11 ms·
FBI document shows what data can be obtained from encrypted messaging apps
- yosito 5y agoI'm skeptical of the accuracy of this document. Telegram is by default unencrypted and virtually public. Yet this document says the FBI can't get any message content?
- xwolfi 5y agoIt's by default encrypted, actually.
- cute_boi 5y agoi don't think its e2e by default. I hope you are not talking about https.
- heavymark 5y agoServer-client encryption by default, not end-to-end encrypted by default. https://telegram.org/faq#q-so-how-do-you-encrypt-data https://telegram.org/faq#q-so-how-do-you-encrypt-data
- maqp 5y agoYeah, with client-server encryption. Which doesn't matter at all. Encryption where the service provider has the key, which is the case for * all Telegram chats by default * all Telegram group chats * all Telegram Win/Linux desktop chats is indistinguishable from end-to-end encryption where the service provider has a backdoor (ANOM[1]) In both cases the service provider, and anyone who hacks them, can read your messages. [1] https://www.pcmag.com/news/fbi-sold-criminals-fake-encrypted-phones-that-actually-copied-their-messages https://www.pcmag.com/news/fbi-sold-criminals-fake-encrypted...
- heavymark 5y agoI assume they are referring to telegram "secret chats"? Also their own website notes all chats are "encrypted" by default. It's simply that by default they are not "end-to-end" encrypted unless you use secret chats for instance.
- 3np 5y agoTelegram is not based in any jurisdiction collaborating with the FBI. I'm assuming the KGB has free access
- luckylion 5y agoTelegram moved out of Russia precisely so they wouldn't be under their influence, so that's wild speculation. If the argument is that the KGB (or is it FSB now?) might go and just put a gun to their head: they could do that to literally anyone anywhere, so it doesn't matter. Telegram was in Berlin for a while but moved out of Germany for privacy/legal reasons as well (good call, considering that Germany is discussing trying to outlaw them) and moved to Dubai iirc.
- lowwave 5y agoTelegram is influenced by FB of Russian VK (something like that). And VK has KGB tights. This is from Ukraine activists point of view just FYI. So your choices is Signal or Wire. Signal sever is in US, and Wire may or may not be in US. So there you go.
- emptysongglass 5y agoThe grandparent comment was already hearsay but yours really scrapes the bottom of the barrel. Durov was forced out of VK on threat of violence: there are no ties to VK.
- boeingUH60 5y agoNo, there are ties, even though Durov was forced out. Durov sold his VK stake to a Russian oligarch with extensive government ties, such that they now control the majority of the company. https://www.reuters.com/article/russia-vkontakte-idUSL5N0KY3DQ20140124 https://www.reuters.com/article/russia-vkontakte-idUSL5N0KY3...
- emptysongglass 5y ago
- jeroenhd 5y agoTelegram does have end-to-end encrypted one-on-one chats, I suppose this document refers to that. Telegram group chats are very much available to law enforcement if they can convince Telegram to hand over the data. It could also be that Telegram (and any other foreign chat company) is more reluctant to (and more difficult to force to) share data with the FBI.
- maqp 5y ago>if they can convince Telegram to hand over the data. Or if they hack Telegram's servers. Or ask some other agency like the NSA (that hacks systems all the time) to do that for them. As for the legal aspects, I'm fairly sure Telegram can be made to comply, no individual user's is worth losing (tens/hundreds of) millions of customers in that particular country. It's not like Telegram can't do that technically*, the server-side database encryption key is by definition in the RAM of the server system. * That hasn't prevented them from actively misleading customers with their split-key-and store-parts-under-multiple-jurisdictions -scheme.
- yosito 5y ago> Or if they hack Telegram's servers Or they join the group chat
- maqp 5y agoSure, that works for public groups but generally the private group chats with sensitive private information about peoples' personal/business life are not public.
- adamcstephens 5y agoI’m curious how you think the US law enforcement agencies would compel Telegram to comply.
- BenoitP 5y agoWhy are group chats more exposed?
- berns 5y agoIt's encrypted but not e2e encrypted. Why would you say that it is virtually public? Do you think you or the FBI can easily access Telegram messages?
- randomhodler84 5y agoBecause telegram can access the messages. If the vendor can access the message data (eg: not end to end encrypted), anyone can. That is the bar. E2E||GTFO.
