Telegram App Says Apple Is Blocking Updates Over Dispute with Russia
nytimes.com
nytimes.com
Over the last month they seem to have banned apps because some government out there didn't like that app. To make matters worse, those very same governments weren't happy with the app being removed from their regional app store but they demanded it removed from all app stores.
The VPN issue was a wake up call for a lot of developers. These apps were on the app store for years and because China didn't like these apps one morning, they banned it and referred to some arbitrary clause in the app store TOS.
The thing is this script has played out before. Twitter also had a vibrant ecosystem of third party developers. Those developers made Twitter into a billion dollar company. Then one morning, they decided certain classes of apps were not okay. This back and forth went on for months until there were barely any apps left. Twitter eventua
The same thing is happening with Apple. Several founders I've spoken to, all with big exits in the past, refuse to write apps first for Apple or Google because of the threat of getting "banned one morning".
Worse, VCs are now getting nervous in investing in startups where the app is the fundamental foundation of the business.
For any market to thrive, there needs to be transparency and stability. Just like Twitter, once developers are gone....they're gone. They won't come back and consumers will start wondering if the 1,000 dollar smartphone they purchased, with subpar apps, is really worth it.
Purism's Librem 5 phone is funded and dev kits are only $400!
https://puri.sm/shop/librem-5/
I'm a little excited about this company.
If my operating system has a rootkit or APT I am boned. If twitter is hacked I couldn't give a fuck, it doesn't affect my equipment or how I use my computers.
However, You're completely arguing a point that is different from what the entire discussion is about. We're talking about proprietary control points. The iOS operating system is proprietary and the App store dictates who and who can't publish on it.
The same is the case with Twitter. It has APIs and they control who and who can't use them to make apps.
Both companies have invited developers to make apps. Both companies have benefited from having those apps make their services/devices useful.
The fact that if you do not control the product you do not actually own the product.
You never buy a Apple device, you pay alot of money for the permission to use the device temporarily
That is distasteful to many people.
>That’s their key differentiator that enabled a lot of their advantages.
This is complete rubbish, there is no reason Apple could not have the App Store, have all the their "advantages" and by default lock their OS down, but still have a path for people that choose to break out of the wall garden, to do so.
Betting on startup whose business solely depends on a mercy of someone else's platform is a bad idea to begin with.
That’s the key problem here, if what Telegram says is true and they’re blocking Telegram worldwide, it’s really different.
I don't know what exactly has happened though. Is Apple defying China's government in secret now? Or are Chinese regulators only concerned with GFW bypass on some special days that has passed?
I am speculating and somewhat playing devil's advocate. My thought process is that Apple is huge, global, and communication is going to suffer sometimes for it.
https://www.amnesty.org/en/latest/news/2018/03/apple-privacy... Campaign targets Apple over privacy betrayal for Chinese iCloud ...
Once you implement that, you have to toady up to whatever governments exist, including oppressive/murderous regimes, to be in their markets.
If your ecosystem is just console video games, say, it's not that big of a deal; you have to either censor some games or don't enter certain countries at all. Might be unfortunate, but its not a fundamental human rights issue.
But if your ecosystem is about general-purpose apps and communication tools, you become complicit to some degree in all sorts of vile shit; oppression and forced relocation of minorities (China), mass murder of gay people (Russia), etc.
There's no way around this for Apple; they have to cave to government demands or risk being forced out of the Russian market. That wasn't inevitable, though; it's a side effect of the model they chose.
It doesn't matter too much if your videogame console is closed source, but it matters a lot if the software you use to read books, to write, to communicate with people is closed source.
Apple isn't going to do it, Google isn't going to do it. We must do it.
Back when Stallman outlined the distinction between proprietary vs open, he meant all of the above in spirit, but never really addressed the hosting and server-side side of things. I think it's currently still a weak spot in his philosophy. Open-source software doesn't truly solve the server-side if your phone has a hardcoded "ax.itunes.apple.com" - in theory, you could modify & recompile & host your own, but it wouldn't be a first-class-citizen thing. Also, consider e.g. if Apple's stack was open but highly customized - you needed a team of engineers and a swath of servers to simply get a clone up and running. Again, not impossible, but I don't think open-source is only a part of the solution.
Another way to prevent this issue is simply to have open computing platforms without significant barriers to running arbitrary software, and without any gatekeeper that can prevent them. This is mostly how computers have worked since their inception, and indeed is still how Apple's macOS machines work.
I am not saying that this model can prevent atrocities, but it can prevent companies like Apple from being complicit in those atrocities.
(But I think it's likely that this kind of platform model would benefit at-risk populations to some degree, too, because when there's no effective gatekeeper, there's no central point for a state actor wishing to do evil to apply pressure to.)
[1]: I just assume I will live to 100. :)
If Apple is based in the "right" country (that believes in freedom) -- and I think you and I seem to agree this is the case, because you don't mention anything bad about the U.S., mentioning only Russia and China by name, and with descriptions like "vile shit", "mass murder", "oppression" --, then the U.S. government should be doing whatever negotiations and interventions need to take place to keep foreign governments from forcing a U.S. company to do evil.
