Telegram removed from the App Store for 'inappropriate content'
theverge.com
theverge.com
Why is Telegram X issued by "Telegram Messenger LLP" while the original Telegram is issued by "Telegram LLC"?
Telegram LLC, which issues the original Telegram app on the App Store has been undergoing litigation with regards to its ownership. It is based out of Russia and a company called UCP with Krelim ties who 'bought' VKontakte has been suing Durov for full Telegram ownership pursuant to VKontakte 'purchase'.
Telegram Messenger LLP however is based in London and seemingly wholly owned by Durov crew. In 2014, Telegram Messenger LLP launched Telegram HD, a separate app from Telegram-LLC-issued-Telegram. Now it is launching Telegram X , another separate app (which was until very recently Challegram, an open source Telegram client, winner of Telegram contest, and purchased by Durov) .
Draw your own conclusions.
EDITED for clarity and details
https://themoscowtimes.com/articles/the-telegram-lawsuits-ex...
http://www.ewdn.com/2014/07/29/pavel-durov-has-cloned-telegr...
https://rusletter.com/articles/ucp_requires_to_recognize_tel...
http://www.frandroid.com/android/applications/securite-appli...
Yesterday Facebook took down all crypto-gambling adverts. There is a duty of care to not be the company responsible for making your customers crypto bag-holders. The gig is up with crypto in its current scam incarnation.
Are you saying that Facebook is responsible to make decisions for us - because all it takes is one advertisement to override the average human's discipline and self control?
The advertisements are just what they sell. As the platform owners, they can do a lot more in terms of information curation.
Facebook taking down cryptocurrency gambling ads is much different than Apple removing a general purpose instant messenger. You're finding a connection you want to find, I'm guessing based on your knowledge of PnD groups being on Telegram, that being your sole exposure to Telegram, and your opinion on cryptocurrency.
Apple is very conservative with adult content which I consider the far more likely reason, be that buggy image search, some kind of trending view that porn snuck into, that kind of thing.
It's just not worth it financially for Apple to assume that liability.
Think about what you're suggesting.
Telegram isn't even responsible for what people send using their service as long as they take reasonable steps towards stopping abuse. Apple has no liability here at all.
Apple got sued for encryption-related reasons. In theory these types of lawsuit don't stop after one time.
Anytime you submit an app to the App Store you have to check a box that asks if you're complying with all necessary encryption export laws. In theory, those laws could change in the future and they just simply won't let you publish apps using strong encryption.
Y'all are right, there a probably very could counterarguments to that, but I don't think that makes Apple potentially any less liable.
Wait, how does that work?
What next, automatic voice censorship? That's technically feasible now.
Anyway, I don't see anything wrong with it, to each their own. I was just offering a thought about why Apple might censor the app.
Anyway, all I ever see are the "trending" ones in the app's interface. I wouldn't know where to look beyond that (and I don't use them so I don't care to look for them anyway).
Yes. The manual from 1984 is being followed in an uncanny fashion.
There is more to it. Using apps instead of websites we're killing the whole concept of making information and services available using a standard protocol. That's like going back over 30 years, even before gopher. Then there is the cloud->mainframe similarity, with data and services being moved somewhere into the net where the user has no control over his/her own data, and the whole email/usenet->social media migration which puts private and public communications in the hands of corporations having no intention of guaranteeing interoperability with competing systems.
Basically the industry screwed 40+ years of IT development, not just in a technical way, but they did it behind shiny graphics and animated emoticons, so nobody really cares.
I think the interesting thing to note here is that for most end users a standard protocol is not nearly as appealing as a standard user interface. Like how most iOS apps follow common navigation paradigms, so users don't need to spend time learning each new one. And how people tend to prefer buying things on Amazon instead of any random webshop. And how WeChat has almost become a little web of its own with custom chat UIs for e.g. ordering pizza. If open software for consumers is ever to stop being beaten by these walled gardens, it needs to get a ton more UX people involved and focus on the end user UX, not just the technical implementation.
