27 ms·
After Delhi High Court ruling, Telegram discloses personal details of users
- ls15 4y agoDon't use messengers that ask for your phone number and aren't end-to-end encrypted. Use services that store as little data as possible. If data is stored, it can be given away and I would assume that it will be given away. Telegram disguises itself as encrypted chat app, when it is actually just a regular centralized plaintext messenger that has an encryption feature that nobody uses.
- rvz 4y ago> Don't use messengers that ask for your phone number and aren't end-to-end encrypted. Don't use messengers that ask for your phone number. Period.
- bentley 4y agoI sympathize with the sentiment, but the vast majority of my contacts already use other messaging systems that are identified by phone number such as SMS and WhatsApp—they don’t even use email, at least not for “text messaging”‐like things. In practice I’ve found that Signal has been the most successful privacy‐respecting messenger that my friends communicate with, which I attribute in large part to its policy of populating contacts lists by phone number, as well as its fad‐chasing features like stickers and GIF search.
- ls15 4y ago"Network effects" is an euphemism for "peer pressure".
- nonrandomstring 4y agoWell said. Pondering why your refactoring of "Network Effects" has a lot of truth; The supposed property that the attractive influence of a network is proportional to its size, rather like gravitational agglomeration, turns out to be largely false in practice. My observation is that people don't join a network because "all their friends" are on it. That's a myth. But they do find it hard to leave because one or two highly weighted friends (family, parents living abroad etc) are on it. You could probably say "network effects is just marketing" too. I think the idea of "organic growth" is also largely a myth. Massive amounts of marketing hype and billion dollar influence operations herd the masses, and also default settings and bundling. It's hard to avoid Google, Facebook or Twitter when your phone and browser come pre-configured with them.
- twelve40 4y agoso you like to run around and force all your contacts onto a new better messenger du jour? Messaging is by definition a social activity, so unless you sever most connections and just message yourself, you do end up using whatsapp, telegram, shit some of my family still uses skype! so all this well-meaning advice "just use..." is ridiculous in practice.
- ls15 4y agoThis fragmentation of the communication space is the problem that the new EU regulation for messenger interoperability tries to attack. I agree with this idea and also with the idea to make it mandatory only for platforms above a certain size. To me it makes sense. We had centuries where people could send a letter from one country to another country, both with their own postal services. Why can't we send a message from iMessage to Whatsapp without installing another company's spyware? However, I do not agree at all with the EU's plans for Chat Control.
- Markoff 4y agoAfter they announced removal of SMS I installed Johann's fork after few years (been using it for few years before but gave up with extended family after PIN nag screen fiasco which was last drop) to use it as SMS app only to find out that Signal is still missing such basic features as select multiple threads at same time and Archive or Delete them, you have to do it one by one, reminds of days when users for years requested basic feature to send more than one photo at time. Signal is total UX failure. I use it now just for SMS and didn't promote it to people to contact me, anyway there is basically only one person which I don't have on other messenger anyway.
- renewiltord 4y agoIn English that translates to "Don't use messengers that ask for your phone number and don't use messengers that aren't E2EE" => "Use messengers without phone numbers and with E2EE". So no, I think your weaker condition is not as good. E2EE is a good thing.
- emptysongglass 4y ago> Telegram disguises itself as encrypted chat app Where does it do this?
- ls15 4y agohttps://telegram.org/ https://telegram.org/ > Private > Telegram messages are heavily encrypted and can self-destruct.
- emptysongglass 4y agoBut they are encrypted. I think you're looking for e2ee, which it advertises only for Secret Chats.
- ls15 4y agoTransport encryption does not make it private. Optional e2ee is as good as no e2ee. And they rolled their own crypto... For some reason my non-technical friends still would be very surprised to learn that Whatsapp is more private than Telegram.
- emptysongglass 4y agoI don't think you understand how Telegram encrypts its chats. MTProto is also used to encrypt Cloud Chats at rest. It's not just transport. Cloud Chats are not e2ee because the keys are held by Telegram. Moxie also "rolled his own crypto". "Rolling your own crypto" is typically used disparagingly by those who claim moral or intellectual superiority over the competition. The Signal Protocol was rolled by someone, yes? The version of MTProto that had vulnerabilities discovered was deprecated many years ago.