Here is an analogy. If you're CEO at a Fortune 500 American company, you don't have to make your life choices so that foreign governments can't blackmail you into doing evil, by kidnapping your family. Because the government protects you from that. If Tim Cook's family were abducted by China to force Tim Cook to have Apple do something... well this scenario is just completely implausible, the whole weight of the entire U.S. government would be all over it, it would be an international issue of immense proportions.
I think it's kind of up to the government to keep foreign companies from forcing American companies to do bad things.
Apple and numerous other businesses are beholden to shareholders, whose #1 demand is profit. Many shareholders are located in the U.S. - so far, so good.
At some point, the business decides that more profit is best obtained through international expansion. Apple extracts money from Europe, China, Russia etc. and delivers the desired returns. Yay.
The flipside is that if those returns are in danger of disappearing, there's now an immense pressure to stop that from happening. I don't believe the U.S. government can even help Apple if they don't want to be helped - their primary incentive is not preservation of diversity and free speech, but satisfying the shareholders.
Possible fixes:
a) Avoid conflicts of interest. Apple is not an American company at this point, it's an international company. So, limit your market reach to regions that align with your principles, i.e. don't expand to Russia and China. Of course, this can never work because public companies are legally obligated to maximize shareholder returns. Which leads to,
b) Put incentives in place to prefer doing the right thing over the profitable thing, i.e. don't sell a voting majority of your business to investors who will sacrifice principles for money.
Both of these fixes mean sacrificing market share to other, less morally grounded businesses, because you don't get to be a world leader in selling stuff by playing fair. You can't go back to playing fair once you depend on being a world leader. Apple literally can't do anything about it because of what its incentives are, and if it aligned those differently then it wouldn't be the big Apple that we give a shit about.
I don't believe there's a solution to this except supporting a decentralized market and educating others about why that's important. Apple is a lost cause, they're at the point of no return. They couldn't fix it if they wanted to. Let's make sure they're only one of several viable options going forward.
Also, I didn't mean to imply by omission that the United States government is not a bad actor. An evidence-based examination of the US government will reveal that it is (when taken as a whole) a deeply and objectively racist institution, has more people incarcerated than China and Russia combined, has killed far more civilians over the past 20 years than China and Russia combined, etc.
But as you say, American companies and individuals typically enjoy a far higher degree of freedom from governmental interference than their counterparts in (say) China and Russia.
So the reason I didn't mention the US government in this context is simply that they don't exert that type of control (at least, not yet) on platform companies like Apple.
Although parts of the US government are trying to ban encryption, and trying to force companies like Apple to create backdoors for the various secret police and law enforcement institutions, they don't seem to be successful with that so far.
Be careful of the ground you might concede to the censors. Freedom of expression is most certainly a fundamental human right:
https://berkleycenter.georgetown.edu/quotes/universal-declar...
It's easy to dismiss video games as "lesser" forms of art or expression, but we shouldn't underestimate the potential for games to convey significant social and political messages (both positive and negative).
In case a concrete example is needed of a thought-provoking video game with artistic merit, let me suggest this to those who haven't seen or played it:
So censorship of games is bad, too. But in my judgement, it is probably not going to rise the the level of interning or murdering people at scale.
Will check out the game. ;-)
any source on that? I have never heard about any murdering of gay people in russia.
Clearly, Russia is rather hostile to gay people. But "mass murder" requires a proper source. Or you you are walking on the Iraq Weapons of Mass Destruction path.
https://www.newyorker.com/culture/2017-in-review/the-year-ru...
https://www.theguardian.com/world/2017/oct/27/russia-chechny...
https://en.wikipedia.org/wiki/Gay_concentration_camps_in_Che...
https://www.theguardian.com/world/2013/sep/01/russia-rise-ho...
And calling Chechnya Russia is similar to calling Peurto Rico the United States. It's a subject of Russia, but is not what you'd call Russia. It's a 95% Islamic nation that waged a lengthy war of terror attacks against Russia and has its own independent government, rules, and laws which are driven primarily by Islamic law. You'll find nations driven by Islamic law tend to make Russia look like LGBT heaven.
Of course Russia is no such thing. It's illegal in Russian to distribute 'propaganda' for homosexual or bisexual advocacy in the presence of minors. And that in turn is used as a justification to prevent nearly all public homosexual or bisexual activism, though people are free to do whatever they want in private. In any case stating Russia is engaging in "mass murder of gay people" is something way beyond sensationalism and a reflection of how our media's efforts at creating a Red Scare has, arguably intentionally, driven people completely to the point of overt ignorance. It's like wartime propaganda, without a war.
My understanding is that Chechnya is part of Russia in a similar way, but I'm not an expert there, so maybe I'm wrong. If so, then I should have said "murder of gays in the Russian Federation" or "in Chechnya".
