Russia’s move to block Telegram another attack on online freedom of expression
amnesty.org
amnesty.org
Wondering if whatsapp is unblocked because it already is sharing users' information?
The real reason is more simple: it's mostly used by the small middle class, people working in tech and business. The current laws in Russia were used to block LinkedIn, but they didn't touch Facebook or Twitter — that would be too much.
Considering Facebook owns WhatsApp this isn't surprising, they're definitely happy to share this information (ever seen someone in your FB "suggested friends" list after messaging them on WA?)
If they had pushed a different version of the app to Russia or there was a way of breaking message encryption I'm sure someone would have noticed by now.
[1] https://www.heise.de/mac-and-i/meldung/Entwickler-Facebook-k...
Corporate statements about the security and privacy of their products usually leave open the possibility that they engage in lawful intercept. Even if they don't they can always just lie and use the fact that they have national security letters barring disclosure as legal cover if it ever comes out.
https://www.theguardian.com/technology/2017/jan/13/whatsapp-...
If you're a user of WhatsApp, make sure you enable the two-factor authentication PIN, too, because otherwise it should be relatively trivial for your own government to gain access to your account by using your number with the local carrier's help (it's also possible to do it without the carrier's help, given how broken the security of carrier networks is). Many Telegram users were hacked this way by the government in Russia, too.
Only concern could be the file size, but Orbot is only 12MB for example.
It will also greatly increase popularity of the messenger.
Blocking Telegram helps Russian intelligence operations by making it appear like as if the Russian government did not have access to the vast majority of conversations over Telegram.
> The power that local governments have over IT corporations is based on money. At any given moment, a government can crash their stocks by threatening to block revenue streams from its markets and thus force these companies to do strange things (remember how last year Apple moved iCloud servers to China).
At Telegram, we have the luxury of not caring about revenue streams or ad sales. Privacy is not for sale, and human rights should not be compromised out of fear or greed.
Remember Telegram recently raised a whopping $1.7 billion from a coin offering. It's also the reason I've been begging Signal to do something similar for over a year now. Cryptocurrencies can provide the liquidity open source projects need, and it can also help them stand against oppressive governments.
https://www.bloomberg.com/news/articles/2018-03-30/telegram-...
Aren't they in the process of doing that with MobileCoin[0]?
I know the whitepaper is pretty sparse on information, but according to the last paragraph in the whitepaper[1], it's designed to integrate with IM platforms, and, according to the only tweet from their Twitter profile[2], there is no ICO at the time.
[0] https://www.mobilecoin.com/
[1] https://www.mobilecoin.com/whitepaper-en.pdf
[2] https://twitter.com/mobilecoinone/status/960359924562739200
>The Russian government has started to block messaging app Telegram, according to reports from the local news agency Tass.
>Russia's media regulator had sought to block the app because the firm has refused to hand over encryption keys used to scramble messages.
>Telegram had missed a deadline of 4 April to hand over the keys.
As the proverb goes: “Undue strictness of Russian laws was always compensated by it being optional to follow them.”
Rules should be valid for all and applied uniformly.
I believe it turns the biases of individual enforcement officers into society-wide inequalities. E.g. white kid with marijuana gets a stern warning while black kid gets his freedom taken away. Instead, the enforcement officers should be obligated to charge both with crimes due to the rule of law.
Telegram is also exceptionally popular here, so I have trouble believing it will stick or do anything in the first place.
It could take years to trully cover all ISPs. Like it was with rutracker.
And then LinkedIn is blocked for a long time now but I get new job opportunities through it quite often. Sometimes w/o turning VPN on.
But yeah - i'll agree the current situation isn't ideal.
[0]: https://matrix.org/docs/guides/faq.html#what-is-the-differen...
Also, modern XMPP is just as modern. With MAM, stream management, message carbons and some other smaller XEPs it just feels like a modern, mobile-friendly IM network.
Go slightly south, there is other country that blocked Telegram long ago without notify anybody.
There's always the possibility your own country could request the same thing and act as a proxy.
Russia blocks Telegram while the US splits cables and installs snooping devices between data-centers, use secret courts, monitors everyone, etc. Why do we pretend Russia is such a problem when a lot worse stuff happens closer at home every single day?
