Live data from Hacker News

Telegram reportedly surrendered user data to authorities

androidpolice.com

71–80 of 81 posts

Re: Telegram reportedly surrendered user data to authorities

#71

Earlier quoted context omitted.

> iMessage Unrelated to this, but for all intents and purposes, iMessage cannot be considered e2e encrypted if either party has iCloud backups enabled. Apple has access to your iCloud backups, and they contain the iMessage keys.

IIRC With the keys they can technically decrypt in line, backups are not required.

Yes they can choose to decrypt messages going forward (by injecting a third key controlled by the gov/Apple in a multi person message and silently copying messages) but they can't retroactively decrpyt them in that case.

Re: Telegram reportedly surrendered user data to authorities

#72
post #33

Earlier quoted context omitted.

A prepaid SIM having the same security checks as a bank account definitely felt sour. And for some reason people think they have any privacy from the government.

Is this the case now in the US? Is the "burner phone" a thing of the past?

No. I believe they may be required to ask for a name on activation, but definitely not to verify it.

Individual retailers and service providers may have different policies, of course.

Re: Telegram reportedly surrendered user data to authorities

#73
post #22

Earlier quoted context omitted.

> Look no further than Signal's supboenas and how they respond to them. With all the information they hold about an account. Which is just the creation date and last connection date. https://signal.org/bigbrother/eastern-virginia-grand-jury/ Signal's subpoenas have always left a sour taste in my mouth. I just can't believe that they are getting so few, at least some cases they'll just send the standard letter out and…

> Signal has a push token for the vast majority of accounts otherwise they wouldn't be able to send out push notifications on iOS It's technically possible for them to not know which phone numbers correspond to which devices and tokens.

If they have the ability to send notifications, it's irrelevant how exactly that works: they can let a third party do that through them.

Re: Telegram reportedly surrendered user data to authorities

#74

Earlier quoted context omitted.

Like other algorithms, it's a fairly simple mix of existing encryption paradigms. One paper tried to validate Telegram's protocol: https://www.researchgate.net/publication/346702021_Automated... That seems to have gone well. The mechanisms used seem very similar to the mechanism used in Signal's last audit from 2017. Another paper only verified part of the protocol in a specific way: https://www.computer.org/csdl/pro…

Signal's protocol is not proprietary. You are mistaken

Exactly. And neither is Telegram's.

Re: Telegram reportedly surrendered user data to authorities

#75
post #69
post #50

Earlier quoted context omitted.

Meh. In any case involving data/tech I suspect there are people involved who can handle much more sophisticated formats/conversions than this. I may disagree with the government’s stance on privacy, bit they’re not stupid or tech-illiterate.

I regularly help my lawyer friend parse the DVDs she gets from police with the evidence from her case and it's a nightmare collection of proprietary ancient standards for old versions of Windows. They also still use fax machines for everything. The only place you'd find technical talent is in the federal police or a few guys higher up in the major urban police forensics labs.

Sure, but my point is that any agency or group that is going to subpoena Signal definitely has someone on their team who understands what a UNIX timestamp is. Think about it: If a service actually does comply with one of these subpoenas, they probably had over a trove of JSON files that need to be parsed or searched.

Re: Telegram reportedly surrendered user data to authorities

#76
post #33

Earlier quoted context omitted.

A prepaid SIM having the same security checks as a bank account definitely felt sour. And for some reason people think they have any privacy from the government.

Is this the case now in the US? Is the "burner phone" a thing of the past?

My experience was in Germany. They checked my passport, face, name, address via PostIdent video.

Same procedure as with N26 and ING online banks, though the latter didn't work due to connection problems so I had to do it at the post office.

I like prepaid because I avoid contracts whenever I can. And I liked that I can get one fast.

I understand the reasoning - they can tie an identity to any SIM card and find you pretty fast if your number/IMEI pops up in some suspicious communications, but still, privacy blah blah.

This is the country that recently was against the EU wide chat surveillance directive that surfaces every few years now.

Re: Telegram reportedly surrendered user data to authorities

#77
post #33

Earlier quoted context omitted.

A prepaid SIM having the same security checks as a bank account definitely felt sour. And for some reason people think they have any privacy from the government.

Is this the case now in the US? Is the "burner phone" a thing of the past?

It really depends. Most prepaid phones require some sort of identify verification in the US. There may be a few that you can buy with cash, but i don't have the cash to find out which ones. I think it is also important to note that they are probably doing some sort of GPS and tower tracking, so even if you buy prepaid... activating it and what not probably discloses enough location information to help identify you.

Re: Telegram reportedly surrendered user data to authorities

#78
post #62

Earlier quoted context omitted.

For me, despite its flaws in E2E, Telegram is the sweet spot for small to medium sized groups. Easy to install, works on every platform I need it, super-simple bot support and the UX is very nice. You even have tools to make write-only groups (microblogs of sorts) and actual moderation tools for larger groups. For a "community", I'd pick Discord though. Matrix as a technology is a good competitor, but the UI/UX for e…

Sounds like you were running with an account on the default matrix.org server? It's gotten faster, but there were a bunch of months when it was dog slow. The point is kinda to run your own server.

I don't have the time to run my own infrastructure. That's why I pay someone else to host my mail, compute and everything else.

Re: Telegram reportedly surrendered user data to authorities

#79
post #62

Earlier quoted context omitted.

Sounds like you were running with an account on the default matrix.org server? It's gotten faster, but there were a bunch of months when it was dog slow. The point is kinda to run your own server.

I don't have the time to run my own infrastructure. That's why I pay someone else to host my mail, compute and everything else.

You can pay someone to host a Matrix server too.

Re: Telegram reportedly surrendered user data to authorities

#80
post #46

Earlier quoted context omitted.

Source? My cursory search hasn't found much wrong with the current protocol, though mtproto 1 relied on some rather weak cryptography which luckily got replaced years ago.

Audited and found to be a mess is a complete lie. 0 encrypted telegram messages have ever been cracked. Full stop. They even took some ideas that people in the crypto had pointed out and updated their mtproto protocol to 2.0 https://core.tlgr.org/mtproto

mess ≠ cracked
Post reply on HN