Apple and Russia Face Off Over Telegram on App Store
bbc.com
bbc.com
Not even that: for the 2% who want to install software that hasn't annoyed {Apple, the local government}.
As a result of what? And this is between Russia/USA which has nothing to do with GDPR.
And moreover, company has to be GDPR compliant and not an app. An app may include stuff that helps to be GDPR compliant, but is only a subset of what is required to be compliant.
"as a result, we’ve also been unable to fully comply with GDPR for our EU-users by the deadline of May 25, 2018. We are continuing our efforts to resolve the situation and will keep you updated."
By the way legally Telegram is not a russian company (British company if I remember correctly) so Apple cannot get away with "who cares, they are from Russia". Is it ok that at Russian government's request American company is restricting a British company?
I don't care what you say. I don't believe for a second that vault 7 is an exploit and not a built in backdoor.
[0]:https://www.apple.com/customer-letter/ [1]:https://wikileaks.org/ciav7p1/
EDIT - this is going to get downvoted to oblivion cause it goes against the grain but it is an opinion and people should at least be open to it. Especially with the fact that news[2] like this is coming out everyday.
I can't believe for a second that the government can merely send a magic packet to an iphone and have it exploited as it does. It must a built in backdoor they can only access or else alot of other people would have it as well.
putting aside hubris, take a look through eff.org and see for yourself. If you care enough about privacy and the future, take a look at fightforthefuture.org to see which candidates are funding these programs and the ones who are actively fighting the surveillance state.
I’d love to see any credible explanation as to how this could have happened by accident.
He found a flaw, they fixed it. The flaw itself is of a kind common to a home-brewed crypto and it was lying on a surface. Saying that Telegram made this mistake on purpose is, if you pardon my French, making shit up.
Yes, they fixed it.
No, you can’t accidentally write code that pulls DH nonces from your server.
>The flaw itself is of a kind common to a home-brewed crypto
You can’t say things like this and then proceed to accuse others of making up shit.
Telegram doesn't have reproducible builds, do they? So if they really wanted to fuck people over, all they had to do is to ship a build that uses predictable PRNG. The vast majority of users will use vendor-supplied binaries, so chances are that for any pair of peers you will be able to fully recover all their secrets and eavesdrop on the traffic. You don't even have to be Telegram to do that. In fact, this works against any protocol... unless client binaries are routinely audited and matched against their source, which is never the case with any of the clients. The only example I am aware of was Zimmerman's PGPfone back in mid-90s.
So, yes, I think that you are seeing things that are not there and it's yet another case of stupidity rather than malice on part of Telegram's devs.
This doesn't really matter that much, the source code isn't very helpful while auditing a RNG.
Most of the time Telegram doesn't even encrypt conversations, yet this is their main selling point.
>So, yes, I think that you are seeing things that are not there and it's yet another case of stupidity rather than malice on part of Telegram's devs.
No. I just don't think it matters whether this was stupidity or malice, sufficiently advanced stupidity is indistinguishable from malice. This was not your typical crypto fail. You suggested that this is a common kind of error, can you point at someone else that did this?
I think it's fair to assume malice in the case of Telegram, their "secure encrypted messaging" application still doesn't even encrypt most conversations.
Regarding the nonce attack, it looks like the devs responded and said it was because of poor random numbers source on the client, which I personally don't understand as a justification. However, they said they'll remove it in the next update and that nonce has been "0" up until now.
Regardless, all of these messengers for cell phones aren't great if you are paranoid. That's because the hosting company's servers have all kinds of data on you as it is. Your contacts, access to SMS, access to location, camera, mic, photos, and all the files on the device.
This is true for all the messengers that are currently in widespread use.
If you are paranoid, use Pidgin with OTR plugin.
Don't do that, this is a super bad idea. If you really have to go that way, at least use coyim or something. Definitely not anything libpurple based.
On the CoyIM site it says: "Not yet audited. Do not use for anything sensitive."
>Because they had a code exec vuln in 2017?
No. Look at the code, it’s scary! Pidgin and libPurple were not built with security in mind.
Coyim is being built ground up in an effort to avoid the numerous issues surrounding Pidgin/libOTR.
I think you absolutely should not use either, but if you’re going to use one at least use Coyim.
A messenger that really cares about privacy would never require user to provide a phone number and would not keep decrypted messages on the server.
I wonder who has anything to gain from this position of Apple outside of Apple itself? No one in their right mind can both know Apple's history and believe they are a bastion of privacy. I'd be surprised if they aren't worse than Facebook.
What history are you referring to?
One of the reasons privacy activism has a hard time getting any traction is because of this all-or-nothing attitude. Apple clearly does more than Google for users’ privacy. But they drop the wall in one case and suddenly they’re “truly as bad as Google.”
All-or-nothing hardball works if one has leverage. (Even then, it is a costly strategy.) If one is in the minority, however, it virtually guarantees being ignored. The world exists in shades of grey.
Perfect is the enemy of good. My point is it’s possible to criticise a company without being (falsely) hyperbolic.
https://www.independent.co.uk/news/world/europe/russia-inter...
> Second what has the coverage of this been like in the local media?
All major media in Russia are controlled by the government. They reported that Telegram is used by terrorists and drug dealers and Durov refused to comply with russian law and provide decryption keys that are needed for the invesigation (Durov says that accounts in question are long deactivated and that he was required to provide keys allowing to decrypt the traffic of any user, and that those terrorists used WhatsApp as well).
Putin's advisor on Internet development also suggested that russian users can switch to messengers made by russian companies.
There also was a small rally in Moscow against internet censorship. Only about 12000 people from 12-million city took part in it.
>"Yes, it times out. If a site uses HTTP, there can be a notification about it being blocked, for HTTPS sites it is not possible."
Why wouldn't it be possible to get a notification for HTTPs though since the domain part of the URL is still unencrypted? How does manipulating the packet size help steer around the blocking?
Also I am curious what the media coverage has been regarding the state HTTP filtering?
Because you need a valid certificate to break SSL connection.
> How does manipulating the packet size help steer around the blocking?
The filtering hardware looks for SNI field at specific offset. If you break packet into two it will let the packet through because it doesn't reassemble IP packets (probably because it would require more resources).
> what the media coverage has been regarding the state HTTP filtering?
When the law was discussed initially, I think somewhere around 2012, after large protests against falsifying parlament election results and Putin's third term, media explained that there is many illegal information on the net, for example, terrorists' sites, sites selling drugs, sites that promote homosexual relations or suicide among minors. So the government needs a law to protect children from this. Sometimes they also add that some western countries censor Internet access too.
Several years later new causes to block sites were added, such as sites with pirated movies, casino sites, sites that allow to view blocked content or provide VPN services, or pages that call for an unauthorized rallies.
It is somewhat ironical that when Ukraine blocked russian social networks, media explained how to bypass the block.
Irritating, yes, but his regime does have a fair collection of dark events. I struggle to think of a current world leader in the same league.
Russia wants to ban Telegram, the reasons are their own (not providing CALEA-like access to communication network proven to be used by terrorists is a biggie). They do not have any mean to block just Telegram in the Apple Appstore, but they do have the means to block entire Appstore. Anyone would go for minimal impact: ask Apple to cooperate; if they do, fine. If they don't, pull the nearest gun that achieves the result.
Whenther some random Ivan uses iPhone or not, nobody really cares.
They might stall for a time, but they'll end up blocking Telegram in Russia as well. And other apps will follow.