8 ms·
I am null at cryptography but thie following does not sound too bad as a default tbh. And I think it is misleading to focus solely on e2ee and not mention the d
by 331c8c71 2y ago
I am null at cryptography but thie following does not sound too bad as a default tbh. And I think it is misleading to focus solely on e2ee and not mention the distributed aspect.
https://telegram.org/faq#q-do-you-process-data-requests https://telegram.org/faq#q-do-you-process-data-requests
> To protect the data that is not covered by end-to-end encryption, Telegram uses a distributed infrastructure. Cloud chat data is stored in multiple data centers around the globe that are controlled by different legal entities spread across different jurisdictions. The relevant decryption keys are split into parts and are never kept in the same place as the data they protect. As a result, several court orders from different jurisdictions are required to force us to give up any data.
> Thanks to this structure, we can ensure that no single government or block of like-minded countries can intrude on people's privacy and freedom of expression.
> Telegram can be forced to give up data only if an issue is grave and universal enough to pass the scrutiny of several different legal systems around the world.
> To this day, we have disclosed 0 bytes of user data to third parties, including governments.
- fsflover 2y ago> Telegram can be forced to give up data That's all you need to know. Matrix and Signal can't be forced in any way.
- ThePowerOfFuet 2y agoThe admins of Matrix instances sure can be forced to give up data. The metadata is not encrypted, and many rooms are not either.
- fsflover 2y agoWith Telegram, even the data can be accessed. Also: https://news.ycombinator.com/item?id=41351227 https://news.ycombinator.com/item?id=41351227
- foresto 2y agoMetadata is indeed an open issue on Matrix. I believe addressing it is on their to-do list. Many rooms are not encrypted because they are public rooms, where there would be no point in it. Encryption has been the default for quite a while now.
- _flux 2y ago> I believe addressing it is on their to-do list. I doubt that it's very high on that list, as the problem seems a very hard. Very hard as in that do we even know it's possible? "Metadata" includes a lot of stuff, but basically the originator, the destination and the timing of the messages and participants of a room are all quite difficult to hide in a federated system. I do believe there is a plan for getting rid of the association of one user in multiple rooms, but that's but a small bit of metadata. I think it is part of the puzzle for supporting changing homeservers.
- foresto 2y agoI was referring to the metadata that are typical complaints about Matrix, like usernames and reactions. > "Metadata" includes a lot of stuff, but basically the originator, the destination and the timing of the messages Indeed. AFAIK, sender/recipient correlation cannot actually be protected at the software level, because packet switched networking necessarily reveals it. The common way I'm aware of to mitigate this problem is at the network level, by trying to avoid common routes that would allow monitoring many users' traffic from any one place. Concretely, that might mean having everyone use Tor (which some folks suggest already) or going fully peer-to-peer (which some messengers do already, and Matrix has been experimenting with). Signal tries to improve the situation with Sealed Sender, but I'm pretty confident that can't protect against the Signal servers being compromised, nor against network monitoring. When trying to think of how it's useful at all, the only thing that comes to mind is that it might strengthen the Signal Foundation's position when a government demands logs. (And if that is why they implemented it, I suppose they must be keeping logs, at least for a short period.) Related: https://www.ndss-symposium.org/ndss-paper/improving-signals-sealed-sender/ https://www.ndss-symposium.org/ndss-paper/improving-signals-...
- fsflover 2y agohttps://news.ycombinator.com/item?id=41351227 https://news.ycombinator.com/item?id=41351227
- StrLght 2y agoProblem with this claim is that it's hardly verifiable. Telegram's backend is closed source, and the only thing you can be sure of is that their backend sees every message in plaintext.
