Here, the French government is accusing Durov of being complicit with – i.e. aiding and abetting – criminal activity and also unlicensed provision of “cryptological” software, with encryption products subject to prior government authorization before their use in France will be approved.
Thoughts on the Durov Arrest
161–170 of 228 posts
Re: Thoughts on the Durov Arrest
#162Earlier quoted context omitted.
IMHO second answer does not hold water. If you will end up in situation where you are tortured they will torture you until you will you say how to add the backdoor.
His point is that he can't backdoor it: you can read the code before you install it. I'd go further, and say that this is true of anything end-to-end encrypted, open-source or not, because it's not 2002 anymore and reversing ordinary client software is table stakes. (I'd still rather run something open source, ceteris paribus).
All it does is, should that occur, prevent you from giving the torturer what they want to end the torture.
OTOH, convincing the torturer by, among other means, public statements in advance that you have failed to consider this anhd believe that not having that ability prevents torture, and that for this reason you do not have it, might prevent torture. But that's a big gamble on potential future torturers believing your public statements of motivation.
Re: Thoughts on the Durov Arrest
#163This analysis leaves out the fact that Pavel Durov is, with Telegram, in approximately the same position Ladar Levison was with Lavabit. Unlike Meredith Whitaker, Durov actually is in a position to furnish documents to the French government, where he has citizenship. He's in that position because he has repeatedly made deliberate product decisions, to the bafflement of cryptographers around the world, to keep himself…
Indeed. Two of the more common questions I get with Tarsnap are Q. How do I know that Tarsnap is secure? A. Read the source code. Q. Ok, but you're really smart, what's stopping you from putting in a backdoor and hiding it really well? A. I don't want to get tortured, and ensuring that I can't decrypt your data protects *me*.
Q. How do I know that Tarsnap is secure?
A. Read the source code.
This is a "good enough" but less than reassuring answer in the post-Solar Winds world. (It wasn't before, but less so since the advent of "package managers" and the like.) How would someone evaluate the quality and security of the build process and minimal dependencies (which might have their own problems [0])?As a non-security person thinking of how might one could evaluate this: Could adversarial builds (say performed in and using tools commonly available in several locations with different types of government spying) generate the same binary? Could that act as a sort of proof of an untainted toolchain? Or a canary for where a build process is tainted?
Re: Thoughts on the Durov Arrest
#164Earlier quoted context omitted.
> Also the author fails to understand that the complicity here doesn’t mean that companies in Europe are responsible for their users content In the EU, every company is responsible for what their users post on their service. There's a reason you won't find any (or very few) comment sections on the website of EU media and news companies. No one wanted to pay for the moderators needed, so when the law came around most…
Do you have a source for this very outlandish claim? Since most newspapers do have comment sections.
Re: Thoughts on the Durov Arrest
#165The fact that the French president invited Durov to dinner and then arrested him, is so strange. They want to control Telegram, the arrest is just an excuse.
Judiciary power is (somewhat) independent from executive power. Thank god people can still do things without needing Macron's approval.
Re: Thoughts on the Durov Arrest
#166Earlier quoted context omitted.
Maybe? When you login from a new device you're asked to provide an OTP so maybe there is at least that layer of protection and, hopefully, requires some circumvention at the application code level. However I think the real question is: even if that's possible, can law enforcement compel Durov or an employee to do so?
EDIT: I just want to clarify that I don't believe the claim that an employee can intercept the validation code
Re: Thoughts on the Durov Arrest
#167Earlier quoted context omitted.
> in charge of the communications system for one side Telegram us being used by both sides of the conflict. It is as populat in Ukraine as it in Russia. (or other ex-USSR states for that matter)
It's not used by the Ukrainian military. It is used extensively by Russian military and intelligence
Re: Thoughts on the Durov Arrest
#168Earlier quoted context omitted.
That user and the user you are replying to are not misinformed. They are perfectly correct. Telegram does not store messages in plaintext. Period. No matter how shrill the cries from Moxie Marlinespike and his adherents, E2EE is not the only form of encryption. MTProto 2.0 is fully documented and everything the user linked described is true.
There is quite a large amount of people believing that Telegram stores messages in plaintext. I would like to know how they got that idea. So far the best I've got is something along the line of: if you can get your chats when you log in with a new device, then so can a Telegram employee. With no proof of the claim of course.
Re: Thoughts on the Durov Arrest
#169Earlier quoted context omitted.
I just opened telegram, went to ‘find people nearby’ and was immediately presented with a long list of drug dealers and prostitutes advertising their services. I’m pretty sure that’s not legal
Now try to buy from them. They are just scammers who are nowhere near you. They will ask you to send codes from gift cards.
Re: Thoughts on the Durov Arrest
#170This analysis leaves out the fact that Pavel Durov is, with Telegram, in approximately the same position Ladar Levison was with Lavabit. Unlike Meredith Whitaker, Durov actually is in a position to furnish documents to the French government, where he has citizenship. He's in that position because he has repeatedly made deliberate product decisions, to the bafflement of cryptographers around the world, to keep himself…
It’s worse than that, the ‘find people nearby’ feature is a public drug and prostitution advertising billboard with zero moderation and has been for years. They’re in a closer position to silkroad than lavabit