- yosito 5y agoJust join a group chat. Every message that was ever sent in that chat will be immediately visible. So yeah, it's virtually public. Even your private messages only require you to enter an SMS code to view, so anyone that can intercept an SMS sent to you, can read your messages.
- maqp 5y ago>So yeah, it's virtually public. Let's stop saying that as it implies users are somehow aware the service provider has access to the content, and that they make an informed decisions wrt their privacy. >Even your private messages only require you to enter an SMS code to view, so anyone that can intercept an SMS sent to you, can read your messages. The 2FA password is something everyone should enable. It's still an incremental security improvement if you have to use Telegram and your threatmodel is a banana dictatorship doing SMS interception but not server-side hacking. The right thing to do is get yourself and your loved ones the hell out of Telegram as soon as possible; Signal is your best bet here. Cwtch/Briar if you need to also protect metadata.
- emptysongglass 5y ago> The right thing to do is get yourself and your loved ones the hell out of Telegram as soon as possible; Signal is your best bet here. Cwtch/Briar if you need to also protect metadata. No, this is not the right move. It's engaging with the ecosystem of messaging products balancing ease of use, ethics of the business and people behind it, and your own threat profile. Most will never be under threat of a state actor that necessitates getting their friends and family "the hell out of Telegram as soon as possible". I also use Matrix but personally speaking I find Moxie Marlinspike a deeply unethical person who will gleefully slander the competition including up to suing them in his quest for supremacy. So I don't touch Signal because on my tripod of interests to balance, I don't want to go anywhere near his ethics. Use Signal or Session or Element or Telegram but stop telling people not to use a thing because you believe E2EE is the next Jesus Christ. Only sith deal in absolutes.
- godelski 5y agoThe document is about what can be easily requested from companies, not what can be hacked. Because telegram hosts no servers in the US they can't trivially request it. They can get it other ways and of course by hacking. But the document isn't about what they can successfully hack or request through back channels. This is why people say that you have to trust Telegram, as opposed to fully E2EE systems (like Signal) which require (almost) zero trust.
- skinkestek 5y agoIt is because you and others got your facts wrong. Telegram is not unencrypted. This is a lie spread by certain WhatsApp and Signal fanboys (not all, count me in with the Signal fans - I just happen to be a reasonable one that to some degree know what I'm talking about) with the excuse that "of course we mean end-to-end-encrypted when we say encrypted". What we see now is the resulting confusion: why don't law enforcement have access to it if it virtually unencrypted? Well, the answer is despite all claims of how lousy the encryption is for some weird reason[1] it doesn't seem to leak data. Now that we have seen the confusion that stems from saying "encrypted means end-to-end-encrypted when we say it does", can we stop repeating that nonsense? Also, can we think twice before mindlessly repeating such stuff in the future even if it was originally said by some extremely smart people that are well respected for good reasons? Because those very smart people were the same who recommended WhatsApp for a long time until it became painfully clear to everyone that: - WhatsApp leaks metadata to Facebook which cooperates happily with basically any government as far as I understand - WhatsApp has uploaded unencrypted backups to Google Cloud (yes, probably over https, but Google got all you messages and it was known that they would datamine it.) - and more¨ PS: Some time around half a year before Telegram launched WhatsApp actually sent data unencrypted, i.e. as plaintext. And they sent it over port 443..! PPS: Stay safe folks, opsec is probably more important than the exact messenger you use. My bets today are Signal in the short run and Matrix as soon as possible, but personally I send photos to my parents using Telegram and receive a lot more info back from various groups. [1]: Meaning either this is a bigger honeypot than An0m and everyone Three Letter Agency including both FSB and NSA are in on it or Telegram actually got something right. Or they have just been extremely lucky for 9 years in a row or something.
- egberts1 5y agoTelegram, as a capability, does not do “end-to-end encryption” for one-on-one chat. And Telegram most certainly cannot encrypt group chat.
- skinkestek 5y agoI does have, it is well known and it has existed for years. The remaining criticism now is that the default for one-on-one chats is still the more convenient normal point-to-point-encrypted chat type instead of E2E-encrypted (which, in Telegrams implementation is less convenient since it doesn't sync between clients, which again is reasonably for those messages where one really cares about secrecy in the context of day-to-day messaging apps). As usual: I only observe this from the outside. For what I know maybe Putin reads my messages before he goes to bed every night to fall asleep because I mostly use ordinary point-to-point encrypted messages which can be intercepted if Telegram is a secret FSB front or if Telegram isn't careful. Note however that for all we know maybe Biden reads my mail too to fall asleep since that too isn't end-to-end encrypted. I only comment on observable facts or statements that haven't been debunked. The last means I haven't verified the crypto of any app, I take it for granted that if it is broken someone will figure out just like when WhatsApp sent plaintext messages over port 443, and even faster with Telegram since there are so many who wants to find flaws in it.