- ls15 4y ago> the keys are held by Telegram This is where the privacy promise falls apart. From a user's perspective on-disk encryption makes no difference, because there is no real enhancement of privacy for them. If a third party holds the key, they hold the key. If you put something into the hotel safe, the hotel could still steal it from you. As far as I can tell, most TG users are not aware or do not care, but for those who are not aware, but actually do care, this should be made much more clear. > Moxie also "rolled his own crypto" Besides Moxie being a bit dubious himself, the more interesting question is: was there something that was already verified by many people that could have been used instead?
- Markoff 4y agoTLDR don't use Telegram and Signal as some "alternatives" Use Matrix clients (Element, Fluffy chat) or Session, Briar (no (video)calls), Delta (no (video)calls), Jami, not recommending Threema because they can tie you through payment and it's centralized Here simple chart to see what to use and not use (use translate feature): https://www.messenger-matrix.de/messenger-matrix.html https://www.messenger-matrix.de/messenger-matrix.html
- Normille 4y ago>Use Matrix clients (Element, Fluffy chat) or Session, Briar... With those other clients you mention, one of the reasons your communications will remain secure is that --because so few people use them-- you'll struggle to find anyone to message, in the first place.
- Markoff 4y agoSure, but in that case you can just go with Whatsapp and Facebook Messenger with WA being at least E2E by default, no point even trying some "alternatives" as Signal or Telegram under pretense of security. With Telegram I can see at least appeal in using it as news source, chat room or for bots, but what offers Signal besides hype about The Current Thing? Signal uses centralized server with closed source (they hidden code for one year until they finally gave up when users nagged them, nobody knows what they did during that year), Signal requires your phone number, Signal doesn't allow third party apps officially and tried to push some shady crypto, I mean how many red flags you need to avoid such POS app?
- Normille 4y ago>With Telegram I can see at least appeal in using it as news source, chat room or for bots, but what offers Signal besides hype about The Current Thing?... I use Telegram as a less 'facebooky' alternative to WhatsApp. Most of my friends and all my family are on it and, as a convenient messenger, it has a lot going for it; fast, 100% reliable sync across all my devices, generous file transfers, ability to quickly ping someone your location, ability to set up and subscribe to channels, etc. etc. It also has some infuriatingly shite 'features' such as the fact that one party in a conversation can delete messages from the other party's device and [as is oft-mentioned] the fact that comms are not E2E encrypted by default. But, on the whole, I reckon it's the best all-round messenger app out there. Just so long as you're not under any illusion that your comms are in any way secure.
- 2Gkashmiri 4y agoyes. yes yes. yes. yes 100%. the same reason i avoid whatsapp and signal like the plague. "mobile number" is in itself a big identifier when you are living in a place where you have o do mandatory KYC so that the government knows which each mobile number is linked to the actual human being. i dont care signal doesnt hold any messages. the government can ask for my number and they can use the xkcd spanner method to do the rest. the point is to AVOID PII in the first place, matrix does this wonderfully. no need for mobile number or email number or your real name. living in an actual police state, i can attest to how important that is, americans/europeans can hardly imagine.
- imiric 4y agoSure, but couldn't you just use a disposable number? (Assuming you live in a place where you can buy SIM cards without showing a personal ID, which is most countries.) That's a minor inconvenience compared to not being able to communicate with most people who use these mainstream networks. I'm more worried about the lack of encryption and trustworthiness aspect of them than giving away a phone number.
- ls15 4y agoMost countries require SIM card registration nowadays. https://www.phonetravelwiz.com/phone-travel-options/sim-card-registration/ https://www.phonetravelwiz.com/phone-travel-options/sim-card... > Of the 245 countries/territories with territory-bound mobile operators, 185 countries have SIM card registration laws. 13 will collect biometrics (fingerprints, but some will take a face scan too). 51 countries have no registration requirements. Which by itself is questionable.