But, I mean, I could have instead said "state-sponsored assassinations of journalists and political opponents in Russia".
The specific atrocities involved are kind of incidental to my point that if you decide to operate a DRM-enforced single-source app store platform, you are going to have to get into bed with authoritarian governments if you want to sell your platform in the countries they control.
(That said, I will google the relationship between the Russian Federation, Russia, and Chechnya a bit more, so that I can state things more precisely in the future.)
You misunderstand. They're saying that referring to the entire US (or Russia) when you really only mean Puerto Rico (or Chechnya) is somewhat disingenuous, and clouds what is actually being said.
So Chechnya is the same region of Russian Federation as any other region.
PS.
Look at folk culture, especially at folk songs. You will found that each region of Russian Federation has it own language for folk songs and none of them are in Russian language. It because Russian Empire was formed by clumping together nations and bolting Russian language at top of them by forbidding all native languages. (It's why Russian Empire was called as Jail of Nations).
In contrast, there is 15 thousands of folk songs recorded in Ukrainian(Rus`) language (200 thousands if variants are counted).
Seeing your links, I went to wikipedia to understand what Chechnya is.
It appears to be an area in political unrest.
Right now only 1,9% people in Chechnya are russian.
So I guess it makes more sense to say "there is mass murder in Chechnya"?
And reading the first article, I don't even understand who is doing that, Chechnya people or russian people who live there? or russians from outside of Chechnya?
So my conclusion: what you're saying, is at least exaggerated and at worst just misleading on purpose.
I wonder if it would be possible to sort of fence off communication tools to a more open area of the ecosystem.... like everything in an curated app store.... then another space where it is a bit of the wild west but you don't control what is installed... sort of Android's ability to side load apps....
Granted this is convoluted and I guess there's nothing keeping that side channel from becoming all pirated apps from the other store....
well that thought experiment didn't work.
1) Telegram is prevalently used by Syrian fighters [1]. (Why they chose Telegram over Signal beats me.) As the Syrian conflict winds down, these fighters are returning home. That creates a security imperative for many governments, including in the EU.
2) Telegram recently ran an ICO that, at the very least, probably runs afoul of American securities law.
3) All of the reasons any app gets held up in review that are not "the Russian government pressured Apple."
TL; DR We have no evidence this is because of Russian meddling.
[1] https://www.huffingtonpost.com/entry/isis-telegram-app_us_59...
I think the point is that Android's marketplace functions as a gatekeeper. Apple's marketplace functions as a prison warden. The difference is whether you on the inside are allowed to make exceptions for who can come through, or even pass through yourself. If you have no control, what you've been told is a protective wall is actually restraining wall.
That said, as to your original point, perhaps some people do need their devices imprisoned for the benefit of the rest of us. I'm not sure I believe that, but I will readily admit that a vast number of people are either unable or unwilling to detect and rectify the problem of their digital devices being hacked, and that ends up affecting us all.
Wait, what? The desktop experience is wonderful in this regard - choose any number of app stores if you want, or don't, if you don't want.
I've never, ever thought of this as a problem.
Remember when you'd find four different toolbars on IE that your friend/family/neighbor had no idea how they got?
If you're on this site you are not most people. But, if it wasn't for the rules of Apple and Google what kind of things do you think Candy Crush would install on your elderly relative's phone?
That seems like victim blaming to me. I think this is more like pretty good evidence that Microsoft has done a disservice to its users vis a vis their security.
> Remember when you'd find four different toolbars on IE that your friend/family/neighbor had no idea how they got?
Yeah. I fixed that problem by introducing them to Ubuntu and Firefox, not by cordoning off their ability to install applications of their choosing.
> If you're on this site you are not most people. But, if it wasn't for the rules of Apple and Google what kind of things do you think Candy Crush would install on your elderly relative's phone?
I dunno man, this seems like a very dangerous argument to me. It's like you're saying that there's a huge silent majority that is not qualified to be the sovereign over the machines in their life, and that's not my world view.
I acknowledge that malware is a huge issue, but I think it's reasonably clear that the best ways of mitigating it do not include disempowering people or cutting their free speech at the knees.
I squarely blame developers/designers. Not just Microsoft, but Netscape with SSL, Android with app permissions and side-loading, etc.
There is this terrible historical concept that we can solve security issues with user education and work around design/deployment problems with security through obtuse user prompts.
>> Remember when you'd find four different toolbars on IE that your friend/family/neighbor had no idea how they got?
> Yeah. I fixed that problem by introducing them to Ubuntu and Firefox, not by cordoning off their ability to install applications of their choosing.
Sure, just as long as you keep in mind that Firefox extensions and Ubuntu snaps/universe/multiverse aren't vetted for malware. Plus Firefox extensions (like those toolbars of days past) can inspect all traffic and capture things like credit cards and passwords.
But hey, the user was notified that there was a risk and blindly hit OK - because it was the way to get the computer to do what they said they wanted the computer to do.