I'm not saying the App Store is perfect, not by a country mile is it. I'm just saying if you compare it to the Play store, and the wider Internet, holy moly do walled gardens look nice.
That is very true too. I often wondered what would have happened had someone created say 10 years ago an email client with strict protocol compatibility but employing an higher abstraction layer where discussions/attaches are managed automatically just like in a Whatsapp chat (chat -> mail list) using a similar UI. Probably most users would have rejected the idea because they had no intention to learn a new thing nobody was using. So, back to square one.
(1) Load AOL and visit keyword "UBER" to get started requesting a car now!
(2) Type UBER into your web browser location bar then hit control-enter to visit http://UBER.com/ and get started requesting a car now!
(3) Load your app store and search for "UBER" to get started requesting a car now!
Compared to a website, where you get to keep 100% of zero?
Users will pay for apps (not much, as a rule, but something), but will not pay for web sites. Third-party advertisers might pay, if you're lucky, and if you don't mind treating your users as a commodity, but the users themselves will not.
Subscriptions to web-based services don't count as paying for web sites?
In the end reality is that I just pass on buying subscriptions and would probably prefer buying subscriber access to a website if they made an app facade for the site that handled payment and login. The UX of web sites and subscriptions is that bad.
Those are only 3 examples a ton of people pay for.
If you provide a good service, you will get subscribers. News have been available for free for decades thanks to OTA TV broadcasts. That's why people don't pay for it.
Niche journalism needs to have subscriptions since they can have way less views and people looking for news on that niche are ready to pay.
Would you pay a subscription for Flappy Bird?
I don't do that on the app store either.
And software was sold way before app stores existed, so what's your point?
I refuse to pay monthly for stuff that shouldn't need backend services.
There are somewhere over a billion web sites, dude. The number of those that are profitable with a subscription model (as opposed to being supported by advertising, or not being profitable at all) is a rounding error -- in the fourth or fifth decimal place.
Love to be able to pay for quality content.
Same with Spotify.
Both models are OK with me.
What I don't wanna pay for is every newspaper wanting a monthly subscribtion either I read something or not.
Content/news is a terrible example since there is an oversupply of poor quality content driven by providers who believe content supports their advertising revenue rather than the other way round.
Not a great example.
There's more to the Internet than websites. Believe it or not, there are lots of protocols out there, not just HTTP.
But ya figure for a large company of creative geniuses they could figure out how to democratize security so that the whole system isn't wholly owned and controlled by a single entity.
That makes even less sense.
Really?
https://play.google.com/intl/en_us/about/developer-distribut...
> (4.5) Alternative Stores. You may not use Google Play to distribute or make available any Product which has a purpose that facilitates the distribution of software applications and games for use on Android devices outside of Google Play.
You have no chance of bootstrapping an alternative store outside of Google Play. Sideloading APKs is not how users get software on Android. Amazon failed hard with their attempt, and they pumped tons of money into it by paying developers to give away their apps for free; that, and they shipped hardware that has their store preloaded. Still didn't even make a dent.
We are not much better, sadly. https://floens.github.io/Clover/gp_unavailable.txt
Imagine a city where public parks are all bought out by private entities, that is the Internet right now.
We have less and less public space in the digital world and that is not looking good for the future of democracy.
Apple could keep the default to what it is on the iPhone right now, but should at least allow signed apps from other stores as a non-default option, even if they don’t allow unsigned apps at all.
It's always been Apple vs The Rest Of The World.
[1] https://techcrunch.com/2017/10/24/apples-app-of-the-day-feat...
Getting featured on the App Store is one time, possibly incredibly beneficial, event, but it is not a marketing plan.
As you point out, there are alternatives. Why do you think developers have massively and overwhelmingly opted-in?
