FBI document shows what data can be obtained from encrypted messaging apps
therecord.media
therecord.media
Wickr is set up like an expected honeypot would be set up. So for people that don't or aren't willing to understand that, I'm wondering if this document validates them, or if the skepticism of this document's classification level validates the idea Wickr should be avoided for sensitive communications.
So yes, you should make sure if your threat model cost benefit says you should:
* You have a secure keyboard mechanism. No third party keyboard apps, used a wired / built in keyboard.
* You use a secure OS and keep up to date. You verify updates are public and not made 'just for you', you turn off auto updates.
* You watch the network behavior of your devices with external proxy devices to see if anything weird is happening, you filter out network interactions you don't like, use a VPN with the proxy device and so on.
The more you use 0days, the more they get noticed and the more likely you are to burn them, so you've just increased the stakes towards surveilling you. Now the minimum standard to make you a person of interest has increased significantly, reducing the probability of it.
I only worry about innocent westerners living in a society that is creeping toward authoritarianism in the name of some politically polarizing politician. I do not empathize with hackers breaking into systems and causing major problems.
And there are other threats you'll want to defend from as well, including governments and agencies with smaller budget.
Anyway, if endpoint security is part of your threat model, you'll be pleased to know I've spent the past decade looking into how to address the problem https://github.com/maqp/tfc
Which leaves anyone planning on doing something the US gov’t (or China, or Russia if within their reach) wouldn’t like left with some unpalatable and inefficient options.
Either they blend in enough to not get any attention, or don’t seem “dangerous” enough in the sense they are likely to get anywhere, or don’t use any technology more complicated than a piece of paper and a #2 pencil.
The last one was what osama bin laden was doing, and they still found him - it just took awhile.
As long as the folks being targeted are legitimately out to do harm against innocents, these capabilities are ‘ok’ (scare quotes intentional here).
They’re going to be turned against political opponents or people that just seem ‘bad’ though at some point, and almost certainly already have been for years.
I won't detail the designs here, but we are talking very cheap to build and design.
I am sure such devices exist and are in the wild, being used by spies.
That said -- I am mostly disappointed with the degree to which our intelligence agencies are inwardly focused rather than breaking up foreign spy rings and operations.
There are some scarey, harmful, and extremely complicated foreign spy rings on US soil. They have people working for all major tech companies and they are embedded in key positions.
The FBI should be making "see something? say something" pushes in tech companies. They should have better followup and reward systems.
Never heard of data diode before. The hardware setup gives such a peace for the paranoic mind. Love it!
I'm sure this will not foster distrust, will do wonders for morale among immigrant tech workers, and will in no way leave them primed to be recruited by foreign intelligence services.
If this information has been publicly released, I would assume that it does not comprehensively list all of the methods/sources that could be in use. Thus, I would not trust this document to be accurate.
It's reasonable to believe that at any point in time Root exploits exist for both iOS and Android.
It's viable that the FBI or someone they cooperate with has such exploits from time to time (which doesn't mean they are reliable, or cheap to use).
If you root-hack a phone you can easily get all messages the user sees after you hacked it.
Even without root hacking you might get some, in some circumstances.
EDIT: I should have read the article first, it's more about what content they get without hacking.
https://en.wikipedia.org/wiki/Expectation_of_privacy
This is not even necessary if you're in bed with hardware manufacturers, which could be the case with governments. All is needed is a system level daemon running in background, disguised as service or device driver pushed as mandatory upgrade, having access to the underlying iron. The user employs super strong cryptography? Who cares if we can read what is sent to the screen and tunnel it over the network to us. Passwords? Who cares if we can sniff the touch screen data to get the tapped points coordinates containing the position of keys on the virtual keyboard. Point is that there is zero protection against surveillance if the adversary has control over the hardware. Which is the reason why flashing an FOSS operating system on a closed hardware/firmware platform, although being indeed a good thing, isn't enough to claim victory.
Telegram group chats are very much available to law enforcement if they can convince Telegram to hand over the data.
It could also be that Telegram (and any other foreign chat company) is more reluctant to (and more difficult to force to) share data with the FBI.
> Telegram group chats are very much available to law enforcement if they can convince Telegram to hand over the data.
Telegram public channels and groups are open, including for law enforcement. They also say openly that they cooperate with everyone to take down certain illegal material from channels and open groups.
Telegram claimed as late as a few months ago - and nobody has proven otherwise in any form as far as I can see - that not a byte of their users private data (i.e. not on open groups or channels) have been handed over to any government.
