Live data from Hacker News

Telegram reportedly surrendered user data to authorities

androidpolice.com

61–70 of 81 posts

Re: Telegram reportedly surrendered user data to authorities

#61
post #9

Earlier quoted context omitted.

Signal also requires a phone number, IIRC

Yes, a significant flaw, however, it's not that difficult to source a disposable phone number.

It's impossible to get a phone number without a personal ID in a large amount of western countries (number of which is increasing).

Re: Telegram reportedly surrendered user data to authorities

#62

I love Telegram, but it is one of those apps that since it requires a phone number I don't really trust them with ultra-secret data. I think their E2E protocol is fairly sound, but even that isn't ideal. I think you may also get some minimum benefit by using the open-source Android app vs the Google Play Store app. Regardless, if you really desire secrecy (and I believe in privacy but would never advocate for serious…

For me, despite its flaws in E2E, Telegram is the sweet spot for small to medium sized groups. Easy to install, works on every platform I need it, super-simple bot support and the UX is very nice. You even have tools to make write-only groups (microblogs of sorts) and actual moderation tools for larger groups. For a "community", I'd pick Discord though. Matrix as a technology is a good competitor, but the UI/UX for e…

Sounds like you were running with an account on the default matrix.org server? It's gotten faster, but there were a bunch of months when it was dog slow. The point is kinda to run your own server.

Re: Telegram reportedly surrendered user data to authorities

#63
post #59

Earlier quoted context omitted.

"Just fine" by conveniently managing the keys for you. You have no idea what they really do with them. Well, except Threema. Last time I used it, it was not possible to receive their messages across multiple devices simultaneously.

You have no idea what any software does with your keys unless you audit it, then compile and install it on your device yourself. Oh, and audit your compiler. And its compiler...

If you have a piece of software, that can read supposedly encrypted messages on several devices, it is obvious that it does something with the keys. You don't have to audit the compiler and argument into ad-absurdum.

Re: Telegram reportedly surrendered user data to authorities

#64
post #24

Earlier quoted context omitted.

> Terrible advice. If you want e2e you can choose to enable it. It is not enabled because many users choose to receive their messages across multiple personal devices simultaneously. This is not possible with e2e, which is why it is an option. Signal, WhatsApp, iMessage and Threema seem to do just fine.

> iMessage Unrelated to this, but for all intents and purposes, iMessage cannot be considered e2e encrypted if either party has iCloud backups enabled. Apple has access to your iCloud backups, and they contain the iMessage keys.

IIRC With the keys they can technically decrypt in line, backups are not required.

Re: Telegram reportedly surrendered user data to authorities

#65
post #29
post #8

We either accept countries are sovereign over tech companies or not. If tech companies operate with the territory of a country or provide services to citizens in that country, we can expect that they would have to do so under the laws of that land. Those tech companies can choose to withdraw services if they have a problem with doing so. Twitter / FB et al withdrew from the Chinese market (they were not banned by the…

Not necessarily. If a company doesn't engage in commerce then it can be based in one country and provide services in other countries regardless of their laws, so long as their home country is willing to resist attempts by other countries to prosecute them.

Americans and European should use Chinese chat providers and vice versa. No joking. Small Islandoneasea might be bullied to comply.

Best would obviously be to use some FOSS true E2E encryption app that actually prompt you for accepting keys.

Re: Telegram reportedly surrendered user data to authorities

#66
post #59

Earlier quoted context omitted.

You have no idea what any software does with your keys unless you audit it, then compile and install it on your device yourself. Oh, and audit your compiler. And its compiler...

If you have a piece of software, that can read supposedly encrypted messages on several devices, it is obvious that it does something with the keys. You don't have to audit the compiler and argument into ad-absurdum.

The Sesame protocol lets the linked device generate its own keypair, the only thing in common is your user id. Each private key never leaves the respective device.

A talk on the technicals can be found here: https://www.youtube.com/watch?v=7WnwSovjYMs&t=1762s

Re: Telegram reportedly surrendered user data to authorities

#68

It doesn't actually even matter if they did this. The only thing that matters is that they are physically capable of doing so. Telegram is not e2e encrypted by default, and therefore you shouldn't use it if you're concerned about privacy. Look no further than Signal's supboenas and how they respond to them. With all the information they hold about an account. Which is just the creation date and last connection date.…

> It doesn't actually even matter if they did this. The only thing that matters is that they are physically capable of doing so.

Exactly. It could be the truth or Russian psyops to undermine the trust among users, which happens very often from all sides involved, not just during war time. It should be noted that all governments hate private communications systems, except when they suit their needs. That's one more good reason to push for systems offering full e2e encryption by default.

Re: Telegram reportedly surrendered user data to authorities

#69
post #50

Earlier quoted context omitted.

It is particularly amusing that they provided the two date/time pairs in the form of "Unix millis" only. Obviously there's the legal risk of getting the conversion to Gregorian wrong, but I suspect that may have cause some head-scratching at the court.

Meh. In any case involving data/tech I suspect there are people involved who can handle much more sophisticated formats/conversions than this. I may disagree with the government’s stance on privacy, bit they’re not stupid or tech-illiterate.

I regularly help my lawyer friend parse the DVDs she gets from police with the evidence from her case and it's a nightmare collection of proprietary ancient standards for old versions of Windows. They also still use fax machines for everything.

The only place you'd find technical talent is in the federal police or a few guys higher up in the major urban police forensics labs.

Re: Telegram reportedly surrendered user data to authorities

#70

It doesn't actually even matter if they did this. The only thing that matters is that they are physically capable of doing so. Telegram is not e2e encrypted by default, and therefore you shouldn't use it if you're concerned about privacy. Look no further than Signal's supboenas and how they respond to them. With all the information they hold about an account. Which is just the creation date and last connection date.…

Signal is just another walled garden actively fighting decentralization. If it becomes big enough, attacks of big adversaries will be inevitable. Also, the problem with funds. Consider Matrix instead.
Post reply on HN