Live data from Hacker News

Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn

decripto.org

161–170 of 878 posts

Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn

#161
post #127

Earlier quoted context omitted.

Data that is transmitted or stored along with the keys is effectively plaintext, which Telegram does. The data is effectively plaintext on my device, at Telegram, and on the group members' devices, even if it is not plaintext in-between. Data I send to a website over TLS is effectively plaintext on my computer and on the other side; in transit, it is not. It all comes down to your threat model. Encryption does not pr…

> stored along with the keys It's not. They use a split-key encryption system so it's not exactly the same as storing the keys where the data is. > It all comes down to your threat model. Encryption does not protect information from entities who hold the keys to decrypt that information. I agree, which is why I'll say that the bottom line is: Are auditable E2EE algorithms stronger in security than cloud encryption? Y…

> It's not. They use a split-key encryption system so it's not exactly the same as storing the keys where the data is.

Yes, again, it all comes down to your threat model. No one can kick down the door and get to the keys.

But Telegram can get to all the keys, and thus can be legally expected to. The data is effectively plaintext to Telegram.

> Is MTProto 2.0 Cloud Encryption plaintext? No.

Just to note: "effectively plaintext" has been in use for a couple of decades as a term of art. We don't say it's plaintext, because it's not. It means there's effectively no security properties lent by the encryption.

For example, my web browser encrypts a few passwords for me and stores them on disk, but doesn't need a cryptographic secret from me to decrypt them; they're effectively plaintext, because no one has to break any encryption to read them.

Indeed, here's a thread on HN from 2013, where Durov is participating, where people are using "effectively plaintext" in exactly this way to describe exactly what we're talking about: https://news.ycombinator.com/item?id=6937097

Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn

#162

Earlier quoted context omitted.

Because those providers cooperate with authorities and moderate their content to a fairly large degree?

Reddit moderates itself so well that even half the legitimate posts get immediately removed by mods or downvoted by users to oblivion

I've actually given up trying to post on Reddit for this reason. Whenever I've tried to join in on a discussion in some subreddit that's relevant(eg r/chess) my post has been autoremoved by a bot because my karma is too low or my account is "too new". Well how can I get any karma if all my posts are deleted?

Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn

#163

Earlier quoted context omitted.

[flagged]

This has no relevance to the question

You are assuming this is purely a French endevour.

I am assuming the opposite.

Maybe you forgot how us democracies work together for good and evil.

Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn

#164

Earlier quoted context omitted.

Because those providers cooperate with authorities and moderate their content to a fairly large degree?

How does Meta cooperate with the authorities? Isn't Whatsapp supposed to be end-to-end encrypted?

Read the founder exit letter. whatsapp is definitely not e2e encrypted for all features.

You leak basic metadata (who talked to who at what time).

You leak 100% of messages with "business account", which are another way to say "e2e you->meta and then meta relays the message e2e to N reciptients handling that business account".

Then there's the all the links and images which are sent to e2e you->meta, meta stores the image/link once, sends you back a hash, you send that hash e2e to your contact.

there's so many leaks it's not even fun to poke fun at them.

And I pity anyone who is fool enough to think meta products are e2e anything.

Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn

#165

Earlier quoted context omitted.

Because those providers cooperate with authorities and moderate their content to a fairly large degree?

How does Meta cooperate with the authorities? Isn't Whatsapp supposed to be end-to-end encrypted?

isn't meta only end to end encrypted in the most original definition in so much that it is encrypted to each hop. but it's not end to end encrypted like signal.. ie meta can snoop all day

Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn

#167

Earlier quoted context omitted.

Because those providers cooperate with authorities and moderate their content to a fairly large degree?

How does Meta cooperate with the authorities? Isn't Whatsapp supposed to be end-to-end encrypted?

Supporting E2EE doesn’t imply a failure to cooperate. This is not the issue here.

Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn

#168

So let's say I open up a night club. I have to abide the laws and regulations, and make sure things like the following: Minors aren't getting in or being served alcohol, that people aren't selling drugs there, that prostitutes aren't doing business there. If undercover agents come by, and discover that minors are purchasing alcohol - the business will get fined, and likely banned from selling alcohol for some time. I…

Lets say I open up a grocery store. Criminals start buying their food and bookkeeping supplies there. The police discover this. Should I be held liable for fueling and enabling these criminals?

Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn

#169

Earlier quoted context omitted.

Because those providers cooperate with authorities and moderate their content to a fairly large degree?

How does Meta cooperate with the authorities? Isn't Whatsapp supposed to be end-to-end encrypted?

In a number of ways, and probably all the ways that are required by law in your jurisdiction.

Learn more: https://about.meta.com/actions/safety/audiences/law/guidelin...

Yes, WA messages are supposed to be e2e encrypted. Unless end-to-end encryption is prohibited by law in your jurisdiction, I don't see how that question is relevant in this context.

Re: Arrest of Pavel Durov, Telegram CEO, charges of terrorism, fraud, child porn

#170

Earlier quoted context omitted.

> Compared to other apps like WhatsApp with claims of E2EE and no body of verification and validation. We do have at least some empirical evidence that WhatsApp is properly encrypted. WhatsApp's cryptography has made judges in my country foam at the mouth with rage so hard they ordered retaliatory nation wide blocks of the service at least twice. People are right to distrust Meta but I for one am glad that everyone I…

> We do have at least some empirical evidence that WhatsApp is properly encrypted so do we. Telegram's MTProto 2.0 has been audited multiple times by independent researchers, compared to WhatsApp's closed-source claims of E2EE. I'd rather trust a company with a proven track record of no security incidents and fight for user privacy than a corporation which lies through its teeth time and again.

What is stopping Telegram from signing in as you and reading all of your past messages by changing how the authentication logic is handled for specific targeted users? Not saying they have done this, but they obviously could.
Post reply on HN