Telegram told to give encryption keys to Russian authorities
zdnet.com
zdnet.com
Seriously, disregarding trade-off between security and usability is exactly how we ended up with very secure, 20-digit passwords, containing every possible unicode symbol, updated every Monday, written on post-it notes hanging on the wall.
Pick a threat model and stick to it.
If you're seriously worried about communicating without trusting your phone, then you either need to find communication devices you do trust, or else look into verifiable TRNGs [0], dumb serial printers that can be directly attached to RNGs [1], and either manual encryption/decryption algorithms [2] or one-time pads.
WhatsApp doesn't have a native (or near native Qt app as Telegram does) on anything but phones. No tablets, no desktop OS. This is bad usability.
If I sign in to a new device on Telegram (and it can be nearly any device), I can instantly have my entire message history available. This is what they mean by chat history.
I no longer actively use Telegram, but only because no one else I know could be convinced to use it over Messenger. Messenger solves some of these problems but not all.
I can understand it'd be very annoying when you're affected -- eg having to work in an area with ethernet, but without wifi/3G, or when you need a fallback when the phone is out of battery. For the most part, it's a non-issue for me.
Signal uses the same basic protocol and doesn't require the phone to be online all the time.
Chances are the WhatsApp implementation chose a trade off that minimized confusion for less sophisticated users (within the constraints of maintaining confidentiality). That tends to be a good idea when you've got a billion users.
If I sign in to a new device on Telegram ..., I can instantly have my entire message history available
Including "secret chats"?
Telegram has a lot of users as well. It's a design choice for sure, but I disagree with it and it doesn't work for me personally. Their lack of support for anything but phones is my primary concern though - I could maybe stomach the requirement for my primary device to be online, but simply not making at least an iPad and preferably a macOS app is a no go for me.
> Including "secret chats"?
No, Telegram secret chats are device to device and can't be backed up or transferred. This is also why I rarely used them.
First off, as long as I have any device with chat history online — it is possible for my new device to inherit it as well. It's fine even if I have to confirm manually that session keys are equal or whatever.
Second, note that history can be stored on Telegram servers in encrypted form, I only need to have some secret key that is never sent to Telegram. This way "backing up the history" wouldn't be any different from "sending a message". And being responsible for taking care of my security keys is entirely reasonable.
Third, remember that primary Telegram credential is your phone number — something I abhor, but as long as this is true, I do need to have my phone to log-in on a new device anyway. By the way, I never tried to see if it actually works, but I would rather not being able to access my history after losing my device at all, rather than accepting that anyone who will get in possession of my phone number will be able to read all my chats. "My phone number" is not "me", for fuck's sake. (Yes, I know about 2-step auth, but we are talking about defaults here.)
And, honestly, I guess I would be fine with anything more or less usable, all I really have to know is that "normal people" do use WhatsApp and do find its usability ok. This means they would accept secure chats by default in Telegram as well. How long is it since you lost all your devices that can host Telegram at the same time, anyway? It is rarely the case that anyone's I know devices are all off at the same time, let alone lost.
Wire [1] already has both end-to-end encryption and cross device sync. It's not the only one to do that either.
It's not a tradeoff.
I only wish it had a better desktop client, the current one is a little laggy especially when scrolling up chat history.
Does Wire have a light-weight and solid desktop client yet?
Personally, I'm rather unhappy that Signal isn't federated, and they don't allow third-party apps to use their server.
Finally, the Signal app isn't compatible with my phone. Conversations (XMPP+OMEMO) and older versions of Riot.im (MAtrix) are available to me.
https://github.com/vector-im/riot-android/blob/d0cc1053fe7f7...
i.e. Riot/Android requires minimum SDK version of 16 (i.e. Android 4.1).
Signal doesn't have a native (or even near-native) desktop app for macOS and Windows nor does it support my iPad. For an app I rely on as much as my messaging software it must be available and high quality on every platform I commonly use. Signal's desktop app is poor compared to the extremely polished Telegram macOS app and the nearly as well made Telegram Windows/Linux/macOS app. Admittedly Messenger doesn't have a very good Windows app but in my opinion it is still better than Signal's, while it completely lacks a macOS app which is a bummer.
The Signal iOS app has no way for me to back up my messages, and I understand they are not backed up on Signal's servers. This means if I lose my phone I will lose all my messages. On IM services such as Facebook Messenger and Telegram this is a non-issue for non-E2E chats. I realize this is considered a feature for many, but for me it is a strong anti-feature.
And finally yet most importantly - practically no one I know uses Signal. Even the 5 or 6 contacts it found haven't even set profile photos nor did they reply to a test message I sent - it's likely they've uninstalled it from their phone. Everyone I routinely interact with save maybe two people are on Facebook Messenger or at least visit Facebook.com eventually.
edit: grammar and expanded responses
I have a few people I chat with that I'd prefer the conversations not be generally available. There's little friction to installing whatever apps we need to get that done.
We want confidentiality, but not inability to do what we want with our own data - as you say, the inability to sync or backup messages is a strong anti-feature. I'm regularly screwing around with software on my phone and don't want to lose all my messages every time I screw around a little too far.
It's okay to tie accounts to phone numbers, but the app shouldn't require (or be an asshole about not allowing) access to things like phone books, SMS, etc. (This is what initially turned me off of Signal.)
Security issues and all, my figuring with Telegram is that at least if anyone it's the Russian government collecting information on me this time instead of the US, China, Google, etc. I'm uninteresting enough that simply spreading it around a little should help in avoiding anyone learning too much about me.
