Live data from Hacker News

After Delhi High Court ruling, Telegram discloses personal details of users

livelaw.in

121–130 of 230 posts

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#121
post #2

Don't use messengers that ask for your phone number and aren't end-to-end encrypted. Use services that store as little data as possible. If data is stored, it can be given away and I would assume that it will be given away. Telegram disguises itself as encrypted chat app, when it is actually just a regular centralized plaintext messenger that has an encryption feature that nobody uses.

yes. yes yes. yes. yes 100%. the same reason i avoid whatsapp and signal like the plague. "mobile number" is in itself a big identifier when you are living in a place where you have o do mandatory KYC so that the government knows which each mobile number is linked to the actual human being. i dont care signal doesnt hold any messages. the government can ask for my number and they can use the xkcd spanner method to do…

So what exactly is your threat model here that signal doesn't counter? They need to know your phone number before asking signal about it.

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#122
post #78

Earlier quoted context omitted.

In theory you can use OTR[1] but I've yet to see an easy way to use this from a phone. I remember IRC very fondly, but I feel it has a lot of baggage that makes it difficult to bring into the modern era. This blog post (not mine) explains it quite well: https://jlu5.com/blog/im-tired-of-irc-heres-why [1] https://otr.cypherpunks.ca/

OTR doesn't do groups. So it isn't really applicable to IRC. At this point, I am not really sure that end to end encryption is generally applicable to groups. The identity management problem quickly spirals out of control. I note that Telegram doesn't even try. I think the best that can be done is a scheme that makes everyone entirely trust the moderator of the group.

>At this point, I am not really sure that end to end encryption is generally applicable to groups.

You encrypt the message with all the public key's from persons in the group, what's the problem? You do it the same way with Mail...aka pgp.

You don't need OTR just plain old gnupg:

https://www.gnupg.org/gph/en/manual/x110.html

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#123
Does Telegram have a branch in India? What is the teritorial limit of the Indian court decision? Internet is very tricky in this regard, but an Indian court has no jurisdiction over entities that are in other countries (this is also a very complicated matter).

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#124

Earlier quoted context omitted.

yes. yes yes. yes. yes 100%. the same reason i avoid whatsapp and signal like the plague. "mobile number" is in itself a big identifier when you are living in a place where you have o do mandatory KYC so that the government knows which each mobile number is linked to the actual human being. i dont care signal doesnt hold any messages. the government can ask for my number and they can use the xkcd spanner method to do…

So what exactly is your threat model here that signal doesn't counter? They need to know your phone number before asking signal about it.

In much of the world, for the government at least, that is a given: you can't get a phone number without presenting legal ID, and the issuer of the phone number is required by law to maintain this association. This is true in much of Europe, for example.

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#125
post #2

Don't use messengers that ask for your phone number and aren't end-to-end encrypted. Use services that store as little data as possible. If data is stored, it can be given away and I would assume that it will be given away. Telegram disguises itself as encrypted chat app, when it is actually just a regular centralized plaintext messenger that has an encryption feature that nobody uses.

yes. yes yes. yes. yes 100%. the same reason i avoid whatsapp and signal like the plague. "mobile number" is in itself a big identifier when you are living in a place where you have o do mandatory KYC so that the government knows which each mobile number is linked to the actual human being. i dont care signal doesnt hold any messages. the government can ask for my number and they can use the xkcd spanner method to do…

Problem with matrix is ip address. Even with VPN, fingerprinting your messages is a issue. You can't delete your messages, whose copies maybe stored in multiple servers.

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#126
post #82
post #7

Earlier quoted context omitted.

TLDR don't use Telegram and Signal as some "alternatives" Use Matrix clients (Element, Fluffy chat) or Session, Briar (no (video)calls), Delta (no (video)calls), Jami, not recommending Threema because they can tie you through payment and it's centralized Here simple chart to see what to use and not use (use translate feature): https://www.messenger-matrix.de/messenger-matrix.html

Threema can be paid with burner Bitcoin. So I would say that Threema is fairly secure.

Good luck buying bitcoin with cash. I mean it is possible, but hardly anyone does it, thus you can't really anonymously pay for Threema, you have to jump through way too many hoops to use Threema compared to other apps, which is why it's difficult to recommend it.

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#127
post #72
post #37

Earlier quoted context omitted.

It is not. Session and Matrix alone use the same protocol Signal uses without needing your phone number or google play services.

You might want to read up on how Matrix works and what the spec says. (I won’t comment on Session, I’m not familiar with the finer details there.)

I don't use it these days but please enlighten me or show me the specific section you are talking about. Specifically, I was referring to libolm.

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#128
post #71

Earlier quoted context omitted.

True. That does not affect the message integrity and message confidentiality though. So let me ask you this: What’s your threat model? Does your threat model require you to hide your location from the Five Eyes?

In my opinion "secure messenger" should protect from any actor. If we start making exceptions then it cannot be called secure anymore. Signal requires extra information that is not necessary for exchanging messages. That is at least suspicious. If you are fine with giving away your number you can just use WhatsApp or Telegram.

“If you are fine with giving away your number you can just use WhatsApp or Telegram.”

Those projects do not have the same high standards as Signal has. Especially not Telegram. I use Whatsapp for convenience/social reasons, but I definitely prefer Signal for the additional security. Telegram I don’t use at all.

I don’t believe it’s reasonable to throw out the baby with bath water, just because Signal requires a phone number for registration.

Protection from “any actor” would of course be nice – but do you really believe that threat model is reasonable?

Would using Session, Matrix or OMEMO protect against any actor whatsoever?

If we want to base our discussion in reality, I do believe we need to talk about threat models in more detail than “I want protection from any threat actor”.

Let’s take an example:

If I send a message to a friend I don’t want any script kiddies, ISP, cloud provider or advertising agency to be able to read it. I don’t want any passive eavesdropper to be able to read it e.g. by slurping up all traffic from my nearest IXP (i.e. dragnet surveillance). However, if Five Eyes/Mossad/MUST/FSB really wanted some intel on me, they would probably be able to retrieve it if they were willing to spend some resources. But probably not by decrypting my Signal messages. There would be other, far cheaper ways to retreive the info.

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#129
post #127
post #72

Earlier quoted context omitted.

You might want to read up on how Matrix works and what the spec says. (I won’t comment on Session, I’m not familiar with the finer details there.)

I don't use it these days but please enlighten me or show me the specific section you are talking about. Specifically, I was referring to libolm.

This is a starting point: https://nebuchadnezzar-megolm.github.io/

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#130
post #95
post #53

Earlier quoted context omitted.

Most countries require SIM card registration nowadays. https://www.phonetravelwiz.com/phone-travel-options/sim-card... > Of the 245 countries/territories with territory-bound mobile operators, 185 countries have SIM card registration laws. 13 will collect biometrics (fingerprints, but some will take a face scan too). 51 countries have no registration requirements. Which by itself is questionable.

Hmm I didn't think it would be that many. I'm sure there might be workarounds, like ordering online or buying from vending machines at airports, etc., but yeah, it's certainly not as convenient as before.

The problem isn't buying the SIM card, the problem is activating it.
Post reply on HN