7 ms·
Indian government bans 14 messenger apps including Element, Briar and Threema
- PrimeMcFly 3y agoA decentralized internet is the only way forward, at least if we want to maintain the level of freedom we have now. Too many countries are trying to lock too much stuff down.
- notRobot 3y agoWell they just banned the decentralized communication apps (like Element). Users can of course work around these bans, but many of them don't have the technical know-how or aren't going to bother.
- villgax 3y agoThat's the saddest part of our current world. Deciding what is best for their citizens using technology which they did not invent themselves....
- rogers18445 3y agoThese things are typically bureaucratic security theater. Terrorists can sideload. The decision makers just care to be seen doing something, whether it's useful or not is not their problem.
- p-e-w 3y agoYou severely underestimate the people in power, and the people who stand behind them. Such bans are deliberate attacks targeting (parts of) the general population. Terrorists have nothing to do with this. "Hahaha those stupid bureaucrats, they have no idea what they are doing" is a popular meme, but it couldn't be further from the truth. They do know what they are doing, and it's working. If you believe it isn't, that's only because you misunderstand what the real goal is.
- nsriv 3y agoAbsolutely. I know from personal experience that much of what remains of independent journalism in India, as well as some NGO work (long under government scrutiny) is conducted through Signal and Element.
- jruohonen 3y agoWell they've caught bad people using Signal too: https://telecom.economictimes.indiatimes.com/news/dangerous-signal-this-encrypted-app-is-helping-isis-members-in-india-to-communicate/51774226 https://telecom.economictimes.indiatimes.com/news/dangerous-... Besides Pegasus and such and the interception issues with SMS, might be as well due to HUMINT and the weaknesses in verifying fingerprints. Probably it would be best for people in some of these countries to do their work offline.
- jruohonen 3y agoPerhaps I should add that I do not wish to undermine the terrorism situation in India, which is very much real. Regardless, there is a paradox because at the same time the associated terrorism laws and hacking operations have been misused to target opposition, journalists, scientists, activists, and many others.
- deleted 3y ago[deleted]
- dalbasal 3y agoI disagree. This may or may not be effective, but it's not theatre. Criminals, terrorists, dissidents, politicians, even intelligence people sometimes... they're users. Just because they can sideload, or otherwise use more sophisticated methods doesn't mean they will. The margins are wide. Imo, same thing is happening in India as is happening in most places with an active security-intelligence service. They receive valuable intelligence from PMs. Then they fret about potentially losing access or want to increase access. If you read HN/Reddit/Twitter, you'd get the impression that all this stuff is fake. It's not. Intelligence agencies in 2023 are all about these sources, and jelously guard them. Once they have a source, they're not giving it up willingly.
- jruohonen 3y agoExactly as you said. Besides, much of things cannot be sideloaded because otherwise recruitment for a cause becomes impossible.
- nine_k 3y agoCertainly a ban like that, if it can be made at least somewhat effective, will prevent a lot of uses of encrypted messaging by less sophisticated users. I'm afraid it's not going to be effective against the stated targets, the well-prepared terrorists sponsored by a neighboring state. Those will be trained to sideload, or whatever else it takes.
- rinka_singh 3y agoEven "somewhat effective" is better than no ban. Given the state of terrorism in some parts, this is a crucial tool. For example in the aftermath recent terrorist bombing in Pulwama, clamping down on Internet had helped. Let's not forget people died there.
- princevegeta89 3y agoWhat if they also get blocked on a DNS level, just like how they did those porn sites? You can actually use VPN. But what if the vpn services also get blocked? While achieving 100% of a blockage is not possible but achieving even a 30% is great.
- notimetorelax 3y agoThey do deep packet inspection on the telco end and drop packets to the blocked servers. Sure there might a way to circumvent, especially if there’s a p2p app, but even those packets may be detected and dropped.