- imiric 4y agoHmm I didn't think it would be that many. I'm sure there might be workarounds, like ordering online or buying from vending machines at airports, etc., but yeah, it's certainly not as convenient as before.
- 4y ago
- ummonk 4y agoEnd-to-end encryption doesn't protect you from this, since any recipient can report illegal material to the authorities and trigger an investigation of the sender.
- ls15 4y agoAgreed, ideally you have both, e2ee and no linked phone number.
- ViViDboarder 4y agoI’m that case, literally nothing will protect you from this. Any recipient can put anyone in any conversation.
- ummonk 4y agoThere can be TOR-like systems that with an ideal implementation make it impossible to obtain any metadata about the sender.
- dncornholio 4y agoSo that basically means don't use any messenger.
- brobinson 4y agoThere are options. Matrix, Session, Threema, Wire...
- Accacin 4y agoWire? Didn't they get bought out by some shady company a few years back?
- neongreen 4y agoI used to work at Wire. As far as I know there was no shady buyout, just new investors who were less lax about wanting Wire to actually make money. So they started reorienting at big corporate clients. The technology itself wasn't changed and Wire was still involved in exciting things like MLS (https://datatracker.ietf.org/doc/draft-ietf-mls-protocol/ https://datatracker.ietf.org/doc/draft-ietf-mls-protocol/) when all this was happening (~4 years ago).
- _8j50 4y agoNo, most. Like Signal for example. Even without security you can't migrate between android and iphone or have multiple devices with the same account. But they have crypto amd stories now lol.
- yieldcrv 4y ago*after giving them your phone number and everyone you want to message and the entire social graph from anybody with your number stored in their device's contacts list F, for Failure
- Accacin 4y agoAll the hating on Signal but for me it's the best and fits my threat model. I live in the UK and by all accounts I'm pretty unremarkable - I want privacy but not overly worried about anonymity, I also wanted something that I could persuade family and friends to use. Signal works perfectly in my use case, my friends and family happily switched over to it where when I tried to help my parents set up Matrix it was super verbose and required them to remember long passwords, etc. (of course they shoul dbe using a password manager, but one step at a time!).
- baxtr 4y agoWhich ones don't ask for a phone number?
- Semaphor 4y agoJabber/XMPP, Matrix are the obvious answers.
- nix23 4y agoI add IRC to the Mix
- bentley 4y agoIRC is not end‐to‐end encrypted.
- throwaway3859 4y agoYou could use a secure encrypted IRC-like protocol like Pest[0], though. [0]: https://pestnet.io https://pestnet.io
- mwest 4y agoComes up with a privacy error atm. Guess their server got bit hard by HN? Cached copy here: https://web.archive.org/web/20220915015328/https://pestnet.io/ https://web.archive.org/web/20220915015328/https://pestnet.i... Reminds me a bit of SILC: http://www.silcnet.org/ http://www.silcnet.org/ Still going to struggle with UX on a phone though...
- mwest 4y agoIn theory you can use OTR[1] but I've yet to see an easy way to use this from a phone. I remember IRC very fondly, but I feel it has a lot of baggage that makes it difficult to bring into the modern era. This blog post (not mine) explains it quite well: https://jlu5.com/blog/im-tired-of-irc-heres-why https://jlu5.com/blog/im-tired-of-irc-heres-why [1] https://otr.cypherpunks.ca/ https://otr.cypherpunks.ca/
- mtgx 4y ago> Telegram disguises itself as encrypted chat app, when it is actually just a regular centralized plaintext messenger that has an encryption feature that nobody uses. Best description of Telegram that I've seen so far. I do trust Signal to keep the phone numbers safe with their methodology for doing that, but probably wouldn't anyone else.
- Gasp0de 4y agoWhile Signal does require a phone number to register, they only know your phone number, your date of registration and the date of your phones last connection to signal's servers. Anyone requesting your information from them needs to provide your phone number, so any info they can get is account creation date and date of last connection.
- aliqot 4y agoSignal shouldn't ask for phone numbers. I don't give a shit what the justification is.
