Live data from Hacker News

After Delhi High Court ruling, Telegram discloses personal details of users

livelaw.in

91–100 of 230 posts

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#91
post #7
post #2

Don't use messengers that ask for your phone number and aren't end-to-end encrypted. Use services that store as little data as possible. If data is stored, it can be given away and I would assume that it will be given away. Telegram disguises itself as encrypted chat app, when it is actually just a regular centralized plaintext messenger that has an encryption feature that nobody uses.

TLDR don't use Telegram and Signal as some "alternatives" Use Matrix clients (Element, Fluffy chat) or Session, Briar (no (video)calls), Delta (no (video)calls), Jami, not recommending Threema because they can tie you through payment and it's centralized Here simple chart to see what to use and not use (use translate feature): https://www.messenger-matrix.de/messenger-matrix.html

Matrix is not secure, Fluffy chat even less so than Element (but client is irrelevant it's still insecure)

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#92
post #88

Earlier quoted context omitted.

I don't think you understand how Telegram encrypts its chats. MTProto is also used to encrypt Cloud Chats at rest. It's not just transport. Cloud Chats are not e2ee because the keys are held by Telegram. Moxie also "rolled his own crypto". "Rolling your own crypto" is typically used disparagingly by those who claim moral or intellectual superiority over the competition. The Signal Protocol was rolled by someone, yes?…

> the keys are held by Telegram This is where the privacy promise falls apart. From a user's perspective on-disk encryption makes no difference, because there is no real enhancement of privacy for them. If a third party holds the key, they hold the key. If you put something into the hotel safe, the hotel could still steal it from you. As far as I can tell, most TG users are not aware or do not care, but for those who…

I think you are being far too uncharitable and you've simply gotten the facts wrong a number of times, which I've needed to correct you on.

Use another messenger if you like but e2ee encryption is not some moral imperative that must be done. There are always trade-offs. I appreciate Telegram for the purposes I use it for. If I want e2ee, I turn on a Secret Chat.

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#93
post #56

Earlier quoted context omitted.

This is silly. You adopt practice based on your threat model. Threat models presuming the government can just torture information out of you also mean that any system will give you away - you're either completely anonymous or not, but if you use a messenger of any kind from your home internet IP address, then they'll come pick you up. Telecom companies have full records of who had what IP, for what duration and when…

Exactly. You need to manage to be indistinguishable from p50 users if you are serious about anonymity. This is much more difficult than using strong encryption and matrix instead of signal.

Very much this. Which creates all sorts of weird problems, like very act of using an unusual messaging or encryption scheme is likely to finger you.

Signal is partly an attempt to normalise a service with strong encryption to provide a crowd it's easier to hide in.

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#95
post #53
post #44

Earlier quoted context omitted.

Sure, but couldn't you just use a disposable number? (Assuming you live in a place where you can buy SIM cards without showing a personal ID, which is most countries.) That's a minor inconvenience compared to not being able to communicate with most people who use these mainstream networks. I'm more worried about the lack of encryption and trustworthiness aspect of them than giving away a phone number.

Most countries require SIM card registration nowadays. https://www.phonetravelwiz.com/phone-travel-options/sim-card... > Of the 245 countries/territories with territory-bound mobile operators, 185 countries have SIM card registration laws. 13 will collect biometrics (fingerprints, but some will take a face scan too). 51 countries have no registration requirements. Which by itself is questionable.

Hmm I didn't think it would be that many. I'm sure there might be workarounds, like ordering online or buying from vending machines at airports, etc., but yeah, it's certainly not as convenient as before.

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#96
post #77

Earlier quoted context omitted.

as i said, the MOBILE NUMBER IS A PII and the government needs just that bit to extract you from your home and subject you to anything they deem necessary in order to silence you. this is not a fairy tale i am larping about. "sealed sender" or whatever BS tech you throw at the wall doesnt make you secure. if your number can be found out, your goose is cooked.

