7 ms·
IANAL, but I think that this case mostly has merit. Telegram is not end-to-end encrypted by default. So they have access to the conversations in group chats and
by sgjohnson 2y ago
IANAL, but I think that this case mostly has merit. Telegram is not end-to-end encrypted by default. So they have access to the conversations in group chats and non-E2E encrypted DMs.
One of the charges is refusal to provide information when requested by law enforcement. And he is a French citizen, so there might be an explicit obligation to cooperate with law enforcement when requested.
To me it sounds like he’s being done in for not putting E2E encryption on everything.
Whether he should be liable for what others do on his platform is a different matter entirely. But it has merit.
- IncreasePosts 2y ago> And he is a French citizen, so there might be an explicit obligation to cooperate with law enforcement when requested. Seems unlikely. If French law enforcement asked a French citizen working at Microsoft in Washington to exfiltrate some data for an investigation, could they be arrested if they didn't do it?
- j16sdiz 2y agoI don't know French law. but, afaik, the Australia and China can do that to their citizen
- linotype 2y agoAustralia can compel a citizen to break the law in a foreign country?
- loa_in_ 2y agoYes. In fact every country can.
- ronsor 2y agoIn theory, but that might get you prosecuted in the country you currently reside in, which can easily become a political mess for your home country if the reason gets out.
- viraptor 2y agoIt's not theoretical. It spans lots of areas, from trivial food safety (you're forbidden/required to wash eggs depending on the country), to social (can't allow / can't deny education for women), and many others. Countries have explicitly conflicting laws in many cases and effectively force people to break another country's laws.
- mc32 2y agoThe country where it’s done would likely arrest said person for industrial espionage, if not regular espionage, among other things like unauthorized usage of computer systems, etc.
- Scion9066 2y agoLooks like they couldn't order an employee in Washington to do it but could order someone inside France to provide the data: https://academic.oup.com/book/27039/chapter/196319372 https://academic.oup.com/book/27039/chapter/196319372 "The French Code of Criminal Procedure provides that a réquisition ordering access to computer data can permit access to data that is stored in servers outside of France as long as the réquisition involves a terminal that is located in France with authorized access to the relevant data located abroad, and as long as the access is permitted under international law.7 The location of the data itself is irrelevant."
- lxgr 2y ago> To me it sounds like he’s being done in for not putting E2E encryption on everything. That seems fair and indeed completely on Telegram: Having data but not sharing it with law enforcement just doesn't fly pretty much anywhere. What's concerning is that the French authorities seem to have slapped on an "unauthorized import of cryptology" charge on there. It's bizarre to still have such a law on the books in 2024, and even more so to actually enforce it.
- viraptor 2y agoNot "sharing the data" - he's investigated for not acting on it. We can speculate about government control conspiracies etc. but in a more simple scenario - we know telegram is popular for crime and scams and they don't care. Looking further until that part is solved feels weird.
- rpmisms 2y agoI think you're right, but it can also be politically motivated (it obviously is)
- ETH_start 2y agoNo, the reasons given for the arrest in the press release from the prosecutor's office includes the charge of him not getting appropriate permission before implementing E2E. This is an anti-encyption measure, amongst other things. https://www.tribunal-de-paris.justice.fr/sites/default/files/2024-08/2024-08-26%20-%20CP%20TELEGRAM%20.pdf https://www.tribunal-de-paris.justice.fr/sites/default/files... English translation of the last three points: • Providing cryptology services aimed at ensuring confidentiality without certified declaration. • Providing a cryptology tool not solely ensuring authentication or integrity monitoring without prior declaration. • Importing a cryptology tool ensuring authentication or integrity monitoring without prior declaration.
- yorwba 2y agoThese three points are not about not getting permission, but about not declaring the services offered. The difference being that permission can be refused, but a declaration is just a one-sided formality. Other services do require permission, like offering cryptanalysis tools or exporting to non-allied countries. See this info page by the French government: https://cyber.gouv.fr/controle-relatif-un-moyen-de-cryptologie https://cyber.gouv.fr/controle-relatif-un-moyen-de-cryptolog...
- ETH_start 2y agoSo in what way did Telegraph fail to declare the cryptographic services offered? "Certified declaration" implies an authority that certifies it, i.e. approves it, i.e. has to give permission.
- yorwba 2y agoSince the case hasn't yet been adjudicated, I don't know whether or how Telegram failed to provide a certified declaration, but it seems possible that they simply never submitted the form. "Certified declaration" does not imply any authority giving permission, especially not when the original French is "déclaration conforme." You could call it a "declaration fulfilling the legal requirements" instead if you want.
- sagarpatil 2y agoIANAL?
- sgjohnson 2y agoI Am Not A Lawyer
- Scion9066 2y agoNot only do they have access to group chats and non-E2E encrypted DMs, their moderation practices for those are: https://telegram.org/faq https://telegram.org/faq Q: There's illegal content on Telegram. How do I take it down? A: All Telegram chats and group chats are private amongst their participants. We do not process any requests related to them.
- sgjohnson 2y agoIt gets worse. What they are saying is quite openly, "We have the data you're after. Force us to disclose it." > Q: Do you process data requests? Secret chats use end-to-end encryption, thanks to which we don't have any data to disclose. To protect the data that is not covered by end-to-end encryption, Telegram uses a distributed infrastructure. Cloud chat data is stored in multiple data centers around the globe that are controlled by different legal entities spread across different jurisdictions. The relevant decryption keys are split into parts and are never kept in the same place as the data they protect. As a result, several court orders from different jurisdictions are required to force us to give up any data. Thanks to this structure, we can ensure that no single government or block of like-minded countries can intrude on people's privacy and freedom of expression. Telegram can be forced to give up data only if an issue is grave and universal enough to pass the scrutiny of several different legal systems around the world. To this day, we have disclosed 0 bytes of user data to third parties, including governments.