Live data from Hacker News

Telegram is asking German users when to share information with law enforcement

news.ycombinator.com

211–220 of 234 posts

Re: Telegram is asking German users when to share information with law enforcement

#211
post #165

Earlier quoted context omitted.

The signal code is public and has been widely reviewed. We know full well what the server knows regardless of what they say.

Suppose an update is rolled out in app stores, and many people update to it. Suppose this new version contains surveillance instead of matching the published/reviewed code. Won't there be some substantial period of time during which many messages can be stolen before somebody eventually goes on twitter to say "hmm, wireshark shows more data than I'd expect" and/or "hmm, I can't get the source to build quite like the…

Then we're screwed. All mainstream applications running on modern general purpose computers are vulnerable to this.

You don't like that? Stop busting their balls and produce an alternative operating system and application update framework which is not vulnerable.

Re: Telegram is asking German users when to share information with law enforcement

#212
post #165

Earlier quoted context omitted.

The signal code is public and has been widely reviewed. We know full well what the server knows regardless of what they say.

That is at least an indication, but unfortunately not a proof. They could run modified versions on their servers, if they wanted.

No, it simply does not matter what modified version of their server they run. We know what the clients do, and we know what the servers can log. This is a fact as sure as day follows night, and that an apple will fall to the ground when dropped. It isn't even debatable. Your comment is incorrect, full stop.

Re: Telegram is asking German users when to share information with law enforcement

#213
post #165

Earlier quoted context omitted.

The signal code is public and has been widely reviewed. We know full well what the server knows regardless of what they say.

That means the end to end encryption (if you verify your identities) works. It says nothing about how much meta data Signal collects.

We know exactly how much metadata can be collected. You can just look at how the official client works. You can reverse engineer what the server has to do. This not a matter of uncertainty. Signal doesn't mention the collection of the push messaging device IDs explicitly. But that ID doesn't yield a government level adversary any advantage that they don't already have from knowing the phone number, so it doesn't matter. Contact intersection can be logged, then pre-imaged. We can't know. But we already know it can because we know how the clients work. That's it.

Signal doesn't claim cryptographic security against that metadata collection, but then there isn't currently any working system that can make such a claim, so why bust their balls over it?

Re: Telegram is asking German users when to share information with law enforcement

#214

Earlier quoted context omitted.

Kind of, but as they aren't lying about allowing private conversations not really. More saying https is end to end encrypted, but what one end does with that data isn't necessarily private.

https on its own isn't e2ee: >End-to-end encryption (E2EE) is a system of communication where *only the communicating users can read the messages*. In principle, it prevents potential eavesdroppers – including telecom providers, Internet providers, malicious actors, *and even the provider of the communication service* – from being able to access the cryptographic keys needed to decrypt the conversation.[1] If the ser…

The server is the communicating user in this instance, it is the intended recipient of the message. No potential eavesdropping can happen.

Even though I intend for you to read this message, I am sending it to the HN server to post publicly. My communication with HN is E2EE, my communication with you is not. This isn't meant to be useful information, and it certainly isn't advice. It's just an accurate nonstandard way of looking at things.

Re: Telegram is asking German users when to share information with law enforcement

#215
post #3

Hi, German here. How about not storing any information at all? Nothing to give, problem solved. Just like Signal. I seriously don’t understand why people use Telegram instead of Signal. Any reason! The app doesn’t solve any privacy problem, default chats are unencrypted, keeps personal info. App should be dead already or turned into a dating app because it’s clearly not seriously privacy fucused.

Moxie rubs me the wrong way and I don't trust him. So defacto, I don't trust signal.

Re: Telegram is asking German users when to share information with law enforcement

#216
post #167
post #3

Hi, German here. How about not storing any information at all? Nothing to give, problem solved. Just like Signal. I seriously don’t understand why people use Telegram instead of Signal. Any reason! The app doesn’t solve any privacy problem, default chats are unencrypted, keeps personal info. App should be dead already or turned into a dating app because it’s clearly not seriously privacy fucused.

> I seriously don’t understand why people use Telegram instead of Signal. Any reason! Any reason? I’ll give you some serious ones. Signal sucks really bad on user experience and features. If you try both for a week or two and learn about the features, you’d be able to conclude the same. Signal does not care about users and prevents backups on iOS. Lose your device or delete the app due to some issues and reinstall? A…

> Signal does not care about users and prevents backups on iOS. Lose your device or delete the app due to some issues and reinstall? All your chats are gone!

My chats being gone from new devices is one reason I use Signal over others.

> Signal still has message delivery issues (like long delays)…it’s 2022!!!

I've sent tens or hundreds of thousands of messages over the course of years and the only time i've had delays is when I had spotty service.

Re: Telegram is asking German users when to share information with law enforcement

#217
post #158

Earlier quoted context omitted.

Would a secret CIA subsidiary hand over data for a routine civilian court request? If anything not doing so would make their covert surveillance tool even more trustworthy and effective.

The only information Signal can provide is [1]: * Time of account creation * Date of the account’s last connection to Signal servers. That is all. If you want, the link below is the grand jury subpoena for Signal user data, Central District of California, in full. [1] https://signal.org/bigbrother/cd-california-grand-jury/

[deleted]

Re: Telegram is asking German users when to share information with law enforcement

#218
post #75

Sadly I think that it is the slippery slope for Telegram. Instead of the spirit of privacy first, they start to concede little by little for commercial interests. First it is just the IP and phone number. Then, it will be extended to contacts. Because, why not, that can be useful also for "terrorist investigations". Then it will be chat history,because it makes sense, the police has a warrant... And telegram is techn…

Slippery slopes are a logical fallacy for a reason. We live in a society, I don’t see how giving out basic information to law enforcement with a court order is somehow a fault of the company - first of all, your mobile service provider knows orders of magnitude more info on you (and quite likely sells it as well), second of all, your employer will do the same without a second thought as well as your bank, etc.

Slippery slope because the first step is hard to pass: share any data.

Then, just share a few of them, not a big step but it starts the machine of making it easy to share more and more little by little.

First IP, then IP and phone nb, then IP, phone nb, and connection log, then IP, phone, connection log, and geodata; then IP, phone nb, connection log, location data; then IP, phone nb, connection log, location data, contacts; Then IP, phone nb, connection lots, location data, contacts, chats ...

If you look at the "because terrorism" reason, it can apply at any of these data.

No one will say: we think they are terrorist, share their IP but not their location or their chat.

Re: Telegram is asking German users when to share information with law enforcement

#220
post #210

Earlier quoted context omitted.

That was in the past though. Now Signal is storing exactly that same information permanently in the cloud. Specifically they store your name, phone number, photo, and a record of every person you contact.

Metadata is enough to execute people (by certain country but anywhere in the world--it is immoral for Signal to position itself as secure if it provides such data).

Last I checked Signal was outright lying in their privacy policy which was never updated after they started collecting and storing user data in the cloud. You can't morally market yourself as secure while you lie to your users about what their risks are.
Post reply on HN