Better to not have to trust the intentions (or ability to resist torture, etc) of Telegram, Pavel Durov, et al. Better to have end-to-end encryption by default, like in Signal.
https://www.techdirt.com/articles/20131002/17443624734/lavab...
They couldn’t give up the actual storage keys because they weren’t stored. The courts wanted Lavabit to implement a mechanism to capture the keys during use, which they didn’t do.
Signal is more secure in general due to end-to-end encryption but user experience is bad. I would use Signal when I really have something to fear very seriously, in this case personal security more important than usability.
Telegram is much better made UX-wise. It's a more decent product for average user. It's a Facebook Messenger alternative which is secure enough and doesn't sell your data to anyone.
If you are not security expert or journalist and black helicopters are not chaising you, you don't need Signal, Telegram is much better messenger with great clients on different platforms.
Perhaps the difference here is that Russia does not have access to this data?
Does it apply to all mobile operators or only to american ones?
IIRC, these debugging tools exist on all carriers and each have their own custom implementations.
You are bringing up a good but different point, which is that the application environment on a mobile device may not be protecting you from certain privacy violations. I'm no fan of Telegram, but that's not really within their control.
Put another way, if unbeknownst to Telegram someone had installed a keylogger on my device, would you consider that to be broken end-to-end encryption?
If my conversations are not e2e encrypted this makes the probability of someone reading my messages really high, and makes it reasonably easy for a state-level actor to do so even without targeting me specifically. This makes Telegram not secure, end of discussion.
If my messenger uses unbreakable e2e encryption w/o back doors, but also somehow requires running it on a device, that is known to have some kind backdoor that sends all my conversations to the 3rd party in some other way — it is not secure as well.
Now, I don't know if allegations of everything happening on my phone being monitored by MNO are true. But if they are, this means every messenger that requires you to have a phone number is not secure. And I mean "roughly equally insecure", because the probability of a breach is high, and not a philosophical "nothing is really secure" here.
All WhatsApp, Telegram, Signal and Viber (something I forgot?), REQUIRE you to have a phone number and use the messenger on a phone. There's no choice. So if OPs implication is any true, it makes him really on point with his remark, and makes all the messengers in question about equally (totally) insecure.
> Meet Telegram, A Secure Messaging App From The Founders Of VK, Russia’s Largest Social Network
Really? Source? I thought they were based in NYC?
Well, there goes any interest I ever had in using Telegram.
That's part of why I trust it enough to use it (at least for some of my communication. )
Only because of the public backlash against the local government last time they were known to have poisoned someone in the same country without consequences.
> kidnapping or murdering people outside of Russia would be an act of war
It would, but that hasn't stopped them before.
Do they cooperate?
[111] http://news.softpedia.com/news/russia-wants-encryption-backd...
There are public reports[1] that they are refusing to comply with similar requests eg in the UK.
[1] who knows what goes on behind closed doors... https://news.sky.com/story/whatsapp-denies-government-access...
Telegram as usually refuses to give encryption keys to anyone.
While there seems to be a lot to say about Telegram crypto at least their priorities seems to be aligned with mine unlike WhatsApp that is owned by Facebook.
I could switch to Signal today but I'd be talking to myself only.
Telegram just happen to be what my friends and family standardized on after WhatsApp failed on their stated mission.
• find accounts on the device
• read your own contact card
• modify your own contact card
• read calendar events plus confidential information
• add or modify calendar events and send email to guests without owners' knowledge
• find accounts on the device
• read your contacts
• modify your contacts
• approximate location (network-based)
• precise location (GPS and network-based)
• read your text messages (SMS or MMS)
• receive text messages (MMS)
• receive text messages (SMS)
• send SMS messages
• edit your text messages (SMS or MMS)
• directly call phone numbers
• reroute outgoing calls
• read call log
• read phone status and identity
• read the contents of your USB storage
• modify or delete the contents of your USB storage
• take pictures and videos
• record audio
• view Wi-Fi connections
• read phone status and identity
• send WAP-PUSH-received broadcast
• receive data from internet
• view network connections
• create accounts and set passwords
• pair with Bluetooth devices
• send sticky broadcast
• change network connectivity
• connect and disconnect from Wi-Fi
• disable your screen lock
• full network access
• change your audio settings
• read sync settings
• run at startup
• set wallpaper
• use accounts on the device
• control vibration
• prevent device from sleeping
• toggle sync on and off
Signal just became broken/a pain in the ass. It's been a while, I just know I couldn't actually get to a point where I could send someone a message without granting it unnecessary permissions so I gave up and uninstalled it.
WhatsApp is NOT any different. They may have Signal's encryption algo, but they still store effectively unencrypted messages in their servers. Because that is the only way to sync between devices when adding a new device. And also the only way for FB to data mine.
So... Yeah bad reporting.
They store undelivered, encrypted messages on the server.
> This document describes the Sesame algorithm for managing message encryption sessions in an asynchronous and multi-device setting.
But if you are doing regular messages between people, those messages are certainly readable by the server and because adding a new device decrypts all previous messages, the server has decryption knowledge.
Note: At each point in their sesame algorithm the user has a non-empty set of devices. So if you want to sync another device acts as a p2p syncer.
What happens when you remove your last device and add another new one. Hence why whatsapp has a non-privacy mode. Or am I misunderstanding?
If you switch devices, other clients will use the old keys until they have received the new one (and then they will silently re-encrypt and resend undelivered messages, something WhatsApp was heavily criticized for).