7 ms·
Another thing that wasn't pointed out: Du Rove said "Signal messages have been exploited against them in US courts or media." This would be the same case for T
by ixwt 2y ago
Another thing that wasn't pointed out: Du Rove said "Signal messages have been exploited against them in US courts or media."
This would be the same case for Telegram as well, if someone has your phone. I believe that Signal can have a lock on the client, and the database is encrypted.
The other part that Du Rove conveniently left out: Signal went against the US courts and won [0]. When subpoenaed to give all user information they gave them all that had: the unix timestamp of when the account was created, and the last date you connected to the signal service. That was in late 2021. I'm really curious as to what Telegram has told the FSB.
[0]: https://signal.org/bigbrother/cd-california-grand-jury/ https://signal.org/bigbrother/cd-california-grand-jury/
- noirscape 2y agoTelegram iirc moved it's lead developers to Dubai specifically because the FSB was demanding info from them, so you could argue that's an unfounded concern. The bigger problem with Telegram is that it by default has insecure encryption settings (as opposed to Signal, where encrypted is the default, you need to manually activate it with Telegram + I think it's not possible to enable for all chats and clients) and to my knowledge, Telegram will outright co-operate with law enforcement agencies to just hand over unencrypted communications. I'd personally argue that's a security dark pattern - make privacy a big selling point, but then don't activate the security by default
- 1oooqooq 2y ago> security dark pattern - make privacy a big selling point, but then don't activate the security by default pretty similar to whatsapp. they boast end to end encryption, but business account (all of them now) uses the facebook server's key, so that the business can give access to several other clients to answer customers. they still call it end to end encryption, and this was actually the last crap the original founder accepted before leaving with lots of money on the table.
- FiloSottile 2y ago“All of them” in what sense? I use WhatsApp dozens of times a day, and interact with business accounts every couple months at most.
- 1oooqooq 2y agoGood for you, you probably do not live in a country under digital colonialism where the gov allowed facebook et al to force internet providers to tax the pop with absurdly low and expensive data limits and then "not count" things like facebook and whatsapp and one music app. In most of the global south, 100% of business have a whatsapp. In those places it pretty much replaced telephone and the green whatsapp icon is now what the current young generation recognize as the we did the black telephone outline on a business front next to a number. and if you own a business, or is self employed, it is even worse: you live by that app.
- robertlagrant 2y agoAre you saying this is a worse alternative to other communication methods with businesses? What would you use with them that has better encryption?
- xethos 2y agoThe lack of encryption between myself and a business is less offensive than replacing an open standard (plain old telephone systems, eMail) with a proprietary and closed one, backed by a single, private corporation
- robertlagrant 2y agoI don't think they've been replaced, though?
- hughesjj 2y agoDe jure or de facto?
- ixwt 2y agoEDIT: Disregard below. I'm an idiot when it comes to maps. The statement regarding if the developers are still Russian I believe is still relevant. Considering the state of Saudi Arabia, having it there is marginally better, but still problematic. And if the developers are still Russian, there's nothing saying they aren't being squeezed unless their families came with them to Dubai.
- rgrmrts 2y agoDubai is in the UAE, not Saudi Arabia
- znpy 2y ago> I'd personally argue that's a security dark pattern - make privacy a big selling point, but then don't activate the security by default I think it's a great approach instead: the secure, end to end encryption is there and it's ready to be used. You can easily activated it but you aren't burdened by it for 99% of the time when e2e encryption is not needed.
- input_sh 2y ago> You can easily activated it but you aren't burdened by it for 99% of the time when e2e encryption is not needed. So, in those 1% of the cases when you actually need it, you're instantly flagging yourself as doing something fishy? Because if it ever comes down to it, good luck proving otherwise in a court. That's like the whole point of why it should be on by default. Not because me making dinner plans is something super-secret that needs to be e2e-encrypted, but because those two scenarios need to be indistinguishable from each other for e2e to be effective.
- seanhunter 2y agoYes. Additionally you are at bare minimum signalling that the metadata of the encrypted comms is worth further analysis. For exactly the same reason if you have a paper shredder, you don't only shred confidential material, you shred a bunch of junk as well to make it harder to find which pieces to reconstruct.
- deepsun 2y ago> because the FSB was demanding info from them But they gave the FSB info they asked for -- the vk.com website (facebook clone, at that time it had way more massive amounts of user data than telegram). They could have deleted the data, but no, they handed it over to FSB.
- scott_w 2y agoI will point out, in their defence, they handed it over to an organisation that has a habit of assisting people in learning how to fly from windows. This isn't to say Telegram is secure but that it's unlikely they "could have deleted the data" and remained alive.
- deepsun 2y agoFSB mostly wanted to prevent people organizing, and that would serve it well. They already had another popular service (odnoklassniki.ru) where to direct people.