Are there? Really? No, they're not. No one who isn't in tech is going to install F-droid. Few people will uninstall untrusted sources, or even know what that is. Fewer Apple users than ever jailbreak their phones.
For over 90% of the market, no, there are no alternatives (other than a mobile website). Due to the non-standard nature of ARM and SoC/binary drivers, we don't even have a real alternative OS for old Android devices that's universal like most Linux distros on the PC in the 90s (although PostmarketOS is making some huge strides in this area).
30% is an insane cut. Bandcamp sells music with a 15% cut, literally half of Amazon/Google/Apple. I always prefer it because I know the band gets more money and I get a higher quality version of the song without a patent encumbered codec (FLAC and OGG downloads are supported).
But no, there are no real alternatives. AppStore/Play are bastardizations of the software repo concept from Linux.
If Google Play was a real package managers, it'd keep standardize shared jar files across apps (dependencies to reduce massive app size) either by mirroring maven repos and signing dependencies or creating their own system, and they'd also allow for easily adding 3rd party app trees.
Both Apple and Google are closed walled gardens, where everything you need has to be contained in your bloated package, and where their corporate overlords get final approval of what is in and out.
After all, there are alternatives to bridges, why do the travelers opt to pay the fee?
-- Obviously, /s
Talking about my own experience, once we've made clear that In-App Purchase wasn't a fit for us as we already had our own payment system (we are a SaaS business), things got way more difficult to us. As you can imagine (but I didn't at the time), our app would be in review for weeks sometimes, we started to see arbitrary denials and a lot of "issues" not present on their guidelines started to be identified on our apps.
If there is one thing that I'm now sure is that, if you decide to not play their game (even though following their rules) there will be retaliation.
Not if you want to build a secure system which runs on an iPhone, there aren't. JavaScript crypto is fundamentally insecure; the only secure option is a native client.
I mean, it's awesome.
Pictures from birthdays and everyday life to aunts/uncles and grandparents etc.
Many also use it for social/professional groups (again many-to-many) where it offers simplicity but also includes moderation features in "supergroups" that can have up to 100 000 users.
Lately I've also joined a few channels. Channels are one-to-many (or rather: one or a few-to-many)
As for why Telegram it is super easy to use, it seems well aligned with my interests in that it's owner already lost his previous company to authorities and seems obsessed with preventing that from happening again.
That said: if your life or professional life depends on strong crypto I'd think twice or more as certain bright and leading cryptographers seems to distrust/hate it.
(Anyone who needs that should think carefully anyways but Signal seems to be a good option that is also aligned with the users interests.
WhatsApp is often recommended as well and they also seem to have solid crypto but I actively avoid them as they've broken too many promises already and also has a owner that is not aligned with my interests.)
Telegram is a messaging app with group chat you can join and others where you're invited to. And bots of varying utility.
depressed bear image
RHIZOME
It's pretty handy, and how deep you go is up to you.
> Telegram has risen in popularity thanks to its focus on advanced security features and the ability to hold secret conversations with end-to-end encryption.
Isn't this wrong? I thought Telegram was famous for decrypting messages in transit.
But it's a still valuable privacy-oriented app.
Sorry, what? Can you show me where Signal has been implicated in flaws? There are some stories about security agencies bypassing Signal, but that is true on any hardware platform you didn't wire-wrap yourself.
I was referring to the recently re-discovered paper about group chats (e.g. https://www.helpnetsecurity.com/2018/01/11/whatsapp-signal-g... paper here: https://eprint.iacr.org/2017/713.pdf)
Sounds like making a mountain out of a molehill.
https://conversations.im/omemo/audit.pdf
Tells you everything you want to know about Signal. Or read the secushare comparison page:
http://secushare.org/comparison
Here, some choice quotes from the OMEMO audit that pertain to the Signal protocol:
"Metadata
The protocol leaks metadata about who is communicating with whom and how much they are communicating. Alice’s request for the server cache leaks to the server that she wants to start a conversation with Bob, as does the PreKeySignalMessage. The plaintext message counters that are included in each SignalMessage make it possible to track the rest of the conversation. Unlike the ratchet used in the Signal Protocol, the regular variant of the Double Ratchet [24] also encrypts the message headers, which would make it possible to avoid tracking of the conversation. It would only make sense to implement this if this information is not leaked already in the transport layer."