Is this an actual fact-based observation or just personal memories rooted in a time that Windows 98 was the best that many people got?
It often seems like people who hold your position are arguing against a caricature. As in, you can't do it this way because people used to have problems, or people might...
One of the problems that I think we technical people have not been able to solve yet is giving the user appropriate signals of the relative danger of the action they are about to engage in.
If all the dialog boxes look very similar, and any app can create one, you have yourself a dangerous system.
If you believe that's the case the bigger problem is the lack of education that leads to some people who are incapable of understanding the risks associated with doing so and not that they have access to do so.
Usually it's stuff like sketchy webpages that say "your Flash Player is out of date. Click here to install lates version." and they just do it.
Malware makers will always find a way to trick people into installing their stuff.
IMHO what closed systems like Apple propose is a false dichotomy. There's no reason why Apple couldn't allow sideloading apps and aggressively curate it's own store. The average user will use Apple certified apps and the power users who need more will sideload uncertified apps.
If gatekeepers are as genuinely beneficial to end users as people claim, then there's no reason to force anyone to use them or to block off unofficial channels. If your claim is true then ordinary people will stick to the certified App store of their own volition because it makes them feel safe.
Unless Android phones have an extra side-channel I don't know about, I just can't imagine someone sideloading an app on one of them unless they explicitly have decided the benefits outweigh the risks.
And if an average consumer is going into their settings and explicitly turning off a security measure, then at what point does it become reasonable to say that they're doing it because the official app store is not good enough on its own for the average consumer?
I get the whole "consumers are too stupid to know what's good for them" argument that people make sometimes, but I think that's a very tricky line to walk - especially when a company has a huge amount of profit tied up in deciding that individual freedom is a net negative.
I agree with you that it's a tricky line to walk, but the UX issue can't be dismissed as a triviality.
You can go through the process now with Amazon Underground, Prime Video, and several other Amazon apps for Android. The user is prompted to sideload Amazon's apps that contain functionality disallowed in Google's app store. Amazon shows step-by-step dialogs teaching users how to do it. It would be really interesting to know how many "non-power-user" users have actually stepped through that process at Amazon's behest.
It feels circular to me: "Most users are better served by a gatekeeper" -> "Because if users had a choice to go outside the system they would" -> "Therefore the gatekeeper must be mandatory" -> "Because most users are better served by a gatekeeper".
At what point do we have to step back and say, "maybe users just don't want gatekeepers?" Especially bearing in mind that, again, anyone who actually did want a gatekeeper could still use one and be fully protected.
We're assuming that every casual user who sideloads an app on Android is doing it because they're uneducated. What if they're not? What if they just feel like it's an acceptable risk?
What if the reason we can't trust the average user to stay in a moderated system is that moderated systems are not scalable, adaptable, or reliable enough to meet the needs of even an average user?
This is because it is actually pretty reasonable to make the judgement that Amazon is trustworthy enough to sideload their applications despite the dire warnings, so what you really want to find out is how many people are making unreasonable judgements on what is trustworthy enough to sideload.
Hah. Does the tech crowd never learn?
What we expect the "many users" to see:
+-------------------+
| This is dangerous |
| you'll be on your |
| own, so take care |
| |
| [cancel] [ok] |
+-------------------+
What the "many users" really see: +-------------------+
| This is a mildly |
| annoying message |
| only made to |
| delay access to |
| instant happinness|
| and BTW blah blah |
| blah blah blah |
| blah blah blah |
| |
| [meh] [buzz off and giev me teh warez]
+-------------------+
> And charge additional fee for fixing system broken because of this.<at your regular party>
"Hey I hear from <insert {relative,friend,whatever} here> that you work with, uh, computers and stuff, and, I think my phone is somehow, uh, broken, and I know zilch about computers, so could you help me with it pleeeease?"
I've been astounded with spectacular consistency over the years at how much people can achieve (however unsafely) to get stuff for free even if they openly claim to be tech illiterate. That includes jailbreaking and installing "alternative" app stores. Basically some kind of goal-oriented BOFH's dummy mode on steroids.
For over a year, Minecraft shipped for the Mac without being properly signed for Gatekeeper. Their official support article said the only way to get it to work is to turn the feature off (disable binary signatures system-wide) - probably because they didn't want to explain to people what right-clicking was.
I'm unsure if this was due to lethargy, lack of wanting to pay $99/yr to have their $2.5 bil product have a proper software signing key, or an ongoing technical issue. But they in no way explained to users what the ramifications of this change was, and the typical user making the change was likely a kid.
If Apple provides a way for a company (I'll pick on Spotify here as a likely example) to ship their app without having to play by the rules of the App Store, it will quickly become the only way to get the app. The only way the users will be able to get the functionality they want on their phone would be to disable the security protections and side-load. And historically, companies have dismissed the ramifications to the user of doing this ("Hit 'Ok' on the dialog which is displayed")
Companies like Amazon has a whole third party store based on exploiting what is often referred to in Android as a "developer mode". I see zero likelihood Apple will make it possible for a side loading feature compatible with mass distribution without government pressure. If you don't care about distribution but just want to build and load an app on your personal phone, thats already possible and does not require any fees or paid tools (assuming you have a Mac).
