Live data from Hacker News

Thoughts on the Durov Arrest

prestonbyrne.com

181–190 of 228 posts

Re: Thoughts on the Durov Arrest

#181
post #24
post #23

Earlier quoted context omitted.

IMHO second answer does not hold water. If you will end up in situation where you are tortured they will torture you until you will you say how to add the backdoor.

His point is that he can't backdoor it: you can read the code before you install it. I'd go further, and say that this is true of anything end-to-end encrypted, open-source or not, because it's not 2002 anymore and reversing ordinary client software is table stakes. (I'd still rather run something open source, ceteris paribus).

He probably should have said that if it's what he meant. In his answer he implies that he could in fact back door it but chooses not to because of the liability.

Re: Thoughts on the Durov Arrest

#183
post #156

Earlier quoted context omitted.

There is quite a large amount of people believing that Telegram stores messages in plaintext. I would like to know how they got that idea. So far the best I've got is something along the line of: if you can get your chats when you log in with a new device, then so can a Telegram employee. With no proof of the claim of course.

Somehow they must transfer the chat history from their servers to the user. Either it's plain text, or encrypted and they either use the keys to decrypt or send the keys to the user along with the encrypted content. In all cases they can simply access the contents themselves.

I think this statement requires a stronger argument, since even if they could have access to the data in theory there are concrete implementations where it could be extremely unfeasible.

For example, since we are in the realm of speculations, I propose the following alternative to the plaintext or accessible decryption keys: the decryption could happen inside a nitro enclave making it essentially impossible to access the data without changing the application code.

I'm not saying that this is what happens, just that I don't think that one can so easily deduce that "they can access the data" just from the fact that "they send you chat history to you".

Re: Thoughts on the Durov Arrest

#184
Articles about Telegram and similar encryption problems always tend to hit the very manipulative topics. Terrorism and CSAM are always used. The four horsemen methodology for control.

The point is to emotionally manipulate the audience into complicity. To cause people not to question the underlying privacy and legal issues.

Instead they want the reader to have thoughts of large numbers of people, in organized networks presumably, that want to cause terror to them or harm to their children.

This causes a reaction in many people to forget about basic rights and focus on the fear they have been given instead.

I'm sure France and the U.S. have a million reasons to want this data from the Ukraine war, to probably some cases of the things they claim. However, it is definitely exaggerated and no one should be willing to trade the ability to communicate privately out of some fear that people who want to harm you are also able to communicate privately.

None of it really makes any logical sense because at the end of the day, to end all encryption means the Government would have to basically criminalize math.

So of course they rely on the reliable methods of emotional manipulation. I mean, they should have a blank check to go after this guy and anyone else, right? You don't support terrorism do you???

Re: Thoughts on the Durov Arrest

#185
post #169

Earlier quoted context omitted.

That's not legal either

guess my e-mail provider is going to jail.

Does your email provider cooperate with law enforcement when they show up with a warrant and want details about an email/account involved in criminal activity?

Re: Thoughts on the Durov Arrest

#186
post #156

Earlier quoted context omitted.

There is quite a large amount of people believing that Telegram stores messages in plaintext. I would like to know how they got that idea. So far the best I've got is something along the line of: if you can get your chats when you log in with a new device, then so can a Telegram employee. With no proof of the claim of course.

If the chat is not end-to-end encrypted, which Telegram “cloud” chats are not, then by definition Telegram (the company) has access to the chats. Full stop.

Something being true only by definition is unfortunately a very weak claim.

For example the company servers could be hosted on an island with armed guards instructed to burn everything if anyone approaches and the decryption happens only on those servers: sure they have access by definition, but they really don't.

Re: Thoughts on the Durov Arrest

#187
post #166
post #108

Earlier quoted context omitted.

EDIT: I just want to clarify that I don't believe the claim that an employee can intercept the validation code

There existed one server which sent the code, so whomever administrated that server could trivially have intercepted it by just modifying the software running there to copy/log it to them.

This could be extremely unfeasible. For example the code could be generated by a third party and encrypted before arriving on a server controlled by telegram and sent to the user. Or it could be generated inside a nitro enclave. Sure ultimately someone could modify the server code somewhere to log the code or any other specific message before it gets encrypted, but at this point we are talking about inserting a backdoor.

Re: Thoughts on the Durov Arrest

#188

The fundamental problem we have right know is that we know the charges, but not the factual allegations that underlie those charges. Put differently, if you wanted to put together a charge list for the head of a large social media company you didn't like, this is what it would look like. If you wanted to put together a charge list for someone actively running the group chat of a terrorist group... this is what it wou…

I just opened telegram, went to ‘find people nearby’ and was immediately presented with a long list of drug dealers and prostitutes advertising their services. I’m pretty sure that’s not legal

Every once in a while I find a slip of paper in my postbox with the contact info of a local drug dealer. The police can't be bothered arresting them and even if they do such a dealer gets replaced in hours anyway. They use WhatsApp.

I think it's CP that gets Telegram in hot water. Prostitution or drugs bothers noone but pedophiles trading stuff wakes everyone up.

Re: Thoughts on the Durov Arrest

#189
post #185

Earlier quoted context omitted.

guess my e-mail provider is going to jail.

Does your email provider cooperate with law enforcement when they show up with a warrant and want details about an email/account involved in criminal activity?

Did telegram not? They do ban those; the channels and accounts are getting deleted. Some content is available in one country and not available in other countries. Imo we need more data to tell what was happening and how fair these accusations are.

Re: Thoughts on the Durov Arrest

#190

Earlier quoted context omitted.

That user and the user you are replying to are not misinformed. They are perfectly correct. Telegram does not store messages in plaintext. Period. No matter how shrill the cries from Moxie Marlinespike and his adherents, E2EE is not the only form of encryption. MTProto 2.0 is fully documented and everything the user linked described is true.

Nothing in the comment linked upthread is at all relevant to the analysis of Telegram we are discussing.

You don't get to make a false claim and then handwave it away. You made the claim and you were given evidence otherwise.

This was not a case of a user confusing encryption in transit, as you claim.

Post reply on HN