Normally that should be enough. Let me elaborate, though. First, there's extremely little chance of uncovering any "terrorists" or any major criminals by investigating the extant chats: competent lawbreakers delete incriminating messages as soon as possible or communicate in secure chats to begin with, and would do so especially if Telegram showed signs of cooperating with FSB. There would, however, be a guaranteed influx of falsely accused. VK is a good example: there are cases when people are incriminated for inciting hatred because of something like a closed album with Nazi caricature memes, on the grounds that "everything on VK is public"; there were multiple trials for reposted messages. And so on. Most of this is simply due to some random asshat spook trying to furter his career by hauling in a lot of "extremists" and surpassing average "productivity". This is both inhumane and not economical.
More importantly, encryption is not analogous to guns because guns are hard to manufacture and even harder to conceal, but software is different. You can easily create your own encrypted messenger and nullify whatever efforts the government is putting in suppressing current platforms. Signal Protocol is open source, you know. Blocking Telegram would merely speed up the transfer of terrorists to their own networks, and/or increase the popularity of platforms which would not even shut down the channels with terroristic propaganda (something Durov actually does).
There is no replacement to actual investigation, to fieldwork, to international cooperation, to training of competent agents and infiltrators. This is hard and risky, it's so much more easy to vantonly gather data, threaten average citizens with your overreach and pretend to save the day. Well, let me remind you that Boston bombing did not rely on any sort of encryption. FBI received hints from FSB and interviewed Tamerlan way before the event; Dzhokhar’s Facebook was insanely suspicious. They failed to notice the threat. If the intelligence cannot successfully work with open information like this, what more could they gain from Telegram?
That is __really weird__.
Or scammers. Off cause it's scammers.
Other service called Zello avoided blocks by changing IP addresses on AWS until Russian government gave command to block 13,5M of Amazon IPs [1]. On next day Amazon simply forbid them to change IPs.
[1] https://torrentfreak.com/russia-asked-isps-to-block-13-5-mil...
So, in order to block domain fronting the government would have to pressure a whole bunch of large foreign corporations with CDNs to patch their tech to forbid domain fronting.
And cloud providers and CDNs that have large customers from Russia will just give up like Amazon just did. After all it's just a business for them and they not going to lose clients just to fight against censorship.
As I said before, end-to-end encryption in a centralized app is a joke and is absolutely irrelevant for its threat model. But, whatever, security is a very dirty industry.
Let's go though this again. You still have to trust someone to implement E2E encryption, guarantee said confidentiality and guarantee to keep it with each update pf the app they provide, etc. It's absolutely the same as trusting them to just not spy on you on their servers with client-to-server encryption. And if they are forced to implement a backdoor, it doesn't matter whether they do it on their servers or push an update to a supposedly secure app.
Everyone would eventually spy on you on their server. Either by voluntary choice or being forced by some government entity. In this day and age it doesn't even make sense to discuss any hypothetical situations where they are not collecting (all of) your data.
> And if they are forced to implement a backdoor, it doesn't matter whether they do it on their servers or push an update to a supposedly secure app.
One of this things is not like the other. Remember, Signal-style e2e encryption isn't concerned with individual safety that much, it's main aim is the governmental mass surveillance. Server side data collection is, obviously, completely transparent for the end user. Client side backdoor would be quite inconvenient on that scale: the more it's used, the higher would be the chance of discovery. Thus, presumably, it would be used less frivolously.
Every centralized app preserves an ability to eventually spy on you. End-to-end encryption doesn't take it away.
If a government wants mass surveillance it either asks/coerces someone from the company to implement a backdoor or blocks the app in the country pushing people into mass surveillance friendly alternatives. So end-to-end encryption cannot possibly protect from mass surveillance.
Client side backdoors obviously don't need to be pure client side either, only revert back from end-to-end encryption to client-to-server encryption preserving plausible deniability for the company. Possibly even leaving end-to-end encryption in the app, just not enabled by default. Such change can even be advertised as an improvement, like cross device chat history feature or something.
Never said anything like that.
> If a government wants mass surveillance it either asks/coerces someone from the company to implement a backdoor or blocks the app in the country pushing people into mass surveillance friendly alternatives.