- EGreg 2y ago[flagged]
- lukeschlather 2y agoCrypto is really hard. You have to trust that whoever implemented the crypto is smart and diligent, and you have to trust that whoever operates the crypto is smart and diligent, and you have to trust both of those parties. Centralization means that it's very easy to trust that whoever implements and operates the crypto is smart. Do I trust them? I don't know. I trust myself, but I don't think I am independently capable of operating or implementing crypto - if I want to make assertions like "this is end-to-end-encrypted" and ensure those assertions remain true, I will need a several million dollar a year budget, at a minimum. "Decentralized" means you've got tons of endpoints that need securing, and they can share crypto implementations, but the operations are duplicated. Which means it's more expensive, and you're trusting more operators, especially if you want resiliency. Yes, something like Signal or Whatsapp means you've got a single point of failure, but something like Matrix, you've got many points of failure and depending on how it's configured every point of failure can allow a different party to break the confidentiality of the system. Decentralization is great for resiliency but it actively works against reliable and confidential message delivery.
- EGreg 2y agoIt's always very easy to trust as long as you're allowed to be mistaken in your trust. That's literally how people fall for all kinds of things, including wars, advertising, etc. It's much harder to fool all the people all the time, than corrupt some of the people (the ones in charge) all the time: https://www.npr.org/sections/parallels/2014/04/02/297839429/-so-you-think-youre-smarter-than-a-cia-agent https://www.npr.org/sections/parallels/2014/04/02/297839429/... The mistake Moxie makes (and you do as well, you should really click on the links I posted to understand why) is that "no one wants to run a server". In fact, an entire industry of professional "hosting companies" exists for Wordpress, Magento, etc. It's a free market of hosting. You can't trust the software they're hosting, that's true. Which is why we have things like Subresource Integrity on the Web, IPFS, and many other ways to ensure that the thing you're loading is in fact bit-for-bit the same as the thing that was just audited by 3 different agencies, and battle-tested over time. Think UniSwap. I'd rather trust UniSwap with a million dollars than Binance. I know exactly what UniSwap will do, both because it's been audited and because it's been battle-tested with billions of dollars. No amount of "trust me bro" will make me trust Binance to that extent. The key is "Smart contract factories": https://community.intercoin.app/t/intercoin-smart-contract-security/2759 https://community.intercoin.app/t/intercoin-smart-contract-s... In short, when you decouple the infrastructure layer (people running ethereum nodes) from the app layer (the smart contracts) all of a sudden you can have, for the first time in human history, code you can trust. And again, there is a separation of responsibilities: one group of people runs nodes, another group of people writes smart contracts, another group audits them, another makes front-end interfaces on IPFS, etc. etc. And they all can get paid, permissionlessly and trustlessly. Look at Internet Computer canisters, for instance. Or the TON network smart contracts. There are may examples besides slow clunky blockchains today.
- ahmedbaracat 2y agoI am wondering if there was any incident that disproved the “we have disclosed 0 bytes of user data to third parties, including governments.” statement.
- ementally 2y agoYes, https://www.androidpolice.com/telegram-germany-user-data-surrendered/ https://www.androidpolice.com/telegram-germany-user-data-sur...
- littlestymaar 2y agoSplitting stuff between multiple companies doesn't really protect anyone if the boss of all companies is held hostage. Also > To this day, we have disclosed 0 bytes of user data to third parties, including governments. Didn't they conclude an agreement with Russian gvt in 2021?
- kitkat_new 2y agoI wonder if this is practically relevant at all. Given that users can access their messages without interaction with people at Telegram, automatic aggregation of the cloud data for single end points is in place. In consequence the data can be accessed from a single jurisdiction anyways.
- al_borland 2y agoWouldn’t being forced to give up the password and logging in be a violation of the 5th amendment, at least in the US? I think it’s a mixed bag of rulings right now, but it seems like it would make sense for it to fall that way at the end of the day.
- kitkat_new 2y agoeven if you have a password in Telegram as a second factor, Telegram can bypass it anyways; and the user isn't even asked
- episteme 2y agoI do wonder if this would hold up though, if telegram stored each character of your chat in a different country, would a single country not be able to force them to hand over the data and either fine them or force them to stop operating if they wouldn't share the full chat? It seems like a loophole but I don't know what the precedent is.