Of course, this App Store is also the central authority which would allow Telegram to take down fake apps which are there to confuse users and potentially provide vectors for things like ransomware and surveillance by state actors.
(That system on macOS is, for those who don't remember, called Gatekeeper!)
But then I can sign a jailbreak with my developer certificate and pass it around. Now, you're going to say that such a thing has never happened on macOS, but the fact that it could happen because you've opened the door to it is something that should be considered.
They also state they are continuing to work with Valve to get it published (presumably with only the feature to play existing purchased and free content, like say the Kindle app)
Yes, you can roll your own with a ROM and limit yourself to the tiny selection on F-Droid, but you enter an increasingly niche area. While it's "technically possible", it isn't really supported well enough to justify holding it as a benefit over a competing platform from a mainstream sense.
Bear in mind, when faced with a technical question revolving around making a backup of APK files, a core Android engineer said they "didn't support piracy", which was... a pretty hefty accusation to throw around for an innocuous backup of apps for being able to sideload should they be pulled from the then-called Android Market.
But I think you know this?
But this is not the first time we can see a difference between how Apple and Google conduct themselves in these situations.
Look at China. The China government tried to hack Gmail accounts and so Google left China. Versus Apple handed all their user data over to the China government. I get it was so Apple could make money in China but sometimes principle is more important as we saw with Google.
https://www.amnesty.org/en/latest/news/2018/03/apple-privacy... Campaign targets Apple over privacy betrayal for Chinese iCloud ...
Since Signal is actually open source, you can install it even if Apple decides to block it in the future (if you have a Mac).
So technical users could install for their friends.
You can reinstall it every 7 days for free though!
This really makes no sense on its face - if this is real Apple responding to Russian demands, why is Televram even available in the App Store at all?
So Apple is afraid that they will start killing people in Europe using newer Telegram versions?
Russian propaganda says similar things, that Telegram is used by terrorists and drug dealers and that is why government needs to be able to read your messages.
> Telegram recently ran an ICO that, at the very least, probably runs afoul of American securities law.
Telegram is a British company.
(I'm agreeing with you, just stating the point more obviously).
BS. There is exactly 0 reasons why they should infringe on your rights. Remember that. 0 reasons.
There was a project I was involved in rather heavily (cyph // resulted in a pair of neat conference talks) where we'd accounted for the risks of apps being banned by making the entire application operate exclusively in a web context. To at least somewhat mitigate the related risks stemming from having to trust the cryptographic logic delivered by a web server every time you use the service, trust-on-first-use was achieved by mangling the living daylights out of HPKP in tandem with service workers in order to persist barebones codesigning logic used for validating cryptographic packages delivered from the web service. Alas...
All of this is to say that there have been multiple parties involved in addressing this challenge, each one thinking from novel angles in an effort to mitigate the risks posed by the threat of sanctions against secure messaging. As it stands, it appears there's now a rather glaring weakness: if a nation-state decides as much, they can just twist the arms of the walled gardens supporting your secure messaging client in order to:
1) deny access generally, reducing or eliminating the growth of the target space and improving target acquisition,
2) persist known vulnerabilities just long enough to exploit against a target.
Telegram has been criticized again and again for their security hygiene and for their architectural decisions. Signal's seen some of that heat quite recently, and I raise both of these because they speak pretty strongly to the bullets above: there's a chance we're seeing a live demonstration by a preeminent world power against one of the few tools dissidents are using to literally stay alive.
If this demonstration succeeds without any sort of significant blowback (in the form of corporate or popular resistance or some other subversion or mitigation of the attack), there's nothing to stop any other major party from trying it, regardless of whether they're a nation-state.
---
Anyway, I'm keen on a deeper discussion here. Maybe the tinfoil hat's been a bit corrosive to my brain; counter-arguments are welcomed.
Russia is applying pressure to Apple (what pressure?) that prevents Apple App Stores in all countries from accepting a new update of Telegram
I don't get this - why is Telegram not releasing updates in a UK or Japanese region? What pressure (besides the local russian court system) is being applied here
---
In general yes I expect that app stores are the / a weak point in mobile encryption messaging, but it is only at the level of major player threat model. These things are good enough for use against all but a State level actor targeting you specifically (at which point leaving the country is probably good, if tardy, advice)
I mean we presumably do have Russian court Records from April, records that the Roskomnadzor went to court for encryption keys, and that there have been "shutting down entire segments of the Russian internet. Many small organizations, including language schools and museums, have been blocked as collateral damage." And evidence there was a demonstration with paper aeroplanes?
I am happy to accept that Durov has an axe to grind but Russia does look like a good suspect to start looking at first.