- proxysna 2y agovk.com and telegram have nothing in common, except the founder. Durov was forced to sell his part in the vk.com and telegram development started after that as a response.
- ceejayoz 2y ago> vk.com and telegram have nothing in common, except the founder. This is a deeply funny sentence. "Other than that, Mrs. Lincoln, how was the play?"
- 5e92cb50239222b 2y agoYou conveniently forgot about the second part of that comment. Durov was forced out of the country and had to cell vk.com for peanuts because of his refusal to cooperate with the government. He is still pissed off at the country at large (not just the government) and refused to add the Russian translation for years, for example, despite it having absolutely nothing to do with Putin. Since he is Russian in origin, it's okay to throw baseless accusations at him and spout nonsense like "maybe they're FSB agents" or "maybe they hired an FSB agent without knowing it". You see it here everywhere, and HN is one of the better sites in that regard. Well, maybe Signal has hired an NSA agent and doesn't know about it either? How does that sound?
- viraptor 2y ago> Telegram iirc moved it's lead developers to Dubai specifically because the FSB was demanding info from them, so you could argue that's an unfounded concern. I'd argue it's not giving us any certainty. They could've moved away to escape. They could've moved away to a nice FSB-sponsored location while making good publicity. Ideally the tech should be good enough for this issue to not matter.
- slac 2y agoTo add to this: and they may have hired a FSB agent without knowing it.
- pdimitar 2y agoTelegram has moved to Dubai long ago so no idea where you get the idea that FSB can strong-arm them from.
- sbarre 2y agoAh yes, Dubai the bastion of integrity, equality and human rights.
- pdimitar 2y agoTrue, they aren't. Whether they're friends with Russia is another thing though.
- sbarre 2y agoThey don't have to be friends to turn a blind eye. If Dubai had to pick between letting some nobody foreign national living on their soil get squeezed by a foreign secret police, or pissing off the Russians, what do you think they would do? (This isn't a knock on Dubai specifically, substitute them for almost any non-NATO country in the world).
- pdimitar 2y agoAnd you think the USA doesn't do such things? If so, that's quite naive.
- sbarre 2y agoDid I say that? Did I mention the USA at any point in this discussion? What a strange thing to add. I am not American btw.
- pdimitar 2y agoI mentioned it because people very easily single out Russia and I think that's quite the outdated sentiment. I'd start with USA, North Korea, China, Russia and Iran -- again, just as a start, and I am sure there are many others that can't be trusted. Where Telegram's devs and business resides hardly matters IMO. If somebody truly wants to put them under their boot they'll find a way, and that goes for probably half the countries on this planet.
- seventyone 2y ago"Winning" would mean not having to comply with the subpoena...
- ixwt 2y agoThe winning in this case was they had to fight to be allowed to release what they provided. As nice as it would be to not have to provide that information, Signal proved that the only information they have to give is largely useless to law enforcement.
- seventyone 2y agoSo they lost and have to give up the information/metadata they have. It's just good news that it wasn't much. But that's not guaranteed to always be the case.
- _djo_ 2y agoNo, you're misunderstanding the situation. Companies can't legally refuse to provide information in the jurisdiction they're in some cases, especially when there's a court order. Every company is subject to someone's jurisdiction. Signal prepared ahead for that eventuality and designed it so that their services received stored only the absolute bare minimum of information, and that most importantly didn't preserve the metadata of chats and calls. This is unlike Meta, for instance, which does keep that data for WhatsApp even though the chats themselves are encrypted. That means that what they provided in that particular subpoena is all they can provide from their server records for any user of Signal, not that it's all that was available in that particular case. It would've been even more anonymous if not for the phone number requirement, but I can understand why they made that trade off and given the lack of metadata it's not that useful to law enforcement/surveillance agencies in any case.
- hobs 2y agoThe database is encrypted, and the password is right next to the database in a json file.
- Tmpod 2y agoOn desktop, on Android and iOS it uses the OS keystore. It really should do on desktop as well, Windows, Mac and Linux (through freedesktop standard) all have APIs for that, there really isn't much excuse. Desktop Signal has always had terrible security, unfortunately.
- deleted 2y ago[deleted]
- jjav 2y ago> they gave them all that had: the unix timestamp of when the account was created, and the last date you connected to the signal service. I'm confused. Signal also has your phone number because they require it, that's the primary privacy criticism against Signal.
- smarek22 2y agoI believe they have your phone number hashed not in plaintext, also they rolled in usernames recently and option to not expose your phone number to anyone, which addressed privacy concerns
- jjav 2y agoI don't know how they store phone numbers, but hopefully not hashed since the search space is trivially tiny. The usernames thing does not address any interesting concern. I don't care to show my friends who I chat with my name and phone. They already know these after all. What I care about is not having to give Signal (the company) my phone number. That's not something they should have.