- tamimio 2y agoThat’s Telegram's CEO saying how he and his employees were “persuaded and pressured” by US FBI agents to integrate open-source libraries into Telegram (1).. There are a lot of questions to ask, like if the open-source libraries are indeed compromised, among other things. I take it as this arrest was the final straw to pressure him to give up and hand over some “needed” data, as all the accusations I read are laughable. Instagram is full of human trafficking and minor exploitation, drug dealers, and worse. The same goes with other social media, and I don’t see Elon or Zuck getting arrested. I am confident that this arrest is to obtain specific information, and after that, he will be released, or spend 20 years if he doesn’t comply. (1) https://youtu.be/1Ut6RouSs0w?t=1082 https://youtu.be/1Ut6RouSs0w?t=1082
- maqp 2y agoOr he's trained in the art of lying "At St. Petersburg State University, Mr. Durov studied linguistics. In lieu of military service, he trained in propaganda, studying Sun Tzu, Genghis Khan and Napoleon, and he learned to make posters aimed at influencing foreign soldiers." https://www.nytimes.com/2014/12/03/technology/once-celebrated-in-russia-programmer-pavel-durov-chooses-exile.html https://www.nytimes.com/2014/12/03/technology/once-celebrate... You really think the FBI would casually go to Durov and start telling him which libraries to deploy in his software. This "They're trying to influence me that means its working" 5D-chess is the most stupid way to assess security of anything. There's nothing to backdoor because it's already backdoored: Code does not lie about what it does. And Telegram clients' code doesn't lie it doesn't end-to-end encrypt data it outputs to Telegram's servers. That's the backdoor. It's there. Right in front of you. With a big flashing neon light says backdoor. It's so obvious I can't even write a paper about it because no journal or conference wouldn't accept me stating the fucking obvious.
- tptacek 2y agoYou can coherently argue that encryption doesn't matter, but you can't reasonably argue that Telegram is a serious encrypted messaging app (it's not an encrypted messaging app at all for group chats), which is the point of the article. The general attitude among practitioners in the field is: if you have to reason about how the operator will handle legal threats, you shouldn't bother reasoning about the messenger at all.
- EGreg 2y ago[flagged]
- kasey_junk 2y ago> you can install a reproducible build of Telegram and be sure it's end-to-end encrypting things. This is incorrect. The construction for group chats in Telegram is not e2e at all. The construction for dm’s is considered dubious by many cryptographers. It does not matter if you can reproduce a non-e2e encrypted message scheme, you must still trust the servers which you have no visibility on. Trustworthy e2e is table stakes for this for that reason. Reproducible builds aren’t because we can evaluate a bunch of different builds collected in the wild and detect differences in implementation. This is the same thing we’d do if reproducible builds were in effect. There are lots of reasons splitting jurisdictions makes sense but you wrote a whole bunch of words that fall back to “hope Telegram doesn’t change their protections in the face of governmental violence”.
- EGreg 2y agoThe reproducible build of Telegram lets you evaluate the code doing end-to-end encryption. Once you satisfy yourself it's doing this kind of encryption without implementation-level backdoors, then you don't need to worry about servers reading it (except for #5 above). I didn't claim it encrypted "group chats". I said "things". If you want me to be specific, the "things" are individual 1-1 end-to-end encrypted chats.
- 2y ago
- gospelsod 2y agoThe problem with this approach is that it relies on governments accepting your legal arguments. You can say "no, these are separate legal entities and each one requires a court order from a different country" all you want, but you also need to get the courts themselves to agree to that fact.
- lovethevoid 2y agohttps://www.spiegel.de/netzwelt/apps/telegram-gibt-nutzerdaten-an-das-bundeskriminalamt-a-0e4d3fcb-8081-4b87-b062-db412bbc294b https://www.spiegel.de/netzwelt/apps/telegram-gibt-nutzerdat... > Translated: Contrary to what has been publicly stated so far, the operators of the messenger app Telegram have released user data to the Federal Criminal Police Office (BKA) in several cases. https://torrentfreak.com/telegram-discloses-user-details-of-pirating-users-following-court-order-221130/ https://torrentfreak.com/telegram-discloses-user-details-of-... > Telegram has complied with an order from the High Court in Delhi by sharing user details of copyright-infringing users with rightsholders. Anyways just some examples in which their structure doesn't matter. In the end, user data is still given away. It's also why e2ee should be the sole focus. Everything else is "trust me bro it's safe" levels of security.
