Egypt Blocks Access to Telegram
masaar.net
masaar.net
Good thing that the Telegram client supports proxying traffic over SOCKS5 and MTProto (custom protocol). On the server-side, in the past, they successfully employed domain-fronting and recycling through multiple IPs to bypass the Russian firewall.
The client does its own DNS resolution over HTTPS and so DNS blocks are already ineffective.
It is even more noteworthy that the Masaar site by the link says they blocked 116 news sites, 349 anonymization sites, 6 e-commerce sites, 11 culture sites, 8 blogging platforms etc and... just one terrorist site :-)
The fact that so many authoritarian governments ban/are hostile to Telegram suggests they actually do have some integrity.
IMHO the only good argument against Telegram is that direct messages don't use end-to-end encryption by default.
> IMHO the only good argument against Telegram is that direct messages don't use end-to-end encryption by default.
I'd add two more:
1. End-to-end encryption being device-specific. Example: if you start a secret chat from your phone, you can't view it on your other devices. Other end-to-end encrypted solutions don't have this drawback.
2. End-to-end encryption being available only in one-to-one communications. Take this with a grain of salt, but I don't think it's available at all in group chats and channels.
https://play.google.com/store/apps/developer?id=Telegram+FZ-...
Telegram X is not the official version.It is an unofficial client for testing design and app speed. It has a different UI
So, from the point of view of anyone using the Signal service, the utility of the source is near-useless.
https://signal.org/blog/private-contact-discovery/
SGX is definitely not bulletproof (https://medium.com/@maniacbolts/signal-increases-their-relia...), but it exists to do exactly this job, and Signal is using it.
We are very much trusting the Signal team to do what they're saying (not logging, not leaking) and to make no mistakes in doing it (not logging accidentally, not leaking accidentally).
Which is in general a fair trade-off, but it is very much a trade-off, open audits notwithstanding.
https://signal.org/blog/private-contact-discovery/
It's not bulletproof by any means (https://signal.org/blog/private-contact-discovery/ goes into this, and also points out several features they've used SGX for since), but it's certainly something, and they're doing it.
It has a good reputation for refusing to kick people off when governments demand it. Although accounts are tied to phone numbers it doesn't show them by default and users can choose a unique username, so unlike WhatsApp or Signal it's easy to recognize the pseudo anonymous identity of people you don't know. It's much easier for many people to use than Twitter.
When running an opposition movement it doesn't matter if there's no encryption. Since you are open to the public your adversaries are going to be in your groups anyway. Another bonus is that most of your followers aren't already using it, which makes them more free to act. If a different messenger is popular in your country you might not want to tie the long held account that everyone in real life knows you as to your freedom fighting activity.
Let's see how long until they hear about signal
Javascript-on-desktop arguments are probably already taking up gigabytes of space in the HN database, so I'll just say it's for all the usual reasons.
$ wget https://github.com/ooni/probe-cli/releases/download/v3.0.8/ooniprobe_v3.0.8_linux_amd64.tar.gz
$ # sha512 => 4f215347022028cf5328446d15e59f2141d1a41e59110c0b85c67b711953d115 ooniprobe_v3.0.8_linux_amd64.tar.gz
$ tar xfv ooniprobe_v3.0.8_linux_amd64.tar.gz
$ # Move to $PATH
$ mv ooniprobe ~/bin
$ # Add crontab to run daily
$ (crontab -l 2>/dev/null; echo "$(( ( RANDOM % 60 ) + 1 )) $(( ( RANDOM % 24 ) + 1 )) * * * ooniprobe run") | crontab -
Mostly just stolen directly from the readme of the CLI probe: https://github.com/ooni/probe-cli#ooni-probe-cliAlso, make sure you're not on a network where someone will report you for visiting the "wrong" websites. It does requests to a lot of websites you don't want to be caught with in your history.
$ curl -L https://ooni.org/install | sh
similar to https://nixos.org/download.html#nix-quick-installDon't forget to think about all the different OSes and the way the handle scheduling!
I believe the paid plan of ProtonVPN also offers TOR connections. Not a specialist on this, though.
These systems mostly use blockchain as PKI or similar to bitcoin mempools with public crypto, but not store messages on blockchain.
How would you block a p2p network like TOR? Just ban all the entry points. You can use proxies to access those, but then you can use the same proxies to access a centralized service.
How do you ban a federated network like Matrix or e-mail? Ban all the servers you can find, then you're back to proxies.
Of course, another issue is that no device is always online, so you can't base the system entirely on devices communicating with each other peer-to-peer. You want to at least have supernodes. When you do, it effectively becomes a "dynamic federated network".
Then Telegram team came up with smart improvements to the protocol, like delivering individual IPv6 endpoint for each user via invisible push notifications.
https://www.theverge.com/2018/4/17/17246150/telegram-russia-...
https://www.reuters.com/article/us-russia-telegram-ipaddress...
I'd like to understand the use of inverted commas here, as if things were not what they seemed. What gives?
other background is that telegram was started by the same guy who founded vkontakt, russia's facebook, and that it advertises itself as having secure e2e chats, which are not default and are difficult to use
Further reading:
https://www.cnbc.com/2020/03/26/coronavirus-lockdown-uae-res...
https://telegram.org/tour/channels
In this case it's more relevant to ask why Twitter or Facebook haven't been blocked (if they haven't).
I think WA has a similar feature ("broadcast") but not as widely used (since it is limited to 256 people).
WhatsApp groups can be set to act like channels, however, by changing permissions to allow just group admins to send messages.
Channels are pretty much news feeds of note.
And they scale from a community, through to global classes of people.