- sandworm101 5y agoThis document is classified U//FOUO (unclassified//for official use only). The actual abilities of the FBI/NSA and like agencies are surely classified to some higher level.
- vmception 5y agoThe real question is if you actually believe what this document writes about Wickr. Wickr is set up like an expected honeypot would be set up. So for people that don't or aren't willing to understand that, I'm wondering if this document validates them, or if the skepticism of this document's classification level validates the idea Wickr should be avoided for sensitive communications.
- champagnois 5y agoConsidering endpoints are compromised like swiss cheese in 2021 and third party apps are all compromised, people should be of the belief that they cannot trust anything they didn't write and build themself.
- lazide 5y agoOr even if they did build the software, anything running on hardware they don’t have a similar level of knowledge about. Which good luck with that. Which leaves anyone planning on doing something the US gov’t (or China, or Russia if within their reach) wouldn’t like left with some unpalatable and inefficient options. Either they blend in enough to not get any attention, or don’t seem “dangerous” enough in the sense they are likely to get anywhere, or don’t use any technology more complicated than a piece of paper and a #2 pencil. The last one was what osama bin laden was doing, and they still found him - it just took awhile. As long as the folks being targeted are legitimately out to do harm against innocents, these capabilities are ‘ok’ (scare quotes intentional here). They’re going to be turned against political opponents or people that just seem ‘bad’ though at some point, and almost certainly already have been for years.
- 5y ago
- acosmism 5y agois facebook messenger omitted because they dont have access to it?
- smolder 5y agoNo, it's because they can request everything from FB and instagram, including message content.
- m1117 5y agoI think including FB messenger is unnecessary, they have a copy of passwords.txt
- bonestamp2 5y agoProbably the opposite... the same reason SMS is not included -- because they have full access to it.
- rnotaro 5y agoRelated thread about the same document from a month ago (November 30th) with 450+ comments : https://news.ycombinator.com/item?id=29396643 https://news.ycombinator.com/item?id=29396643
- neom 5y ago18 U.S. Code § 2703 - Required disclosure of customer communications or records - Contents of Wire or Electronic Communications in Electronic Storage. "can render 25 days of iMessage lookups and from a target number." I thought iMessage was E2EE and with all the iJunk turned off this isn't possible?
- ComodoHacker 5y agoI believe this refers to people lookups, not messages content.
- VWWHFSfQ 5y agoIt's the metadata. Not the message contents.
- DeathMetal3000 5y agoI understand it is e2ee but not the iCloud backup which means for most people it might as well not be encrypted.
- exabrial 5y agoSince you do not [most likely] have root access to your phone, you cannot directly examine what Apple/Google has installed on _your specific_ phone. Any of these applications could have its memory examined transparently if the operating system is evil.
- vmception 5y agoYes, that actually highlights the absurdity of the government's stances to encryption. They can still do an actual investigation on the person and try to dump from the physical devices they find (whether it requires a court order first, or not). Of course, this is expensive, and often it is not possible to know who to go to, or whether they can access that person, or they don't have enough information yet to determine if a crime has been committed. But that's the point. In the US, for example, the constitution was constructed specifically to be an alternative to how England and its colonies were governed. Governments have had a small window of time where electronic communications had a combination of: existing, not being private, and being understood by law enforcement. That window is closing and is just a reversion to the mean. Of course they are going to say "everyone using this convenient poorly implemented system without privacy helps us greatly in investigations", but thats not the point. They have to do an actual investigation now and target the devices itself physically, and even after all that only sometimes that will yield anything, depends on the OS version and app used, and app version.
- gwbas1c 5y agoYes, and don't forget: Anyone who wants to steal your password can covertly look over your shoulder. They can also physically break into your house by smashing a window, or running a bulldozer through your wall. Security always requires a certain amount of trust. If you can't get that trust, meet in person and keep your electronic communication vague.