"Message authentication
Messages are authenticated by the randomized key, which protects the message integrity from outsiders. However, anyone with access to the key can alter the message, which includes a malicious device. There are a few possible mitigations, each with their advantages and disadvantages. A possible solution would be to authenticate inside the Signal session. By authenticating the payload with the tag of the SignalMessage, the full message is authenticated in such a way that no other device can compromise the integrity. The ciphertext (and not the plaintext) of the payload message should be authenticated, so that the MAC-then-encrypt pattern is applied.8 This solution increases the computational load on the sender side, because the payload needs to be authenticated more than once. When the ciphertext is added as authenticated additional data (AAD) of the Signal message, it would reduce the message size slightly, because no authentication tag is required on the payload. The payload encryption method should then be simplified to a non-authenticated block cipher mode. It will also require some alterations on the Signal library, as the current implementation does not allow the library user to add their own AAD. The payload can also be authenticated by including a hash of the payload ciphertext in the SignalMessage plaintext (and therefore the corresponding encrypted hash in the SignalMessage ciphertext). This would not require changes to the Signal library, but it would increase the size of each <key/> element. This solution is less elegant than the previous, as the hash of the payload ciphertext is sent encrypted, even though the recipient can compute this value themselves. By authenticating a list of all recipient device ids in the tag of the SignalMessage, Bob has a guarantee about which devices Alice has sent the message to. Bob’s client might provide him with a warning if that list includes untrusted devices. This protects him against the specific attack described above, but the protocol remains vulnerable if one of the devices gets compromised by another attack. This solution can be combined with the above solution of authenticating the payload ciphertext with the SignalMessage ciphertext or tag."
"Device linkage
There is no cryptographic link between identities and device keys. In other words, Eve can attach her own device identity key as if it is a resource belonging to Bob and fool Alice into adding it. There is a solution: each device could sign a certificate on each device identity key of the same user. While Eve might fool Alice into thinking that Bob has another device, it is highly unlikely that Bob is tricked into accepting another device as his own. Device identity keys with a certificates that was signed by an already accepted device of the same user could be accepted automatically. In order to account for compromised devices, users must have the ability to revoke certificates and certificates should have a finite lifetime. This solution can be extended into a full-blown public key infrastructure (PKI) or web of trust, but I recommend to keep that out of the scope of the OMEMO specification (although compatibility with such systems could be taken into account when updating the OMEMO specification)."
Granted, most of these come down to issues solvable in UX - but Signal doesn't. And the deceptive UX like the disappearing messages (which, for obvious reasons, can't expire on the server and get synced [and subsequently deleted from the client] until the last device has it), because the Signal developers only consider it a "convenience feature" (a fact which they offhandedly communicated in their blog, but think about it, how many users actually read that?), the whole phone number binding, and... Ugh. Just ugh. I don't wanna continue because Signal nauseates me. It's not that it's bad, it's not, but that doesn't mean it doesn't suck.
This is why I will never buy an iPhone (though I don't mind a MacBook as long as root access and legal ways to install Linux have not been locked on them yet) - I want to use the device the way I want, have full control over its filesystem, run the apps I want without all that store bullshit (which hits even harder if you live outside the USA by the way, in synergy with your local government bullshit and with what corporations think about your region market) and decide what is appropriate for me myself.
Today Apple is a fascist organization. Historical fascists did fairly good in eye-candy design and hardware quality too but that's the only good part of them and it's pretty much ruined by so much crazy fascist bullshit to tolerate in exchange.