- thriftwy 3y agoWhen this stuff started happening in Russia qlmost a decade ago, everybody was joking about bureaucrats instead of taking measures. Fast forward a few years, Internet access is not unlike cheese with holes in it, and a great number of people had to invest in VPN access.
- Barrin92 3y ago>Terrorists can sideload many don't because terrorists in reality don't tend to be very smart. And if they do, its not that difficult to trick them and compromise that channel aswell (https://www.washingtonpost.com/world/2021/06/08/fbi-app-arrests-australia-crime/ https://www.washingtonpost.com/world/2021/06/08/fbi-app-arre...) The amount of people who get caught on insecure communication, including some famous tech CEOs, is staggering. Most people, criminal or not, are completely security/tech illiterate. Changing the default has a huge impact. Webs in these investigations tend to be wide so it's not just about literal criminals, if one suspect leaks info to anyone that may be enough for authorities to catch on, it's a statistical game basically and the harder you make it to not mess up the higher your chance to catch someone. Gentle reminder that the US intelligence leaker was caught because he distributed the material on a gaming discord on an account with user info that was one Google search away from his father's instagram and steam profile. And that guy was US National Guard tech support staff.
- norgie 3y agoTerrorists aren't the real target of bans like this. Journalists, dissidents, and opposition figures are.
- rinka_singh 3y agoDisagree - this is unsubstantiated and worthy of an Elon Musk style of how he stripped that BBC reporter down. If they were the targets, Journalists, dissidents would have completely dissappeared over time. They are active and vociferous.
- Andrew_nenakhov 3y agoThe idea of mass surveillance is never to counter the terrorists. It is to control the masses and have a dossier on everyone.
- opportune 3y agoUnless this is a feint, this seems like a dumb way to telegraph which apps you don’t have backdoor access to (the banned ones) and the ones you do (everything relevant enough to be considered that wasn’t banned). Any client side ban can be easily circumvented with sideloading and network-level ban with a VPN (or less easily, TOR) I’m sure in some cases these bans are indeed a feint but not everything is a game of 4d chess. I mean, look at the TSA in the US
- tmikaeld 3y agoSo, you're suggesting Signal has a back-door?
- opportune 3y agoI don’t know. Neither this article nor the article it references (https://www.news18.com/amp/india/govt-blocks-14-mobile-messenger-apps-in-jk-used-by-terror-groups-to-contact-supporters-ogws-exclusive-7684669.html https://www.news18.com/amp/india/govt-blocks-14-mobile-messe...) seem to have the full list. For a high profile app like Signal (which more than just the Indian government cares about) I assume there are security vendors or US intelligence solutions to get access. I mean, for one, the US government and EU can make Google and Apple do anything by showing up to their offices with guns. It’s also a high value target for whatever you call those security firms that sell exploits to nationstates. For intelligence purposes you’d rather centralize targets on a small number of platforms that they think are safe and not give them a reason to leave, rather than have them be fragmented across many platforms which each require some kind of backdoor/additional work to get access to. I guess I’m getting downvoted for insinuating Signal has a backdoor without evidence, but an iOS or Android level exploit or backdoor would easily function as a signal backdoor, and depending on its implementation (like peaking at process memory) could be hard to get working for each and every random app. There’s also the risk of an app store itself adding a backdoor or a Signal insider sneakily creating one to sell the exploit. These all seem highly possible given the various NSO exploits that have hit the news.
- russnes 3y agoLast I checked Signal has reproducible builds at least on Android, so it should be possible to verify it doesn't have back doors.
- gopheryourshelf 3y ago[flagged]
- 0xDEF 3y ago[flagged]
- wolverine876 3y agoWould you share a good, credible source for that?
- dang 3y agoPlease don't take HN further into hellish flamewar. It's not what this site is for, and destroys what it is for. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- dang 3y agoPlease don't take HN into political or ideological or nationalistic flamewar. It's not what this site is for, and destroys what it is for. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- newswasboring 3y agoHi dang, this is a policy on this forum, and it's completely up to the site maintainers. But in that case I would rather you don't allow these articles on HN at all. I understand why this policy is there, but these are completely political policies and as an Indian you not letting us acknowledge that it is a political policy made by a certain kind of government seems... I don't know, I can't come up with a polite term.
