Earlier quoted context omitted.
Not being able to "backdoor it" (presuming this means "exploit a backdoor the torturer presumes you have already put into it") does not prevent you from getting tortured to backdoor it. All it does is, should that occur, prevent you from giving the torturer what they want to end the torture. OTOH, convincing the torturer by, among other means, public statements in advance that you have failed to consider this anhd be…
Tarsnap is software you compile and install yourself. He literally can't backdoor existing installations of it.
Thoughts on the Durov Arrest
201–210 of 228 posts
Re: Thoughts on the Durov Arrest
#202This analysis leaves out the fact that Pavel Durov is, with Telegram, in approximately the same position Ladar Levison was with Lavabit. Unlike Meredith Whitaker, Durov actually is in a position to furnish documents to the French government, where he has citizenship. He's in that position because he has repeatedly made deliberate product decisions, to the bafflement of cryptographers around the world, to keep himself…
It’s worse than that, the ‘find people nearby’ feature is a public drug and prostitution advertising billboard with zero moderation and has been for years. They’re in a closer position to silkroad than lavabit
Also, in my country they usually just write the ordinary website name on the wall and add "VPN Tor" whatever that could mean. Maybe they try to hint that Tor and VPN are apps for drug trade? Do Tor and VPN have moderation and do they cooperate with law enforcement?
Re: Thoughts on the Durov Arrest
#203Earlier quoted context omitted.
From telegram privacy policy: >If Telegram receives a court order that confirms you're a terror suspect, we may disclose your IP address and phone number to the relevant authorities. So far, this has never happened. When it does, we will include it in a semiannual transparency report published at: https://t.me/transparency .
What about "child trafficking suspect", "arms dealer suspect" or "drug dealer suspect" ?
Re: Thoughts on the Durov Arrest
#204Earlier quoted context omitted.
Indeed. Two of the more common questions I get with Tarsnap are Q. How do I know that Tarsnap is secure? A. Read the source code. Q. Ok, but you're really smart, what's stopping you from putting in a backdoor and hiding it really well? A. I don't want to get tortured, and ensuring that I can't decrypt your data protects *me*.
>> A. I don't want to get tortured, and ensuring that I can't decrypt your data protects me . There is a line in RickAndMorty about this, which I won't repeat here. To paraphrase: the one thing worse than bring tortured for information you have is being tortured for information you don't have.
Re: Thoughts on the Durov Arrest
#205> In a subsequent statement, Paris prosecutor Laure Beccuau said Durov was arrested as part of a probe into an unnamed person launched by the office's cybercrime unit on July 8.
So the probe was launched in July, but the warrant was issued in March? I do not understand that. Was warrant issued on a different case? Is information about warrant incorrect?
[1] https://www.france24.com/en/france/20240826-telegram-ceo-pav...
[2] https://www.politico.eu/article/exclusive-telegram-ceo-broth...
Re: Thoughts on the Durov Arrest
#206This is quite a one-sided take. What makes Telegram unique is: 1) They have access to almost all the content 2) They try to use arguments about jurisdiction to avoid helping law enforcement with lawful requests All the other messaging platforms (WhatsApp, Signal, iMessage) have started to use end-to-end encryption to avoid being in this position in the first place. But they also comply with law enforcement and share…
I found it interesting to read that their approach is supposedly to split encryption keys across jurisdictions. It sounds like they believe that they should therefore not be able to be compelled to reveal any plaintext because the keys are not in the jurisdiction asking for data, but as far as I can tell this is obviously rubbish, because a computer is not subject to the law, an individual is, and in this case an ind…
Re: Thoughts on the Durov Arrest
#207The fundamental problem we have right know is that we know the charges, but not the factual allegations that underlie those charges. Put differently, if you wanted to put together a charge list for the head of a large social media company you didn't like, this is what it would look like. If you wanted to put together a charge list for someone actively running the group chat of a terrorist group... this is what it wou…
I just opened telegram, went to ‘find people nearby’ and was immediately presented with a long list of drug dealers and prostitutes advertising their services. I’m pretty sure that’s not legal
Re: Thoughts on the Durov Arrest
#208> What it means is that European states are going to try to extraterritorially dictate to foreign companies what content those companies can and cannot host on foreign-based webservers It looks like the author failed to grab that Durov asked for the French nationality and therefore is a French citizen who must comply to French law. > Telegram is not the only company in the world which has a social media platform used…
What if it wasn't even encrypted, and was just so many gigabytes of data that the government doesn't have the skill or manhours themselves to wade through it? Can they demand big data tools tailor made per company?
Why can't companies submit software and data to these requests so covered in "cookie consent style popups" that nobody could ever get through it in multiple lifetimes?
Re: Thoughts on the Durov Arrest
#209- at Apple's demand Telegram made adult-themed groups unaccessible by default
- at Apple's or Google's demand Telegram removed an animated emoji of an exploding eggplant
Though those requests resemble censorship rather than preventing crime.
Re: Thoughts on the Durov Arrest
#210Earlier quoted context omitted.
Yes. An employee can impersonate a user by registering a device in their name and intercepting the confirmation code and then read all non secret chats and private groups of that user. At least one employee must have the ability to intercept the code. (Unless the user has 2fa enabled, but that is not the default configuration.) There are probably easier ways if we knew more about how the administrate their infrastruc…
Maybe? When you login from a new device you're asked to provide an OTP so maybe there is at least that layer of protection and, hopefully, requires some circumvention at the application code level. However I think the real question is: even if that's possible, can law enforcement compel Durov or an employee to do so?