There are reasonable explanations between "Telegram is directly responsible for the delay" and "Russia made Apple hold up the app worldwide."
> Russia does look like a good suspect to start looking at first
Start. The discussion I'm seeing treats this as a foregone conclusion. That's all I'm cautioning in respect of.
What we don't have any evidence for is that these are in any way related to Telegram's inability to get updates approved by Apple. This is speculation based on the above claims which do have evidence.
They can fine the company, ban import of Apple products into the country, block access to App Store, etc. Yes, that same agency.
It doesn't even matter which regional section of App Store Telegram would use to publish app - users in need can switch between them and censorship agency can't see which part of App Store you are connecting to.
So Russian censorship agency's end goal should be to remove Telegram from all regional sections of App Store and use whatever legal or not-so-legal excuses to do so. Agency in question (Роскомнадзор) is notorious for their bullshit excuses to ban imports of food from Ukraine during all the trade wars even before all European food was legally banned for import.
Apple would be insane to comply with these demands, because it just opens the door for every other regieme to do the same.
So ... is Apple stopping Telegram from sending the updates? Are they doing it because of Russia pressure?
or is there more?
But they already did in China, right?
To drastically simplify it:
- Internal threats are usually motivated by finance/challenge/spite.
- State actors are usually motivated to counter perceived national security threats regardless of whether they're short-term or long-term. The result is a preparedness to spend resources orthogonally as compared to the potential impact of the threat to anyone other than the state but which may be directly correlated to the perceived risk to the state itself.
In simpler terms: risks exploitable by internal threats versus state actors do not assuredly overlap, and a lot of it is because risks exploitable by possessing knowledge might not be the same as risks exploitable with gobs of money.
I presume earlier Apple just gave in a bit to the pressure and stopped updates to help them censor the app.
I'm working for a startup that has had to pivot to web-only applications specifically because of Apple and their frustrating nervousness around anything involving applied blockchains.
If it is "applied blockchain", you don't have to tell everybody it's blockchain. App should look like natural (or, sometimes, magic) to non technical users. They couldn't care less.
Just show them what your app can do.
The specific device we put into production (and patented because of its criticality to Cyph) worked through the use of localized denial of service to pin signature validation logic into the local store of the browser to verify payloads received from other endpoints; in our case, we pin bad keys for the maximum permitted duration. That said, there are many different ways to use HPKP suicide that don't have to do with adding signature validation for client-side application logic, and they still come fairly close to achieving the goal of reducing how often you have to trust the server. The pattern described in this paragraph allows for Cyph to deploy new builds of the full messaging application whenever by just signing new builds such that they're validated by the pinned service worker, but if that flexibility is not a necessity, keep reading.
Since you can effectively pin any code into the browser through HPKP suicide, one different approach might be to pin a key for a more reasonable amount of time, such as two weeks, in order to stick e.g. critical application logic in the browser and rest assured that each user will use a certain build for at least two weeks time. This has the effect of reducing the exposure of an application's userbase in the event of a service compromise—at the expense of possibly committing some users to a bad build (or possibly even a compromised build) unless they manually clear pins. If you're writing a light application, this'll serve you pretty well. If you're writing a heavier application, you can outsource most of the heavier dependencies through SRI (the code pinned as the service worker would use SRI to validate the supporting libraries). The nuance here is that you're not implementing signature validation; you're just relying on that local DoS to ensure that certain code stays in the browser for as long as the bad keys are pinned and just confirming that any separate resources hash as what you'd expect them to. You're still certain to see that code--and any hashes you bake into it for SRI, should you choose to go this route--persist for as long as the invalid pins are live in your users' browsers.
HPKP still works in Firefox, so we intend to continue to research this pattern and related implementations of it. However, considering the browser with the largest market share just deprecated it while publicly mentioning the risk of footgunning via the standard, I'm not sure how much you stand to gain by implementing anything like the pattern we fleshed out two years ago. I'd love to build support to keep/fix the protocol rather than bin it, but the team that created is the team that gave up on it.
If you're curious, the private reason I've heard voiced to others by a person closely connected to the standard is that the protocol was not anticipated to be used in any manner other than what was documented, hence why termination of support for HPKP was preferred in Chrome over revision of the standard. I'm deliberately delicate with my words here because 1) it's hear-say, 2) it was expressed both off the record and in confidence to someone other than myself, and therefore 3) I can't be certain that it was expressed at all. However, key pinning--or any other TLS DoS--should always support what I described above as long as the DoS doesn't interrupt local code from executing in-browser, a behavior I doubt will change for the foreseeable future. You wouldn't want a TLS error to forcibly refresh an offline Google Docs instance just to show you said TLS error (resulting in loss of data from that offline GDocs instance), would you?
TL;DR: you can research alternatives based on the general pattern we described, but using HPKP specifically might be a dead-end for you.
But if you're keen on talking about it in more depth, I'm on keybase.io/bryant
But of course, this would break Apple's "we are the only app source, because you can only trust us" security model. Or maybe it's "... because we can only trust us, and we don't want increased support load".