- dang 3y agoThat question has a long history on HN and we eventually arrived at a clear answer: the shallowest sort of political stories are offtopic here, but there are also interesting stories with political overlap, and it's neither possible nor desirable to exclude all of those. A great deal of past explanation about this can be found at https://hn.algolia.com/?dateRange=all&page=0&prefix=false&sort=byDate&type=comment&query=political%20overlap%20by:dang https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so.... When a story does have political overlap, it's incumbent on commenters to stay within the site guidelines regardless of how strongly they feel, or how wrong they feel other people are. This is in the site guidelines: "Comments should get more thoughtful and substantive, not less, as a topic gets more divisive." That's not easy, but it's possible. For this forum to succeed at its mandate, we all have to work hard at it. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- joecool1029 3y agoBan seems to be limited to Jammu and Kashmir, not rest of India. Only commenting for additional detail, not to express a viewpoint about it. Another source: https://economictimes.indiatimes.com/news/defence/india-blocks-14-apps-in-jammu-and-kashmir-for-spreading-terror/articleshow/99900313.cms https://economictimes.indiatimes.com/news/defence/india-bloc...
- captn3m0 3y agoI didn’t see that in the ET article. Is there another source?
- error_404_302 3y agohttps://www.thehindu.com/news/national/centre-blocks-14-mobile-messenger-apps-being-used-by-terrorist-groups/article66799154.ece https://www.thehindu.com/news/national/centre-blocks-14-mobi...
- joecool1029 3y agoI don't think this ultimately answers the question. It looks like I was incorrect and it is a national blocking order under Section 69A of the IT Act. This is the original news source everyone else is regurgitating: https://www.aninews.in/news/national/general-news/centre-blocks-14-apps-in-jammu-and-kashmir-for-spreading-terror20230501095505/ https://www.aninews.in/news/national/general-news/centre-blo...
- villgax 3y agoNice, now block Koo, ShareChat, Flock in response. Should we just do encrypted SMS at this point lol
- nine_k 3y agoI suppose real secret agents run a VPN client that looks like a game of chess, or go, or something else innocuous, and playing a particular unpopular debut switches on the VPN, while fumbling with settings just so switches it off, etc. Otherwise it's a standard-enough chess program that can honestly play some chess. I don't think that TLS to port 443 can draw too much attention, too.
- nine_k 3y ago> the blocked apps include Crypviser, Enigma, Safeswiss, Wickrme, Mediafire, Briar, BChat, Nandbox, Conion, IMO, Element, Second line, Zangi, Threema, among others. That is, anything that's easy enough to detect in the traffic, I suppose? Or does it just affect App Store / Play Store? > The step was taken after multiple agencies found that these apps were being used by terrorists to communicate with their supporters and on-ground workers I wonder if it applies to members of general public, or to trained agents. For the former, the ban may work. For the latter, I suppose, there's less chance: they must have other means to install apps, various VPNs set up, and some opsec training. > The government found that these apps did not have representatives in India and they could not be contacted for seeking information as mandated by Indian laws. This, of course, should be by design for any really secure communication app. A legal entity representing a secure channel is a people to press on in cases like that, ans such pressure from law enforcement is and will be inevitable. I think Tor network has no legal representative anywhere.
- worldsavior 3y ago> That is, anything that's easy enough to detect in the traffic, I suppose? Or does it just affect App Store / Play Store? No, this is because they have good security/privacy and don't allow the Indian government to control.
- nine_k 3y agoI mean, what the "banning" means? If the internet operators are not ordered to stop these networks from operating, it's not much of a ban. If internet operators have no means to stop these protocols, then the ban is unlikely to have any real effect beside some inconvenience.