I cannot prove this and also I'm getting more careful with Telegram these days (this might come as a surprise for some of you who know my history of defending Telegram) but I still think
1. if it was possibly to prove something else there are enough Telegram haters just on HN to make sure to leak it
2. just to be clear I still think it is a very good alternative for friend-to-friend-communication, group communication etc, I'm just looking for alternatives as I go forward, and also I am worried when I see police using it at work.
I have no reason to distrust the Telegram team, but the data model is simply not designed to keep messages secret. It's Telegram's biggest shortcoming, in my opinion. Things like channels don't need encryption, but group chats can use some WhatsApp-style crypto.
WhatsApp's UX (basically: trust all E2E keys, and show a little notification if the keys changed) makes E2E available to the common smartphone user without the hassle of say Matrix's manual verification. For those with a more security-oriented mindset, there's always the ability to show encryption status changes so you could investigate.
I'll probably be using Telegram for a few years despite its shortcomings. It feels a bit iffy to talk about sensitive personal matters through Telegram, but I know it'll be a while before I can convince any large group of friends to move to something more secure.
For now I'm bridging my Telegram accounts through Matrix, so it's not like I'd benefit much from the added security anyway.
Can you provide a link for that? I could only find that they'd hand over your personal account info if they get a court order claiming that you're a terror suspect (from https://telegram.org/privacy):
> 8.3. Law Enforcement Authorities
> If Telegram receives a court order that confirms you're a terror suspect, we may disclose your IP address and phone number to the relevant authorities. So far, this has never happened. When it does, we will include it in a semiannual transparency report published at: https://t.me/transparency.
Maybe I can:
First a note: "your personal account info" while somewhat correct makes it sound broader than what the paragraph below says: "your IP address and phone number".
That said, here is one that that at least partially confirms this:
From https://money.cnn.com/2015/11/18/technology/telegram-isis-sh... :
> "Our mission is to provide a secure means of communication that works everywhere on the planet. In order to do that...we have to process legitimate requests to take down illegal public content (sticker sets, bots, and channels) within the app."
(emphasis mine)
There seems to be more in the search results here (if you have access to kagi, if not apply now:)
https://kagi.com/search?q=telegram+takes+down+isis+groups+
Edit: here's another link from the first page of results in kagi: https://www.forbes.com/sites/parmyolson/2015/11/19/telegram-...
Another after I added "cooperate" to my query: https://www.europol.europa.eu/media-press/newsroom/news/euro...
In my experience, though, very few people use E2E chats, even in direct chats.
Or if they hack Telegram's servers. Or ask some other agency like the NSA (that hacks systems all the time) to do that for them.
As for the legal aspects, I'm fairly sure Telegram can be made to comply, no individual user's is worth losing (tens/hundreds of) millions of customers in that particular country. It's not like Telegram can't do that technically*, the server-side database encryption key is by definition in the RAM of the server system.
* That hasn't prevented them from actively misleading customers with their split-key-and store-parts-under-multiple-jurisdictions -scheme.
Or they join the group chat
Here in Puerto Rico we made our governor quit over exposed chat logs from a Telegram group. Encryption wouldn’t have saved it: someone took screenshots and leaked them to press.
Telegram is not unencrypted. This is a lie spread by certain WhatsApp and Signal fanboys (not all, count me in with the Signal fans - I just happen to be a reasonable one that to some degree know what I'm talking about) with the excuse that "of course we mean end-to-end-encrypted when we say encrypted".
What we see now is the resulting confusion: why don't law enforcement have access to it if it virtually unencrypted? Well, the answer is despite all claims of how lousy the encryption is for some weird reason[1] it doesn't seem to leak data.
Now that we have seen the confusion that stems from saying "encrypted means end-to-end-encrypted when we say it does", can we stop repeating that nonsense?
Also, can we think twice before mindlessly repeating such stuff in the future even if it was originally said by some extremely smart people that are well respected for good reasons?
Because those very smart people were the same who recommended WhatsApp for a long time until it became painfully clear to everyone that:
- WhatsApp leaks metadata to Facebook which cooperates happily with basically any government as far as I understand
- WhatsApp has uploaded unencrypted backups to Google Cloud (yes, probably over https, but Google got all you messages and it was known that they would datamine it.)
- and more¨
PS: Some time around half a year before Telegram launched WhatsApp actually sent data unencrypted, i.e. as plaintext. And they sent it over port 443..!
PPS: Stay safe folks, opsec is probably more important than the exact messenger you use. My bets today are Signal in the short run and Matrix as soon as possible, but personally I send photos to my parents using Telegram and receive a lot more info back from various groups.
