Live data from Hacker News

Telegram reportedly surrendered user data to authorities

androidpolice.com

41–50 of 81 posts

Re: Telegram reportedly surrendered user data to authorities

#41

Earlier quoted context omitted.

Terrible advice. If you want e2e you can choose to enable it. It is not enabled because many users choose to receive their messages across multiple personal devices simultaneously. This is not possible with e2e, which is why it is an option.

> This is not possible with e2e Why not? You can encrypt a message with more than one key, no? It’s still e2e, just that there are multiple ends. Apple’s Messages is e2e (until SMS is used) and they have group chats.

Until SMS is used OR until either side has iCloud backups turned on (which is the default setting)

Re: Telegram reportedly surrendered user data to authorities

#43
post #27

People use Telegram because they have a great user experience. Signal, unfortunately, does not - and it's not entirely because they're limited by E2EE.

Having switched my family, friends and many colleagues to Signal, I am fairly confident to say that Signal's user experience is good enough.

Signals experience when you want to use it on more than just 1 phone per person is still TERRIBLE compared to Telegram.

If you use 2 computers, a phone, and a tablet and you want to use 1 Signal account on all 4, it's painful.

BONUS: Signal uses crypto funded by the US govt and used by Facebook, so I don't really trust it.

Re: Telegram reportedly surrendered user data to authorities

#44
post #33
post #19

Earlier quoted context omitted.

That very much varies with country. Most countries I’m familiar with the rules for require ID when buying pre-pay SIM cards these days.

A prepaid SIM having the same security checks as a bank account definitely felt sour. And for some reason people think they have any privacy from the government.

Is this the case now in the US? Is the "burner phone" a thing of the past?

Re: Telegram reportedly surrendered user data to authorities

#45

Earlier quoted context omitted.

Like other algorithms, it's a fairly simple mix of existing encryption paradigms. One paper tried to validate Telegram's protocol: https://www.researchgate.net/publication/346702021_Automated... That seems to have gone well. The mechanisms used seem very similar to the mechanism used in Signal's last audit from 2017. Another paper only verified part of the protocol in a specific way: https://www.computer.org/csdl/pro…

Signal's protocol is not proprietary. You are mistaken

The point of GP was that both Telegram and Signal have the same level of "proprietaryness". Either you call both proprietary, or neither.

They are both documented, both have source code of implementation available.

Re: Telegram reportedly surrendered user data to authorities

#46
post #10

Earlier quoted context omitted.

it has been audited, and they said it was a total mess and was full of vulnerabilities

Source? My cursory search hasn't found much wrong with the current protocol, though mtproto 1 relied on some rather weak cryptography which luckily got replaced years ago.

Audited and found to be a mess is a complete lie. 0 encrypted telegram messages have ever been cracked. Full stop.

They even took some ideas that people in the crypto had pointed out and updated their mtproto protocol to 2.0 https://core.tlgr.org/mtproto

Re: Telegram reportedly surrendered user data to authorities

#47
post #24

Earlier quoted context omitted.

Terrible advice. If you want e2e you can choose to enable it. It is not enabled because many users choose to receive their messages across multiple personal devices simultaneously. This is not possible with e2e, which is why it is an option.

> Terrible advice. If you want e2e you can choose to enable it. It is not enabled because many users choose to receive their messages across multiple personal devices simultaneously. This is not possible with e2e, which is why it is an option. Signal, WhatsApp, iMessage and Threema seem to do just fine.

Guess who conveniently holds your "secret key" in escrow just like AWS KMS does by default? The provider.

Re: Telegram reportedly surrendered user data to authorities

#48
post #41

Earlier quoted context omitted.

> This is not possible with e2e Why not? You can encrypt a message with more than one key, no? It’s still e2e, just that there are multiple ends. Apple’s Messages is e2e (until SMS is used) and they have group chats.

Until SMS is used OR until either side has iCloud backups turned on (which is the default setting)

Just shipping keys to someone to hold on doesn't make the encryption not-end-to-end, though it does reduce the point quite a bit.

Re: Telegram reportedly surrendered user data to authorities

#49
post #6

It's honestly not realistic to expect any free service provider to martyr themselves for your privacy. With that in mind, remember that anywhere you don't control the metal someone is watching you. Always.

Sure, but Telegram has repeatedly made misleading claims about the privacy of their app and novel cryptographic protocol compared with alternative free services. The problem isn’t that Telegram disclosed data to lawful requests, it’s that (1) their marketing re privacy is at best misleading and (2) they had that data available to disclose.

Re: Telegram reportedly surrendered user data to authorities

#50

It doesn't actually even matter if they did this. The only thing that matters is that they are physically capable of doing so. Telegram is not e2e encrypted by default, and therefore you shouldn't use it if you're concerned about privacy. Look no further than Signal's supboenas and how they respond to them. With all the information they hold about an account. Which is just the creation date and last connection date.…

It is particularly amusing that they provided the two date/time pairs in the form of "Unix millis" only. Obviously there's the legal risk of getting the conversion to Gregorian wrong, but I suspect that may have cause some head-scratching at the court.

Meh. In any case involving data/tech I suspect there are people involved who can handle much more sophisticated formats/conversions than this. I may disagree with the government’s stance on privacy, bit they’re not stupid or tech-illiterate.
Post reply on HN