Live data from Hacker News

Thoughts on the Durov Arrest

prestonbyrne.com

41–50 of 228 posts

Re: Thoughts on the Durov Arrest

#41
e2ee is not a panacea. Law enforcement is more interested in metadata than content: who messaged whom and when, which account corresponds to which phone number etc. This data is still sitting on whatsapp and signal servers, so not much safer than telegram. I'm looking at Element now: at least it doesn't ask for phone number and I can host my own server.

Re: Thoughts on the Durov Arrest

#42

Trying to understand his legal situation by analogizing with US law understanding strikes me as some real Dunning-Kruegering. Surely someone like Preston Byrne has someone he can reach out to to get a better understanding of the actual French legal situation Durov is in.

Yeah, a lot of people, commentators, HNers, Redditors invoke US laws and procedures as reasoning and for comparison. Which is bordering on the useless - okay, you think he wouldn't have been arrested in the US, cool, what does that actually tell us about him being arrested in France? Nothing? You didn't even bother to look up how warrants and arrests and criminal proceedings work in France? Thank you for wasting my time with your commentary.

Re: Thoughts on the Durov Arrest

#43
post #24

Earlier quoted context omitted.

His point is that he can't backdoor it: you can read the code before you install it. I'd go further, and say that this is true of anything end-to-end encrypted, open-source or not, because it's not 2002 anymore and reversing ordinary client software is table stakes. (I'd still rather run something open source, ceteris paribus).

Reversing ordinary client software is table stakes, sure. I'm not so sure about reversing client software which has a deliberately hidden backdoor. (You can hide a backdoor in source code too, of course, but I think it's easier to hide one in a binary because you could e.g. ensure that a buffer overflow overwrites cryptographic keys, where a C compiler would have the freedom to change the memory layout.)

We can just disagree here for now, since we agree directionally, and I think people should use Tarsnap.

Re: Thoughts on the Durov Arrest

#44
post #23

Earlier quoted context omitted.

Indeed. Two of the more common questions I get with Tarsnap are Q. How do I know that Tarsnap is secure? A. Read the source code. Q. Ok, but you're really smart, what's stopping you from putting in a backdoor and hiding it really well? A. I don't want to get tortured, and ensuring that I can't decrypt your data protects *me*.

IMHO second answer does not hold water. If you will end up in situation where you are tortured they will torture you until you will you say how to add the backdoor.

It could be designed that doing so will generate some alarm to other people. For example, the backdoor do not exists and it has to be developed, so the attacker has to keep them hostage for some period of time and loved ones may report a missing person. The software then might have to be signed with a key that generate alert to the whole engineering team, which someone else in the company may investigate the unauthorized release as cyberattack. Perhaps the release signing key is physically stored in the office (eg. Yubikey) which also require the attacker to perform a heist in the office.

Surely some three letters organization probably could pull that off, but it add risk to their operation that the operation could be leaked.

Re: Thoughts on the Durov Arrest

#45

Thinking is not shitting Is there a difference between telegram and other social media messenger hybrids? Do they allow anti Russian content the same way they allow pro Russian content? Is that a problem?

Telegram allows everything and anything, including unsavoury/illegal content (supposedly you can report it and it gets taken down, but potentially the whole crux of the issue Durov was arrested over was that it's not enough/fast enough/law enforcement can't report). There are channels from Russian and Ukrainian officials making official announcements (today our city of X got hit by missiles, please go to ABC if you need help), there are Russian officials using it for official communications (including military and intelligence). There are paramilitaries and other such groups using it for internal and external communications too.

Re: Thoughts on the Durov Arrest

#46
post #15

This is a take I keep seeing, more or less, and yet Telegram is not an encrypted messaging service for the most part, and so Durov could have moderated but actively promoted his not doing so; and the crimes this article leads with, as examples of things that’d get you in trouble in the US too, are said to have been prevalent on Telegram. (Also, maybe it’s nitpicking, but there are very obvious reasons why it’s better…

Read the actual charges. Providing an encrypted means of communication is one of the charges.

Re: Thoughts on the Durov Arrest

#47
post #6

The speculation on this situation is crazy. People are losing their minds over the idea of Durov being arrested over crimes committed on his platform, but we don’t even know the details. For all we know he could have been completely complicit. Hold your horses people.

The article specifically argues about the ex-hypothesis of Durov's involvement in these crimes.

And maybe I misread it, but this thread also argues about that possibility.

Re: Thoughts on the Durov Arrest

#48
post #12

> What it means is that European states are going to try to extraterritorially dictate to foreign companies what content those companies can and cannot host on foreign-based webservers It looks like the author failed to grab that Durov asked for the French nationality and therefore is a French citizen who must comply to French law. > Telegram is not the only company in the world which has a social media platform used…

The author wants to cry against the EU lows because EU bad period. "Don't travel to Europe, don't hire in Europe" and so on. The rest is looking for arguments to support his "hunches".

Re: Thoughts on the Durov Arrest

#49
post #23

Earlier quoted context omitted.

Indeed. Two of the more common questions I get with Tarsnap are Q. How do I know that Tarsnap is secure? A. Read the source code. Q. Ok, but you're really smart, what's stopping you from putting in a backdoor and hiding it really well? A. I don't want to get tortured, and ensuring that I can't decrypt your data protects *me*.

IMHO second answer does not hold water. If you will end up in situation where you are tortured they will torture you until you will you say how to add the backdoor.

Or, you know, hire ANOTHER software engineer to add the backdoor. Probably cheaper and less hassle and less illegal.

In either case, you'd have to fool the internet army, who are watching the source code of projects such as this like a hawk.

Re: Thoughts on the Durov Arrest

#50
post #3

This analysis leaves out the fact that Pavel Durov is, with Telegram, in approximately the same position Ladar Levison was with Lavabit. Unlike Meredith Whitaker, Durov actually is in a position to furnish documents to the French government, where he has citizenship. He's in that position because he has repeatedly made deliberate product decisions, to the bafflement of cryptographers around the world, to keep himself…

While I agree that in many (all?) ways it is that simple, this is an area where there is a lot of scope for there to be unseen pressure from intelligence agencies. The French literally invented espionage (I choose my words carefully here) let alone whatever pressure comes at Telegram from elsewhere. It is hard to be confident in the whys of decision making around large communications tools and security.

Although, ironically, if the French are arresting him now that says good things about Telegram and their willingness to dob customers in.

Post reply on HN