- stunt 5y agoI worked long enough in telecom industry to know that there is no way for regulators to leave major communication platforms without some sort of surveillance. They can't sleep without it, and they don't take "Oh! sorry it's encrypted" as an answer. I don't buy this. Maybe it's true about FBI, but other agencies have the keys for right or wrong reasons.
- LinuxBender 5y agoI was also in that industry and agree. We could rewrite the firmware on phones over-the-air live and this was long ago. The only reason we didn't do this for customers was the one-off chance we brick a phone and cause higher customer support load. We could read and write to anything on the phone remotely. Such capabilities would surely not be abandoned.
- giuliomagnifico 5y agoThis has been already posted at least five times
- fotta 5y agoPreviously discussed: https://news.ycombinator.com/item?id=29396643 https://news.ycombinator.com/item?id=29396643
- iRobbery 5y ago"The service was acquired by video conferencing software maker Zoom in May 2020." thats when i revoked all my keybase information.
- dathinab 5y agoMessages are decrypted when you read them. It's reasonable to believe that at any point in time Root exploits exist for both iOS and Android. It's viable that the FBI or someone they cooperate with has such exploits from time to time (which doesn't mean they are reliable, or cheap to use). If you root-hack a phone you can easily get all messages the user sees after you hacked it. Even without root hacking you might get some, in some circumstances. EDIT: I should have read the article first, it's more about what content they get without hacking.
- CameronNemo 5y agoYou make some good points, but I need to point out that hacking a phone to obtain message contents is different from serving a warrant to a third party. Legally and practically. https://en.wikipedia.org/wiki/Expectation_of_privacy https://en.wikipedia.org/wiki/Expectation_of_privacy https://en.wikipedia.org/wiki/Third-party_doctrine https://en.wikipedia.org/wiki/Third-party_doctrine https://en.wikipedia.org/wiki/Dragnet_(policing) https://en.wikipedia.org/wiki/Dragnet_(policing)
- squarefoot 5y ago> If you root-hack a phone you can easily get all messages the user sees after you hacked it. This is not even necessary if you're in bed with hardware manufacturers, which could be the case with governments. All is needed is a system level daemon running in background, disguised as service or device driver pushed as mandatory upgrade, having access to the underlying iron. The user employs super strong cryptography? Who cares if we can read what is sent to the screen and tunnel it over the network to us. Passwords? Who cares if we can sniff the touch screen data to get the tapped points coordinates containing the position of keys on the virtual keyboard. Point is that there is zero protection against surveillance if the adversary has control over the hardware. Which is the reason why flashing an FOSS operating system on a closed hardware/firmware platform, although being indeed a good thing, isn't enough to claim victory.
- tomasreimers 5y agoFrom the top: "FBIs ability to legally access..." Implying there are illegal ways to access?
- VWWHFSfQ 5y agoWell anyone has the ability to illegally obtain access. If you hire a hacker or do it yourself. This document is about the legal ways.
- vincnetas 5y agoWhat are the obstacles with current technology to use OTP encryption technology. As far as i know its unbreakable. Of course you are limited to people you know in person, but that should be not an issue for people for who private communication is of most importance.
- airza 5y agoYou need some way of safely exchanging a codebook the length of every message, and you can never reuse an otp page. These together seem to make it… basically infeasible?
- cumshitpiss 5y agoA key in a OTP scheme can only be used once, and the key size has to be the same as the message size. This isn't practical for messaging app
- vincnetas 5y agosd card stores 128GB thats enough SMS messages for multiple lifetimes.
- morpheuskafka 5y agoI don't think this document has anything contrary to existing knowledge, but it does emphasize another significant reason that WhatsApp is not a great choice for privacy despite the use of E2EE. They readily hand over substantially more metadata, and while this is less likely to be enough evidence to convict someone of anything it is more than enough to seriously compromise privacy. > Search warrant: Provides address book contacts and WhatsApp users who have the target in their address book contacts. > Pen register: Sent every 15 minutes, provides source and destination for each message.
- pangolinplayer 5y agoreaaallyyy!?!?! its simple. assume no privacy. someone is always watching.
- Threeve303 5y agoImagine how much of a threat to the current security and encryption model it would be if a remote desktop server was running quietly in the secure enclave. You likely would never be able to know it is running. What good is end to end messaging if you can be watched using the app?
- DeathMetal3000 5y agoSignal FTW!