Alternatively on my phone when I try to install an app, it'll allow me to change that setting just for that single installation and then turn it off again.
I never though of that before but the current situation might be a very good reason for making that library available.
Telegram suspects that Apple is trying to appease Russian censors while keeping a low profile and plausible deniability. Perhaps Apple is buying time and showing goodwill to Russia while they negotiate a deal - who knows?
Acting on their suspicion, Telegram makes this announcement, putting pressure on Apple to unblock updates, or at least to stop stonewalling them.
It's a clever use of PR as a tactical weapon. And assuming that Apple was indeed stonewalling Telegram (extremely likely knowing Apple), I think it's perfectly justified.
To me it just doesn't seem logical to resort to such a "nuclear option" over a review disagreement, instead of just complying, negotiating, or at least working around the problem in a creative technical way. It's not like Telegram is changing in some fundamental way since the last review... What could Apple be telling Telegram that is such a massive showstopper?
> What could Apple be telling Telegram that is such a massive showstopper?
Good question. I don't know. There are a lot of possibilities here and it's impossible for us to know what without Telegram telling us the actual rejection reason.
> Good question. I don't know. There are a lot of possibilities here
I can't think of any. Can you name one?
Or probably something else. But you get the idea. Telegram could have tried to introduce behavior that violated Apple rules. Or they could have snuck existing rules violations past Apple in the past and Apple finally noticed.
Have they been actively rejected (and thus, provided a rejection reason)? Or have Apple just stopped approving their updates silently?
If it's the former, I don't know what app store guideline says "well, Telegram is banned in Russia, and so no more updates." If it's the latter, then I can understand the frustration -- but we don't know which it is. This nuance is important.
For all we know, the answer is the former, and the app store rejection reasons are for completely unrelated issues. But as per usual, we don't know the full story.
This is probably made up/for comedic effect, but just in case it isn't, do you have a link?
Other examples are todo lists that only allow you one group unless you pay them.
Telegram is right to call them out on it, they should have done it earlier. But I guess they were hoping for Apple to re-enable updates and didn't want to make the gatekeeper look bad.
Tim Cook has taken a very public stance on privacy and the addition of police-unfriendly encryption of data. So, there's much to lose if news were to come out undermining that position.
He probably would not be going so far out on a limb personally if the reality of the privacy/security/encryption were just for PR. His integrity is dependent on that position being true.
Slowing things down for political purposes in entirely another matter, and well within the realm of probability.
Remember, those were the guys that unlocked the San Bernardino iPhone.
Android full encryptions are harder/impossible for them, a Cellebrite person told me half a year ago.
https://en.wikipedia.org/wiki/FBI%E2%80%93Apple_encryption_d...
I don't think this is true. Essentially Cellebrite gets ahold of an unpatched exploit that Apple then quickly fixes; that's far cry from being able to unlock "almost any iOS Device".
Well I mean, they wrote the OS so they can theoretically have it do whatever they want. But there's an extremely high probability that the way the OS is written, they cannot remotely trigger screen sharing without the user confirming it first.
https://support.apple.com/en-us/HT202303
"Messages in iCloud also uses end-to-end encryption. If you have iCloud Backup turned on, a copy of the key protecting your Messages is included in your backup"
Given that almost everyone has iCloud backup enabled, messages are certainly retrievable with a simple court order.
¹At least for existing users.
²And almost certainly requires opt-in for new users as well.
Also, russian users are less than 10% of Telegram userbase.
So now Apple is putting sanctions upon a British company just because Russia says so.
This sets a dangerous precedent. What will we see tomorrow? China, Thailand, Iran and North Korea kicking apps they don't like out of App Store? Apple banning apps on political grounds?
https://motherboard.vice.com/en_us/article/538kan/apple-just...
And yes, I think you are likely right: we will see apps banned at the behest of the Chinese government, given the size of their market. (North Korea, perhaps not.)
Apple painted themselves into this corner when they decided to become the gatekeeper of what iPhone users are allowed to install.
Apple received a notice of illegality from Russia regarding Telegram, a third-party app. This notice was inappropriately delivered to Apple, who currently has no responsibility for Telegram. Telegram's compliance with Russian law is not Apple's problem unless a Russian court orders Apple to de-list Telegram. Until such an order occurs, Apple has no reason to de-list Telegram.
Therefore, I believe that Apple did three things:
[1] Apple temporarily suspended Telegram app updates worldwide after receiving a notice of illegality.
[2] Apple immediately forwarded the notice of illegality to Telegram, without any assertion of validity.
[3] Apple notified Telegram that they may resume updates by either declaring in writing to Apple that Telegram is legal in Russia or de-listing Telegram in Russia.
And Telegram did no things:
[4] Telegram has refused to declare in writing to Apple that Telegram is legal in Russia, and has refused to de-list Telegram in Russia.