- worldsavior 3y agoIf the government doesn't allow to use these apps, ISPs probably also have to comply in some way (probably blocking URLs). And if not, app stores would probably need to hide these apps. I mean, those are legal issues. The point is they're banning them and if you use them you go against the law.
- bkishan 3y agoTerrorist use crypto, they also use cash. Ban them too? Doesn't make a lot of sense that something is banned just because it was used by a bad actor. Or this is just security theatre.
- devoutsalsa 3y agoHow about making a chat interface for email? They won’t ban email. Or will they?
- hestefisk 3y agoAnd how come WA is not blocked?
- newswasboring 3y ago[flagged]
- nitrammm 3y agoBecause they weigh pros and cons. Banning these apps will have relatively few cons compared to banning WA.
- error_404_302 3y agoIs there any indian EFF equivalent who can legally challenge this?
- jruohonen 3y agoAs far as I know, no. I think pushback has mostly come from international NGOs but without much success: https://www.hrw.org/news/2022/12/23/india-data-protection-bill-fosters-state-surveillance https://www.hrw.org/news/2022/12/23/india-data-protection-bi...
- pferde 3y agoWow, thats a ringing endorsement for these three services ... a totalitarian government banning them. You can't pay for that kind of marketing! :-)
- chaostheory 3y agoSadly, this will be a global trend. As times get tougher, historically governments tend to become more authoritarian and centralized
- emodendroket 3y ago> As per a report by News18, based on source inputs, the blocked apps include Crypviser, Enigma, Safeswiss, Wickrme, Mediafire, Briar, BChat, Nandbox, Conion, IMO, Element, Second line, Zangi, Threema, among others Are these more popular outside the US? Maybe I’m just out of touch? It looks like you asked ChatGPT to generate a bunch of fake app names.
- potamic 3y agoIndividual countries do stupid things from time to time, but what worries me is the global trend where countries are showing a desire to control communication. It comes in the form of encryption backdoors, age limits for social media, monitoring for child porn etc, but the end goal seems to be complete control of all communication channels between citizens. The concept that governments will love to push for is where citizens need to provide identification for accessing all web services and all web activity is linked to their identification. Digital infrastructure these days is sophisticated enough to handle this and it only takes for one country to enact this and get the ball rolling for everyone else.
- nine_k 3y agoGovernments are created to control, so they strive to grab more control, by their nature. There may be no nefarious intent behind that tendency, or any intent at all. If something is made round, it will have a tendency to roll. This is why systems of checks and balances were invented, separation of powers, press freedoms, the democracy itself: these are systems that actively prevent the government from grabbing more and more power, just because it can. When the government is able to suppress or diminish the influence of these counterbalances, usually on the grounds of enforcing security and safety of the citizens, the process can escalate and end up in an authoritarian rule. Such (attempts at) power grabs will always happen, and will.always need a push back. It's a dynamic balance, when a balance can be achieved at all.
- BiteCode_dev 3y agoBriar can be banned, but for now it can't really be blocked though. It's supposed to work in case the infrastructures are down by design. So it can also work locally, meaning 2 Briar users can meet, and share messages from 1000 other users, and go on their way to propagate the update, without going trough the internet. Now of course you can always enforce the ban, not through blocking, but through detection and punishment. However I doubt you want to spend that much resources for a single app.
- azurenumber 3y agoList of 14 Apps Banned in J&K by Central Government As per the source, the GoI has banned a total of 14 apps and they are as follows: Crypviser Enigma Safeswiss Wickrme Mediafire Briar BChat Nandbox Conion IMO Element Second line Zangi Threema From : https://www.mysmartprice.com/gear/full-list-of-14-messenger-apps-banned-india/ https://www.mysmartprice.com/gear/full-list-of-14-messenger-...
- jruohonen 3y agoI've never even heard of any of those.
