Whoa, it's absurd if true... I fail to see how being responsible for not cooperating with authorities can be turned into being accused of these crimes. And I don't care for the legal gymnastics which makes this possible - the law exists to serve the public interest and is of no inherent value.
Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn
131–140 of 878 posts
Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn
#132Earlier quoted context omitted.
You're technically right (I think). However, I believe if you witness a murder and know the murderer and the police asks you: "Do you know anything about X murder?" Then I think you're legally required to tell the truth here.
> Then I think you're legally required to tell the truth here. Or you can just not respond, at least in the US. https://en.wikipedia.org/wiki/Self-incrimination
If you're the witness to a murder and you're subpoena'd to court and refuse to testify then you are committing contempt of court. There was a guy in Illinois who got 20 years (reduced to 6 on appeal) for refusing to testify in a murder.
https://illinoiscaselaw.com/clecourses/contempt-of-court-max...
Contempt of court usually has no boundaries on the punishment, nor any jury trials. A judge can just order you to be executed on the spot if you say, fall asleep in his courtroom. Sheriffs in Illinois have the same unbridled power over jail detainees.
Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn
#133Earlier quoted context omitted.
> which makes it an inferior choice compared to even whatsapp I'd rather have a good privacy policy with a good enough server-side encryption than some closed-source implementation of E2EE, that we can never audit. WhatsApp actually disallows you from reverse-engineering the app and looking into the algorithm. That begs the question, what percentage of E2EE is it really? 20%? 50%? 100%? Because there's still no way t…
This is no longer true, whatsapp have taken steps [0] to make their e2ee auditable and honestly I disagree with the idea that no e2ee is better than closed source e2ee. I'm not sure why you would trust a privacy policy more than you would trust encryption, with a court order Telegram would provide your chats to law enforcement, while Whatsapp would not be able to. [0]: https://engineering.fb.com/2023/04/13/security/w…
This is not the algorithm being audited, it's the key. Telegram's complete algorithm is auditable, including the open source client apps. Server code is always unverifiable, so let's not bring that up.
Secondly, WhatsApp channels and large groups (copied from Telegram) are not encrypted in any way (cmiw), as opposed to Telegram's MTProto 2.0 Cloud encryption. The app is completely closed-source even with all their claims of privacy and its TnC even discourages you from reverse-engineering it.
Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn
#134Earlier quoted context omitted.
Telegram also only supports E2EE in one-to-one chats, so any bad guys operating out of group chats / channels are definitely doing so in the clear.
What are the downsides to telegram providing default E2EE? Seems like a no brainer to have it as a default feature for the product.
Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn
#135Earlier quoted context omitted.
They are certainly already on Signal, but Signal has end-to-end encryption so cannot supply information other than meta information to authorities.
This would imply that just E2EEing everything would give you a free pass not to moderate anything, which seems very naive. I doubt the judges would care about their self-imposed technological limitations.
Secure message passing is no different. The "shovel", the thing one might sell, is just the application of some math which does something and not any of the infinite other things.
Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn
#136Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn
#137This seems like the Kim Dotcom situation again. Why are these service providers being punished for what their users do? Specifically, these service providers? Because Google, Discord, Reddit, etc. all contain some amount of CSAM (and other illegal content), yet I don't see Pichai, Citron, or Huffman getting indicted for anything. Hell, then there's the actual infrastructure providers too. This seems like a slippery s…
Dotcom got extradited (which was declared legal much later). Durov landed in a country that had an arrest warrant out for him. I hope his situation isn't similar to Dotcom's, as Dotcom was shown to be complicit in the crimes he was being persecuted for. Convicting the megaupload people would've been a LOT harder if they hadn't been uploading and curating illegal content on their platform themselves. As a service prov…
Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn
#138Whoa, it's absurd if true... I fail to see how being responsible for not cooperating with authorities can be turned into being accused of these crimes. And I don't care for the legal gymnastics which makes this possible - the law exists to serve the public interest and is of no inherent value.
Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn
#139> jpost.com > • 5 hours ago > Pavel Durov, Telegram founder, arrested by France following warrant - The Jerusalem Post > The alleged offenses include: terrorism, narcotic supply, fraud, money laundering and receiving stolen goods. For those unaware, all channel on telegram are NOT ENCRYPTED. They are stored in plaintext on telegram servers. All chats that are not 'secret chat' mode (single device to single device) ar…
Yeah. I have no idea how Telegram got this reputation for privacy. I'd like to point out WhatsApp chats are also end-to-end encrypted, just like in Signal. People aren't wrong to distrust Meta but I'd like to point out that WhatsApp encryption often makes judges here seethe to the point they order nation wide blocks of WhatsApp out of spite. The fact everyone I know uses something this secure makes me very happy. It'…
It's basically a UX tradeoff: You can not promote default E2E + no autobackups -- people in mass are not ready to lose their data when losing the device. Nor they are ready to store the key separately in a confidential manner. Nor they are ready to manually transfer the key among different devices.
All this UX situation is defined by Moxie (the author of Signal and Whatsapp encryption) in his blog post about PGP/WoT concept meeting the reality https://moxie.org/2015/02/24/gpg-and-me.html
So in fact as the average user you have either: 1) E2E + unenctypted autobackup (Whatsapp) or 2) no e2e by default and separate e2e secret chats (Telegram) that are available only on a specific device.
In the first scenario all your chats inclusing the most sensitive are available by the law enforcement by issuing a warrant to your file storage provider. In the second scenario you potentially can spill some sensitive information in default non-encrypted chats.
What is worse? I don't know. But I use both Telegram and Whatsapp with backups turned off. So I'm losing all the Whatsapp chat history when using a new device while losing only secret chats In Telegram (not a problem for me since I delete them often manually or set a self-destruct timer anyway)
Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn
#140> jpost.com > • 5 hours ago > Pavel Durov, Telegram founder, arrested by France following warrant - The Jerusalem Post > The alleged offenses include: terrorism, narcotic supply, fraud, money laundering and receiving stolen goods. For those unaware, all channel on telegram are NOT ENCRYPTED. They are stored in plaintext on telegram servers. All chats that are not 'secret chat' mode (single device to single device) ar…
> They are stored in plaintext on telegram servers FYI, this is a totally misleading and false claim. Telegram uses the MTProto 2.0 Cloud algorithm for non-secret chats[1][2]. In fact, it uses a split-key encryption system and the servers are all stored in multiple jurisdictions. So even Telegram employees can't decrypt the chats, because you'd need to compromise all the servers at the same time. Telegram's algorithm…
I very much doubt that. If Durov wanted to, they could decrypt all of those messages.
That fancy encryption system is worthless when someone can hijack the session of any of the users in a chosen group. This is a risk in many crypto messengers, but those usually come with optional key verification whereas Telegram doesn't have that outside of encrypted one-on-one chats.