- hyperionplays 4y agoAgree
- fmn 4y agoDisagree
- Gasp0de 4y agoIf you want an anonymous messenger, Signal is not the product for you. If you want a secure messenger that doesn't (and can't) collect any data on your communication, and at the same time (due to the lack of anonymity) prevents spam, then Signal is the messenger for you.
- droopyEyelids 4y agowhat's up with constraints in general? Why are some things a requirement for other things? let's abolish this.
- para_parolu 4y agoPhone number is enough to find who is behind it in most cases.
- afroboy 4y agoSignal is more privacy than anonymous.
- discardedrefuse 4y ago> Telegram disguises itself as encrypted chat app No. It doesn't. This sentiment is pretty much confined to HN and seems to stem from the whole Moxie non-sense from years ago. Telegram is a so much more than a messenger. It competes with WeChat, not Signal. It has an incredible API, bots, payments, apps/games, and is host to Onlyfans / Discord-like social groups. It's time to stop parroting this idea that Telegram is some kind of secure messenger. Yes, it has secret chats, but that is not Telegram's defining feature.
- ls15 4y agoOn telegram.org under "Why Telegram" it says: * Simple * _Private_ * Synced * Fast * Powerful * Open * Secure * Social * Expressive According to Telegram's own priorization, privacy is its second most defining feature after simplicity. It is not by accident that people think that Telegram is focussed on privacy.
- discardedrefuse 4y ago> According to Telegram's own priorization, If you're going to be that puerile then... I had to scroll past their list of available clients and their recent news section to get to this "Why Telegram" section that first mentions the word "private". So clearly, that far down the page, its not a priority. Back in reality: The word "private" can mean anything. Every app and website that uses https claims to have privacy and security. If you bother to read their FAQ (which is always at the top of the page and, according to your logic, must be very important), there is a detailed explanation of exactly what is and isn't encrypted. https://telegram.org/faq#security https://telegram.org/faq#security I can already hear you typing, "but the average person doesn't read FAQs!" Well, the average person doesn't know or care about e2ee either. And the average person doesn't think Telegram is any more or less private than Facebook Messenger, WhatsApp, Twitter DMs, SMS, or email. The average person just doesn't think about privacy in this way.
- ls15 4y agoWhat does "Why Telegram" describe if not their mission?
- Eleison23 4y ago
- colonwqbang 4y ago> If you shouldn't be saying it, don't say it It's a beautiful thing, the destruction of words.
- rudasn 4y agoThe downvotes indicate you shouldn't be expressing this opinion on this site in this manner. There's a reason why. You shouldn't do it again. This incident has been noted for future reference. Thank you for your cooperation. Have a nice day!
- xsatchelx 4y ago> If you shouldn't be saying it, don't say it. If you're being censored, perhaps there's a reason why. That's awesome man! Now can you please share with us all of your private text messages?
- selfmodruntime 4y ago> What's your threat model that you can't use conventional channels to communicate stuff? If you shouldn't be saying it, don't say it. If you're being censored, perhaps there's a reason why. What an incredibly (western) privileged thing to say. LGBTQ people and oppressed women need secure channels to protect their lives. Protestors need secure channels to free themselves of censorship and an oppressive regime. Grow up. Maybe you‘re not as versed as you think if you‘ve not yet recognized the absolute evil of state actors.
- ls15 4y ago> (western) privileged thing to say Westerners need privacy too. The reversal of Roe v. Wade is a good reason for example.
- tintedfireglass 4y agoliterally 1984
- Eleison23 4y agoImagine if our water service was like the Internet: We'd distribute potable water by shooting it way up into the sky and just having a constant municipal drizzle/rain/downpour everywhere. Every house would have some buckets to collect enough potable water to use. Then the sewer system would be a bucket brigade: You fill a bucket at home and bring it over to your neighbor, and they pass it on in a long stinky chain of wastewater until it gets to the treatment plant or the ocean. There would be no such thing as faucets, pipes, or protected water sources. It would just be a cycle of spraying it all into the air and bucket-brigading back to the source. And that's today's Internet.
- naveen99 4y agoRain, solar, wind harvesting make sense though.
- qwerty456127 4y agoWhat data do they disclose?
