Earlier quoted context omitted.
IMHO second answer does not hold water. If you will end up in situation where you are tortured they will torture you until you will you say how to add the backdoor.
His point is that he can't backdoor it: you can read the code before you install it. I'd go further, and say that this is true of anything end-to-end encrypted, open-source or not, because it's not 2002 anymore and reversing ordinary client software is table stakes. (I'd still rather run something open source, ceteris paribus).
Thoughts on the Durov Arrest
181–190 of 228 posts
Re: Thoughts on the Durov Arrest
#182Re: Thoughts on the Durov Arrest
#183Earlier quoted context omitted.
There is quite a large amount of people believing that Telegram stores messages in plaintext. I would like to know how they got that idea. So far the best I've got is something along the line of: if you can get your chats when you log in with a new device, then so can a Telegram employee. With no proof of the claim of course.
Somehow they must transfer the chat history from their servers to the user. Either it's plain text, or encrypted and they either use the keys to decrypt or send the keys to the user along with the encrypted content. In all cases they can simply access the contents themselves.
For example, since we are in the realm of speculations, I propose the following alternative to the plaintext or accessible decryption keys: the decryption could happen inside a nitro enclave making it essentially impossible to access the data without changing the application code.
I'm not saying that this is what happens, just that I don't think that one can so easily deduce that "they can access the data" just from the fact that "they send you chat history to you".
Re: Thoughts on the Durov Arrest
#184The point is to emotionally manipulate the audience into complicity. To cause people not to question the underlying privacy and legal issues.
Instead they want the reader to have thoughts of large numbers of people, in organized networks presumably, that want to cause terror to them or harm to their children.
This causes a reaction in many people to forget about basic rights and focus on the fear they have been given instead.
I'm sure France and the U.S. have a million reasons to want this data from the Ukraine war, to probably some cases of the things they claim. However, it is definitely exaggerated and no one should be willing to trade the ability to communicate privately out of some fear that people who want to harm you are also able to communicate privately.
None of it really makes any logical sense because at the end of the day, to end all encryption means the Government would have to basically criminalize math.
So of course they rely on the reliable methods of emotional manipulation. I mean, they should have a blank check to go after this guy and anyone else, right? You don't support terrorism do you???
Re: Thoughts on the Durov Arrest
#185Re: Thoughts on the Durov Arrest
#186Earlier quoted context omitted.
There is quite a large amount of people believing that Telegram stores messages in plaintext. I would like to know how they got that idea. So far the best I've got is something along the line of: if you can get your chats when you log in with a new device, then so can a Telegram employee. With no proof of the claim of course.
If the chat is not end-to-end encrypted, which Telegram “cloud” chats are not, then by definition Telegram (the company) has access to the chats. Full stop.
For example the company servers could be hosted on an island with armed guards instructed to burn everything if anyone approaches and the decryption happens only on those servers: sure they have access by definition, but they really don't.
Re: Thoughts on the Durov Arrest
#187Earlier quoted context omitted.
EDIT: I just want to clarify that I don't believe the claim that an employee can intercept the validation code
There existed one server which sent the code, so whomever administrated that server could trivially have intercepted it by just modifying the software running there to copy/log it to them.
Re: Thoughts on the Durov Arrest
#188The fundamental problem we have right know is that we know the charges, but not the factual allegations that underlie those charges. Put differently, if you wanted to put together a charge list for the head of a large social media company you didn't like, this is what it would look like. If you wanted to put together a charge list for someone actively running the group chat of a terrorist group... this is what it wou…
I just opened telegram, went to ‘find people nearby’ and was immediately presented with a long list of drug dealers and prostitutes advertising their services. I’m pretty sure that’s not legal
I think it's CP that gets Telegram in hot water. Prostitution or drugs bothers noone but pedophiles trading stuff wakes everyone up.
Re: Thoughts on the Durov Arrest
#189Earlier quoted context omitted.
guess my e-mail provider is going to jail.
Does your email provider cooperate with law enforcement when they show up with a warrant and want details about an email/account involved in criminal activity?
Re: Thoughts on the Durov Arrest
#190Earlier quoted context omitted.
That user and the user you are replying to are not misinformed. They are perfectly correct. Telegram does not store messages in plaintext. Period. No matter how shrill the cries from Moxie Marlinespike and his adherents, E2EE is not the only form of encryption. MTProto 2.0 is fully documented and everything the user linked described is true.
Nothing in the comment linked upthread is at all relevant to the analysis of Telegram we are discussing.
This was not a case of a user confusing encryption in transit, as you claim.