And Telegram, after two months of refusing to act on [3], is trying to pressure Apple into giving up on [3] using the "woe is me" GDPR excuse.
[5] https://developer.apple.com/app-store/review/guidelines/#leg...
Every country has its own legal requirements. As Telegram is a British company I assume it must comply only with British laws, right?
Theory 2: It’s because Telegram raised more than a billion dollars for a virtual currency that does an end-run around Apple’s in-app payments.
Based on Apple’s past actions, which one is more likely?
How can Apple justify penalising something not in an app? Why is the Kindle app still up, despite the fact that Kindle ebooks don't go through IAP?
So for Apple that is either a good way to get rid of an unwanted app, or a way to do a favor for a competitor, or a way to put pressure on Telegram developers to do something that the devs haven't done yet for some reason (e.g. give access to user data).
Now I'm not saying that Apple does anything like that. It couldn't be proven by simple people like us anyways. I'm just providing possible explanations for what's maybe going on and why it might happen. It is for instance just as possible that Telegram is not updating themselves, because they want to achieve some kind of hidden agenda, e.g. in a subgroup of people they care about users would very much be willing to switch phones just to stay with their secure chat app and they might have a better deal with Google than they have with Apple. Nothing can be said for sure without insider information.
Why does Telegram have decryption keys for all their users' communications (or do they)?
You need to choose an "encrypted" chat.
They have been criticised over this for many years now.
Maybe consider using a CDN or hosting necessary scripts on your server?
https://gfycat.com/gifs/detail/HelplessAlienatedClownanemone...
The app looks great though :)
Mobile apps should not do ICO, period. It's irresponsible for someone to try stealing uneducated people's money while promising something that's impossible to achieve.
Realistically speaking there are only two players in the market: Google and Apple, both of which will happily comply with governments and regulators since they have no business in allowing gray area businesses, and that's a good thing.
However when you raise ICO, you're basically promising the censorship resistant future while fully knowing that it's impossible to achieve what you promised because your app is built on top of these centralized platforms.
This is on a completely different level in terms of scam factor when compared to naive idiots promising things like "putting grass-fed cows on the blockchain", because literally it's impossible to build a censorship-resistant, decentralized mobile app and they are the ones who know this the best.
I point this out because it looks as though all the press coverage seem to be focused on how Russia and Apple is censoring Telegram and Telegram is the victim, when Russia and Apple did nothing different from what they used to do. Russia has always been this way, and Apple has always tried its best to fight for user privacy but did make compromises when they really had to. It's great that Apple is doing its best to fight for user privacy but to be frank, Apple shouldn't be the one to blame here.
It's Telegram who decided to promote itself as a "censorship resistant decentralized blockchain application" to raise billions of dollars, and they got to this position because of this stance they had to take in order to raise the money. The only losers in this case are the idiots who invested in Telegram's ICO.
But even Ripple pales in comparison to something like Telegram, because Telegram is a mobile chat app, which is as centralized as you can get. Not only does it depend on iOS and Android, but also all push notifications must go through APN (Apple Push Notification) or FCM(Google Messaging). In fact, messaging apps are arguably the most centralized apps out there because of these features. And this is why it's so easy to censor these apps.
So if your app can easily be censored, and if your coin is useless if your users can't use the app, what else do you think they were claiming?
One of the major selling points of that utility coin was that it'll be automatically available for 200M active users of Telegram. Frictionless entry point into coins is a huge step forward.
I don't really consider that a good thing. Having government controlled gatekeepers that take 20-30% off of every app with platform lock-in is not a great thing. We rail constantly about FBI/NSA enforced backdoors, especially people in Europe that are potentially having all their data harvested.
I said "That's a good thing" from Apple and Google's point of view. They are public companies with shareholders who don't want them to contribute to potentially illegal behaviors. So it's a "good thing" for them to have the companies comply with the governments.
But this phenomenon itself is not a good thing, so I do think decentralized projects should fix this problem. But centralized companies should not advertise themselves as being able to tackle this type of problem because it's not possible.
This brings us back to the original issue I pointed out. Telegram knows Very very well that they have this issue. Ask anyone who has built a mobile app if building a decentralized ecosystem on top of Apple appstore is possible and they would laugh at you. But Telegram did. And they raised billions of dollars for that false vision which they knew was impossible to achieve as a centralized organization with a product that depends on a centralized platform.
really, should anyone?
If Apple acquiesced to Russia’s demands, Apple would have: 1) removed Telegram from the App Store in Russia, and 2) prevented Telegram from using the Apple Push Notification Service to distribute non-blocked IP addresses to clients.
More likely, updates are being rejected for another infraction. Telegram should publish the App Store reviewer’s criticisms publicly, and provide more context before making public denouncements.
Well, that's one of Durov's powerful weapons. Cry in public and blame others, while he is the one who messed it up.
Edit: actually that article contains much less information and the discussion is correspondingly less substantive, so I've taken the 'dupe' marker off the current post. Carry on.