- asymmetric 4y agoIt’s in TFA
- shapefrog 4y agoHow many times does it have to be said - Companies are not immune to court orders, CEOs wont do 10 years hard time so that your phone number or ip address or even unencrypted content isnt handed over in a police investigation in return for $5.99 a month.
- Grimburger 4y ago> CEOs wont do 10 years hard time They can knowingly launder billions of dollars for drug dealers plus terrorists and not even face a day in jail, comments like this make me chuckle. The only "CEO"s facing jail are the people with 100 employees who shouldn't even have the title in the first place.
- deleted 4y ago[deleted]
- sfusato 4y agoAll of a sudden, it seems really stupid that telegram stores all their data unencrypted and waiting for a court order. I expect them to fight this, because they have a very good track record there, but the moment they capitulate the floodgates will open.
- simiones 4y agoYou expect them to fight this after they have now disclosed all of the data? That's quite a high amount of optimism from you.
- Gasp0de 4y agoHave they disclosed the data? I think the title of the article is misleading. In the content, it says that they have been ordered by a court to disclose the data, but not that they have (they have in other cases though).
- simiones 4y agoThe article goes on to say: > Justice Prathiba M. Singh in the order dated November 24 said the names of admins, the phone numbers and IP addresses of some of the channels as are available with Telegram have been supplied. Of course, I can't independently verify this, but the article claims pretty clearly that the data has already been provided.
- Borgz 4y agoTelegram (and other messaging apps for that matter) should allow accounts to be created without a phone number, and ideally stop saving the IP addresses of users.
- sirius87 4y agoGovts would pretty much get the app delisted from app stores for violating the law as soon as the app got some traction. This is partly why Govts are so persistent about data-localization norms while in the past companies got away by storing data in a more privacy-friendly country. Here too, Telegram tried to make the argument that the data is stored in Singapore, but the courts got their way.
- arbitrandomuser 4y agoIt would have been neat if one could make an app on top of telegrams API to do e2ee , afaik that breaks telegrams API tos
- antisocialist 4y agoTelegram is convenient, the bot feature's great. But some things about it suck and they're prone to government interference privacy-wise. One of the more recent E2EE private messaging apps with metadata shredding and no registration requirement for is https://xx.network/messenger https://xx.network/messenger It's available for Android & iOS. F-Droid users can build Android version from the source (https://git.xx.network/elixxir/ https://git.xx.network/elixxir/) and load it themselves. There's no registration and the app doesn't collect your phone number, device ID and similar crap. Is it mature and polished? No, it has its quirks and rough corners. But it won't let you down on security and encryption.
- discardedrefuse 4y agoThere are so many buzzwords on that landing page. "quantum leap in privacy", "ultra-private messaging", "quantum-resistant and decentralized." And then you get to the best part: "built on the xx network blockchain". Web3 still out here trying to happen. Don't forget to buy some xx coins while you're there!
- AdrianB1 4y agoDoes Telegram have a branch in India? What is the teritorial limit of the Indian court decision? Internet is very tricky in this regard, but an Indian court has no jurisdiction over entities that are in other countries (this is also a very complicated matter).
- cryoz 4y agoIndian court has the jurisdiction to ban all Telegram activities in India. So if they want Indian users they have to comply.
- karp773 4y agoDid anyone already say that Telegram is Russia's KGB operation?
- stereoradonc 4y agoI am not defending Telegram, but as a social media application (and a private chat option), Telegram is only complying with existing laws. Copyright materials are a taboo on ANY electronic medium (including the open web). We just had a major issue around the Z-Library. Each time anything of this sort happens, I see the Signal users coming out from no-where. These news aren't a big deal, and numerous public channels have faced the axe. Most of them have changed tactics by going "private" by rapidly changing their invite links or using bot services to "verify users" before they join. Public groups earlier sharing copyright materials are "banned". There are numerous bots that connect to torrents and upload content to Telegram. Z Library still serves content; Nexus bots have just rolled out a feature to connect your bot (through API token). Signal serves a specific niche of users, and I think polarising arguments (or moralistic stands) are only to play to the gallery.