Feel free to explain your threat model. We are quite many where the threat model does not depend on hiding our phone number from the government.

yeah.... let me present some material

https://gulfnews.com/world/asia/india/kashmir-lockdown-arres...

https://thenextweb.com/news/kashmirs-police-want-people-to-r... >Kashmir’s police want people to ‘register’ their WhatsApp groups

https://www.dailyexcelsior.com/police-crackdown-keypad-jehad... >Police crackdown on ‘keypad jehadis’

https://kashmirobserver.net/2022/01/11/jk-police-launches-cr... >J&K Police Launches Crackdown On People ‘Misusing’ Social Media

"misuing" means writing material that is critical to the ruling party.

https://www.greaterkashmir.com/chenab-valley/authorities-in-... here, the police simply take your name/number and pick you up from the street. open and shut case in an hour.

Why should whatsapp/facebook/twitter help them? 1. they have business interests in india and they NEED to please the government if they want to survive in india so there are no court orders or anything needed. the police have carte blanche to demand any information and for them, name/number is good enough because the data is available with them.

an example from my own home. A family member was active on twitter last year and would get into "twitter debates" and that nonsense. they would use their own name because of the websites ask for "firstname/last name" and normally people don't care about that. anyway, during one such online fight, a random opponent apparently told them "you wont listen to me so i will have police explain it to you" or something to that end. 3 days later the police comes home "enquiring" about them. we had a hard time "explaining" the situation and some money exchanged hands after which we were off the hook. "never again they said, later"...

afterwards, i did a checkup of their account and they had 2FA activated on their number which i strongly suspect was passed on to the police. again, no "evidence" but my own anecdata.

>Feel free to explain your threat model.

i am "living" this threat model so the techniques used in iran for example used by dissidents or anti-government protestors or in china by anti-ccp protestors for example, i am going through that myself and PII in any form is dangerous.

sure, lets say i don't use my real name in twitter or use 2fa and twitter gives my "ip address" or something. they would have to corelate that information with a separate demand with ISP.... not low hanging fruit as much. mobile numbers, well they have dumps and mobile numbers dont change hands a lot.

OTOH, if i use my selfhosted matrix for example, the provider, some random DMCA ignore ones would laugh at them. even if they asked for payment, i pay from crypto so what will they get? and its not like the webmaster of my own server(read me) would not give any details to any demand from even PM of india so short of blocking my server IP,what can they do?

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#97
post #93

Earlier quoted context omitted.

Exactly. You need to manage to be indistinguishable from p50 users if you are serious about anonymity. This is much more difficult than using strong encryption and matrix instead of signal.

Very much this. Which creates all sorts of weird problems, like very act of using an unusual messaging or encryption scheme is likely to finger you. Signal is partly an attempt to normalise a service with strong encryption to provide a crowd it's easier to hide in.

>Signal is partly an attempt to normalise a service with strong encryption to provide a crowd it's easier to hide in.

i am saying remove the mobile requirement and signal is perfect. not until then.

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#99
post #44

Earlier quoted context omitted.

yes. yes yes. yes. yes 100%. the same reason i avoid whatsapp and signal like the plague. "mobile number" is in itself a big identifier when you are living in a place where you have o do mandatory KYC so that the government knows which each mobile number is linked to the actual human being. i dont care signal doesnt hold any messages. the government can ask for my number and they can use the xkcd spanner method to do…

Sure, but couldn't you just use a disposable number? (Assuming you live in a place where you can buy SIM cards without showing a personal ID, which is most countries.) That's a minor inconvenience compared to not being able to communicate with most people who use these mainstream networks. I'm more worried about the lack of encryption and trustworthiness aspect of them than giving away a phone number.

you can't get disposable (anonymous) mobile numbers in india. >I'm more worried about the lack of encryption and trustworthiness aspect of them than giving away a phone number.

you can use your own encryption on top of a cleartext model if that is a problem

Re: After Delhi High Court ruling, Telegram discloses personal details of users

#100
post #45
post #2

Don't use messengers that ask for your phone number and aren't end-to-end encrypted. Use services that store as little data as possible. If data is stored, it can be given away and I would assume that it will be given away. Telegram disguises itself as encrypted chat app, when it is actually just a regular centralized plaintext messenger that has an encryption feature that nobody uses.

Which ones don't ask for a phone number?

Threema
Post reply on HN