- lxgr 2y agoYes: End-to-end encryption is technically quite difficult, but politically and legally feasible (at least currently, at least in most countries). Simply not cooperating with law enforcement is technically moderately difficult, but politically and legally impossible. Between a difficult and an impossible option, the rational decision is to pick the difficult one.
- tigeroil 2y agoIndeed. Even being charitable and assuming that they're not lying (they say elsewhere that they've shared zero bytes with law enforcement, despite this being demonstrably false), in reality if say, they were to arrest the founder in an EU country (France, perhaps), all they need to do is threaten him with twenty years in prison and I'm sure he'll gladly give up the keys from all the different locations they supposedly have.
- yarg 2y agoIs there a nice solution for multiparty (n >= 3) end-to-end encryption?
- dtx1 2y agoHave the room owner create an AES 256 key, send it to all Party members via 1:1 e2ee, encrypt room messages with that AES key.
- kitkat_new 2y agothis is pretty much what Matrix does, if I understand correctly. Additionally the key is regularly updated to provide some degree of perfect forward secrecy and avoid encrypting for people who left the group chat
- foresto 2y ago> this is pretty much what Matrix does, if I understand correctly. I think it has senders encrypt messages with each room member's public key, rather than a single shared key. (At least, that's what the behavior I've seen suggests to me.) Here's the spec, in case you want to comb through it: https://spec.matrix.org/v1.11/client-server-api/#end-to-end-encryption https://spec.matrix.org/v1.11/client-server-api/#end-to-end-...
- mihaaly 2y agoMaybe hijack the key and message before it gets distributed. Or just get after the pieces themselves if they are from Chinese or Russian authorities. Or just threaten to close the local data center if they do not collect the pieces from elsewhere, see if they can be convinced to hand over what they have, regardless where they put it. We can be null in cryptography, but handing over both the secret and the key to this secret to the very same person is quite a trustful step, even when they say 'I promise I will not peek or let others peek, pinky promise!' - with an 'except if we have to or if we change our mind' in the small prints or between the lines.
- Stevvo 2y agoClearly the investigating authorities are not buying that argument because, well, it's completely absurd. Both technically and legally, Telegram are in control of those keys, regardless of where they are hosted.
- deleted 2y ago[deleted]
- maqp 2y ago>To protect the data that is not covered by end-to-end encryption, Telegram uses a distributed infrastructure. Cloud chat data is stored in multiple data centers around the globe that are controlled by different legal entities spread across different jurisdictions. This is utter bullshit I debunked back in 2021. https://security.stackexchange.com/questions/238562/how-does-telegrams-secret-splitting-scheme-work https://security.stackexchange.com/questions/238562/how-does...
- vasco 2y agoIn practice also didn't work, only one government was needed to arrest the guy. And now all they need is a hammer or some pliers. No need for multiple governments to coordinate.
- maqp 2y agoWell I'm sure France isn't taking Durov to some black site at this point. But since there's no such thing as distributed computation of single AES block operation, each server must by definition have access to the server's SQL-database key, and that key can be confiscated from which ever node is interacting with the database. Last I heard the servers in EU were in Netherlands, so if needed, perhaps the authorities there will handle it after court proceedings.
- Vegenoid 2y ago> The relevant decryption keys are split into parts and are never kept in the same place as the data they protect. As a result, several court orders from different jurisdictions are required to force us to give up any data. Or the CEO and owner, staring down the barrel of a very long time in prison, obtains the keys from his employees and provides them to the authorities. Would he do this? To me, it matters little how much I trust someone and believe in their mental fortitude. I could instead rely on mathematical proofs to keep secrets, which have proven to be far better at it than corporations.