- azurenumber 3y agoNot even Element , its default matrix client
- 2Gkashmiri 3y agoas a kashmiri and someone interested in propagation of matrix as a protocol viz a viz EU dma with hopes of the spillover effect reaching the rest of the world and eventually my hometown, this is a spanner in the gears but no worries. element.io is working on Jio fiber here in j&K. AMA
- vinay_ys 3y ago<non-tech> Cross-border terrorism is real. Real-time support (operational and financial) by foreign and local bad actors is real. Governments have a mandate to protect their citizens against them and have to keep up with the tactics, techniques and procedures of these bad actors. So, let's not be surprised or shocked when we see news like this. </non-tech> Many apps in this list are also highly vulnerable. Threema, for example, was found to have serious security vulnerabilities due to rolling its own crypto implementations. It is interesting to note that Signal, WhatsApp, iMessage and soon Twitter DMs – all of which claim to have E2E encryption – are not on this list. Does that mean these companies have a way to break encryption and provide access to government when they ask for it? I suspect metadata is definitely accessible via these companies. Interestingly these are all messengers that have mobile phone numbers as primary user handles whereas a lot of the banned messengers are not. So, its possible that there are phone number based zero-click exploits for these popular apps that governments across the world use (remember NSO?) whereas not for less popular apps.
- MattPalmer1086 3y agoI very much doubt the Indian government can break the encryption of Signal or WhatsApp. The article says that the apps that were banned provided anonymity.
- vinay_ys 3y agoGovt don't need to break encryption technically. They just need to have lawful orders issued to the app or platform companies to comply to provide the information about the targets (1-1 chats or group chats). Question is - can the companies comply? Do the companies themselves have backdoors so they can comply? Btw, there are laws on the books that say they ought to have mechanisms such that they can comply.
- MattPalmer1086 3y agoThe only way a company providing end to end encrypted messaging service can comply with such an order is to ship a backdoored version of their client software. This might send copies of the messages somewhere else as well, or use deliberately weakened keys, or something like that. There is no way for the companies to break the encryption on their servers without compromising the client first.
- akwizgran 3y agoBriar developer here. We weren't contacted by the Indian government and we haven't received a copy of the blocking order. If anyone reading this works at Google or has a contact there, please put us in touch (contact@briarproject.org). We'd love to know whether Google has received a blocking order, and if possible get a copy of the order so we can challenge it in court. In the meantime, the app remains available from our website and F-Droid (https://briarproject.org/download https://briarproject.org/download). The app can also create a wi-fi hotspot to share the APK with people nearby.
- crnkovic 3y agoThe blocked apps are: 1. Briar (decentralised encrypted chat app): https://briarproject.org https://briarproject.org 2. Crypviser (decentralised encrypted chat app): https://crypviser.network https://crypviser.network 3. Enigma (encrypted chat app): https://enigma.im/en/ https://enigma.im/en/ 4. Safeswiss (encrypted chat app): https://www.safeswiss.com https://www.safeswiss.com 5. Wickr Me (discontinued encrypted chat app): https://wickr.com/me/ https://wickr.com/me/ 6. Mediafire (file hosting website): https://www.mediafire.com https://www.mediafire.com 7. BChat (decentralised encrypted chat app): https://bchat.beldex.io https://bchat.beldex.io 8. Nandbox (unencrypted video/voice chat app): https://nandbox.com https://nandbox.com 9. Conion (encrypted chat app): https://play.google.com/store/apps/details?id=com.secapp.tor.conion&hl=en_IN https://play.google.com/store/apps/details?id=com.secapp.tor... 10. IMO (unencrypted video/voice chat app): https://imo.im https://imo.im 11. Element (encrypted chat app): https://element.io https://element.io 12. 2nd Line (unencrypted VoIP app): https://www.2ndline.co https://www.2ndline.co 13. Zangi (encrypted chat app): https://zangi.com https://zangi.com 14. Threema (encrypted chat app): https://threema.ch/en https://threema.ch/en Source: https://qz.com/india-has-blocked-14-messenger-apps-on-security-fears-1850390425 https://qz.com/india-has-blocked-14-messenger-apps-on-securi...