Live data from Hacker News

Thoughts on the Durov Arrest

prestonbyrne.com

211–220 of 228 posts

Re: Thoughts on the Durov Arrest

#211
post #93

Earlier quoted context omitted.

From telegram privacy policy: >If Telegram receives a court order that confirms you're a terror suspect, we may disclose your IP address and phone number to the relevant authorities. So far, this has never happened. When it does, we will include it in a semiannual transparency report published at: https://t.me/transparency .

What about "child trafficking suspect", "arms dealer suspect" or "drug dealer suspect" ?

The problem here is that authoritarian and Western governments might request the data about opposition activists under excuse of being "drug dealer suspect". For example, what if US requests data on Snowden or Assange?

Re: Thoughts on the Durov Arrest

#212
post #24

Earlier quoted context omitted.

His point is that he can't backdoor it: you can read the code before you install it. I'd go further, and say that this is true of anything end-to-end encrypted, open-source or not, because it's not 2002 anymore and reversing ordinary client software is table stakes. (I'd still rather run something open source, ceteris paribus).

Feeding the paranoia above is that cperciva would verifiably be the smartest person in the room. A canny torturer would respond to this bringing in djb as the primary instrument of torture. "First one to break or weaken scrypt or 8-round salsa20 gains their freedom". The loser is forced to give talks at AWS marketing conferences for the rest of their natural

> A canny torturer

A canny torturer would read the Smart People on a public forum red-teaming cperciva's mind.

Re: Thoughts on the Durov Arrest

#213

Earlier quoted context omitted.

You don't get to make a false claim and then handwave it away. You made the claim and you were given evidence otherwise. This was not a case of a user confusing encryption in transit, as you claim.

No false claim was made, and nothing in that thread was relevant to the analysis of this story or on this thread. I'm very comfortable leaving it there, and that the people who will take my word on none of this mattering are the only ones I need to care about. Do not use Telegram.

The person you replied to wrote,

> As another HN user pointed out Telegram does not store messages in plaintext: https://news.ycombinator.com/item?id=41348228

Telegram does not store messages in plaintext.

Your claim:

> That user seems to be misinformed, and appears to be discussing client-server encryption, not end-to-end encryption

Is categorically false. You do not get to redefine what encryption is. That is not your right.

You've been corrected repeatedly. If you continue to insist you have not made a false claim, you are then lying.

Re: Thoughts on the Durov Arrest

#214

Earlier quoted context omitted.

No false claim was made, and nothing in that thread was relevant to the analysis of this story or on this thread. I'm very comfortable leaving it there, and that the people who will take my word on none of this mattering are the only ones I need to care about. Do not use Telegram.

The person you replied to wrote, > As another HN user pointed out Telegram does not store messages in plaintext: https://news.ycombinator.com/item?id=41348228 Telegram does not store messages in plaintext . Your claim: > That user seems to be misinformed, and appears to be discussing client-server encryption, not end-to-end encryption Is categorically false. You do not get to redefine what encryption is. That is not…

No.

Re: Thoughts on the Durov Arrest

#215
post #200

Earlier quoted context omitted.

On the contrary, it’s a very strong claim. The guards could decide they’re not getting paid enough and steal the data. Or the government could arrest them. Or the government could MITM the data center. Or any hundreds of different scenarios. At the end of the day, the only thing preventing somebody from accessing the data is that they just… don’t. This is very weak security and it is why cryptographers and security p…

I am saying that in practice the security might be structured in such a way that it requires several different parties to connive, rendering it essentially fine. I mean, having to modify server code in order to access data that is "effectively plaintext" is not so different from installing a backdoor inside the client: it's not like the user has any choice of client, so even for apps like whatsapp and signal that run…

EDIT: regarding the part about signal and whatsapp I must clarify that of course the possibility of inserting a backdoor on the server side is far more dangerous than the client side: Signal has verified builds so a backdoor would be evident and the user could stop using the service. And the same actually holds true for any app using E2EE if the user simply avoids autoupdating and wait for some confirmation that it is ok to update, at least as long as we can assume that any client side backdoor would be found by independent researchers.

I also want to repeat the original point that started this whole conversation: the point was how easy it would be for Telegram to access the chats and if the justice system can compel them to do so.

When people say it has the data in plaintext, I take as a "they can access them whenever the want right now without changes", and yes of course the could ultimately access the data (in fact they don't claim to be unable to). What they claim (and I believe it feasible) is that even if a judge seized all the assets and servers under his/her jurisdiction it would be impossible to decrypt any user data.

Re: Thoughts on the Durov Arrest

#216
post #160

Earlier quoted context omitted.

The author is “an adjunct professor of law at Fordham Law School in New York City, where [he] teach[es] cryptocurrency law and practice” [1]. The law professor bit is shocking, given the article basically revolves around it making “zero sense for Durov to do any of these things,” as if criminality is always rational. But crypto has broadly come out in support of Durov [2]. [1] https://prestonbyrne.com/ [2] https://ww…

And it all makes sense if Durov is in fact working for the French secret services and his "arrestation" is just a way to protect him from novichok or a balcony fall, and a cover story for how France got hold of the keys to Telegram. I mean, he got French citizenship despite not fitting any legal requirements, and nobody in the French government has given any explanation on why he got it.

This!!!! ^^^^^^^

Re: Thoughts on the Durov Arrest

#217
post #93

Earlier quoted context omitted.

What about "child trafficking suspect", "arms dealer suspect" or "drug dealer suspect" ?

The problem here is that authoritarian and Western governments might request the data about opposition activists under excuse of being "drug dealer suspect". For example, what if US requests data on Snowden or Assange?

Some government officials also qualify environment activists as "ecoterrorist" which make them enter in the "terror" category.

Re: Thoughts on the Durov Arrest

#218
post #74

I wonder why Durov traveled to France, knowing that he would be arrested there. Could there be more to the story?

He did not know that he would be arrested there. The plane tried to leave Paris airspace at the last minute, but it was too late. Durov should have known that he could be arrested. Basically, arrogance and wishful thinking, complacency, believing in "democracy". Still, UAE will probably get him out.

> The plane tried to leave Paris airspace at the last minute, but it was too late.

Do you have sources?

Re: Thoughts on the Durov Arrest

#219
post #131

Earlier quoted context omitted.

It's not used by the Ukrainian military. It is used extensively by Russian military and intelligence

If Ukrainian drone teams and others are using it to publish their footage, in what sense is it not being used by the Ukrainian military?

In the sense that it's not used for military communications.

Re: Thoughts on the Durov Arrest

#220

Earlier quoted context omitted.

What baffles me is why people use a centralised messenger to organise a protest? and the one that is hosted in another country. And what do you imply 'funded by the government' means for Signal? It's a nonprofit org, app has e2e encryption and clients are open-source. How is it worse than an app owned by an LLC in UAE, with no e2e encryption by default, unknown funding sources and no information about what's going on…

> What baffles me is why people use a centralised messenger to organise a protest? Because it works and because real world is not theoretical. > And what do you imply 'funded by the government' means for Signal? I'm not implying anything. I just listed the reasons why Durov doesn't trust state funded american encryption systems. > unknown funding sources What do you mean unknown? They're pretty known. > no informatio…

> What do you mean unknown? They're pretty known.

I mean, you don't believe the fairy tale that he actually paid for everything himself?

Post reply on HN