't have to verify each contact once, but each session the contact uses