Yes.
> So end-to-end encryption cannot possibly protect from mass surveillance.
Are you arguing for mass surveillance friendly software? Decentralized software? What are you arguing? I'm completely lost there.
It’s not the first time Russia pretends to fuck over the Durovs.
Durovs have spent years pretending to live in exile from Russia, despite regularly spending time in the country.
What exactly sounds like a conspiracy theory?
https://twitter.com/ChristopherJM/status/910186197598838784 https://twitter.com/Bershidsky/status/910169626989953024
The theory that Telegram isn't controlled by Kremlin sounds far less credible to me.
Could you elaborate on this please? Are you just referring to the fact that the default settings don't enforce encryption or is there more to it?
In this scenario, while the encryption has never been broken, it is theoretically possible that the creators designed the encryption in such a way that knowing certain values would allow you to decrypt the communication.
This essentially allows the people that know the "secret" to be able to crack the communication, while the users remain under the impression that everything is private.
He's further suggesting that this "move to block telegram" is a stunt to try and promote the idea that their encryption is not currently breakable (in a bid to foster more adoption of the platform).
While there's no proof of any of this, personally I feel it's still within the range of plausibility, and raises further questions about why they would target only telegram and not other encrypted messengers ..
We don't know all of the details but it feels that there is more to this move than what is being presented.
Telegram is marketed as a secure encrypted messenger, but unlike other modern encrypted messaging apps it requires the users to manually begin a "secret chat". Very few Telegram users are actually aware of this fact.
Telegram also makes no attempt to conceal the metadata of the rare encrypted conversations, compared to Signal which goes to significant lengths to ensure that they can't even easily access their users contact lists.
Chats, including group chats, are encrypted, just not end-to-end.
This works the same way as gmail and internet banking, and it means you have to trust Google, your bank or Telegram.
Pretending it is wide open to anyone ("aren't encrypted") is misleading.
AIM, Facebook chat and Windows Live Messenger are all encrypted messengers by that definition.
Few people seems to know much.
> Referring to client-server encryption as encrypted messaging is misleading.
> AIM, Facebook chat and Windows Live Messenger are all encrypted messengers by that definition.
I can partly agree with you on that.
But the way you phrase it, people who don't know better might easily be misled to think it is readable by anyone in between.
There are a few options between cleartext over telnet and the latest in crypto.
So either they're actually doing this because they're scared of the people enabling encryption on this specific platform, or it's a publicity stunt because they already can access the data.
Mostly this. It's not an accident but a deliberate choice.
Their questionable crypto scheme also does not support group chats.
Now WhatsApp could theoretically push a malicious update, but there is no way Signal could even theoretically hand over the encryption keys, because the entire freaking point of their product is for them not to have a copy of those keys.
Since Telegram isn't end-to-end encrypted (outside "secret chats"), they do have a private key that decrypts all the messages, since they only encrypt in transit. Therefore, there is a private key to hand over to the government.
E2E encryption refers to transit encryption. The encryption is between two end devices, rather than decrypted (and re-encrypted) between clients and servers.
It has no bearing on data stored at rest on the end device, and I have no idea what either WhatsApp, Signal or Telegram does to the data at rest.
We are full of this freedom-related bullshit. There is no freedom in the Internet. Currently we share our private information with CIA. We don't like it, but that's OK. Everybody still uses Facebook, Gmail, etc, etc. But when Russian Federal Security Service whats to access user's private data, everybody starts screaming. Shut up already.
https://translate.google.com/translate?sl=ru&tl=en&js=y&prev...
I don't know who you are friends with, but you people are strange.
While all normal people are buying proxies and setting up VPN right now.
You, 'normal people' can buy VPN. But I hope that this will not last too long. We have the China example, we know how strong government should treat VPN freaks.
Does USA have strong government? Why does it force RT, for example? Because strong goverment wants to control its mass media and information in general.
>Only the rulers who are greedy for their personal power turn themselves into living monuments and order to clean the Internet from the memes about them.
There are lots of memes about Putin, for example. Nobody cares. Got visit http://lurkmore.to. Enjoy your silly 'freedom'.
Please do at least a little research next time.
Is that the freedom of speech you, American democrats, are talking about?