[1]: Meaning either this is a bigger honeypot than An0m and everyone Three Letter Agency including both FSB and NSA are in on it or Telegram actually got something right. Or they have just been extremely lucky for 9 years in a row or something.
And Telegram most certainly cannot encrypt group chat.
The remaining criticism now is that the default for one-on-one chats is still the more convenient normal point-to-point-encrypted chat type instead of E2E-encrypted (which, in Telegrams implementation is less convenient since it doesn't sync between clients, which again is reasonably for those messages where one really cares about secrecy in the context of day-to-day messaging apps).
As usual: I only observe this from the outside. For what I know maybe Putin reads my messages before he goes to bed every night to fall asleep because I mostly use ordinary point-to-point encrypted messages which can be intercepted if Telegram is a secret FSB front or if Telegram isn't careful. Note however that for all we know maybe Biden reads my mail too to fall asleep since that too isn't end-to-end encrypted.
I only comment on observable facts or statements that haven't been debunked. The last means I haven't verified the crypto of any app, I take it for granted that if it is broken someone will figure out just like when WhatsApp sent plaintext messages over port 443, and even faster with Telegram since there are so many who wants to find flaws in it.
If you have and you have real proofs, bring them and I'll probably repent.
In light of that hypothetical but far-fetched pathway, there is probably no need for you to repent there.
With WhatsApp the claim was that if someone snuck a backdoor into it there are enough people watching it to make sure that it would be found out soon.
My point is that even more people are sceptical to Telegram and even dislike it strongly so there should be even better chances of someone discovering if something was broken.
I'm honestly interested.
I only intend to defend Telegram against lies (most of the time the claim that "it is not encrypted"), not to cover up any actual problems so if you comment on it or write a post about it I will read it and probably will upvote it.
Even your private messages only require you to enter an SMS code to view, so anyone that can intercept an SMS sent to you, can read your messages.
Let's stop saying that as it implies users are somehow aware the service provider has access to the content, and that they make an informed decisions wrt their privacy.
>Even your private messages only require you to enter an SMS code to view, so anyone that can intercept an SMS sent to you, can read your messages.
The 2FA password is something everyone should enable. It's still an incremental security improvement if you have to use Telegram and your threatmodel is a banana dictatorship doing SMS interception but not server-side hacking.
The right thing to do is get yourself and your loved ones the hell out of Telegram as soon as possible; Signal is your best bet here. Cwtch/Briar if you need to also protect metadata.
No, this is not the right move. It's engaging with the ecosystem of messaging products balancing ease of use, ethics of the business and people behind it, and your own threat profile. Most will never be under threat of a state actor that necessitates getting their friends and family "the hell out of Telegram as soon as possible".
I also use Matrix but personally speaking I find Moxie Marlinspike a deeply unethical person who will gleefully slander the competition including up to suing them in his quest for supremacy. So I don't touch Signal because on my tripod of interests to balance, I don't want to go anywhere near his ethics.
Use Signal or Session or Element or Telegram but stop telling people not to use a thing because you believe E2EE is the next Jesus Christ. Only sith deal in absolutes.
Please don't do that here. It's both personally insulting and a motto used by fanatics, not an argument for anything.
Who is "my adversary" exactly and what do they want with me?
No, I don't think Moxie's past and current behavior is indicative of a person who subscribes to ethics. I think he's vain, eager to be in the spotlight and eager to profit off a cryptocurrency invented by a company he has a very complicated history with [1].
[1] https://www.coindesk.com/tech/2021/04/09/signal-founder-may-...
He will extort money from you based on your private message history, when they eventually leak from Telegram's effectively plaintext database.
>I think he's vain, eager to be in the spotlight and eager to profit off a cryptocurrency
That says more about you than about Moxie. You've shown your character, now strongly consider showing yourself out.
I'm sorry, what? Do you want to explain how giving evidence of Moxie acting poorly is a reflection of me? Or why you're now personally attacking me?
I didn't do any such thing to you, please kindly treat me with respect.
Sorry, this is a hacker board. I, and others hackers, agree with me. E2E||GTFO.
I think you should qualify that as "most people - in the western hemisphere/democracies - will never be under threat of a state actor that necessitates getting their friends and family "the hell out of Telegram as soon as possible"
This isn't just about nation states. Companies get hacked by common criminals all the time. Consider the case of the Finnish psychotherapy center Vastaamo https://www.wired.com/story/vastaamo-psychotherapy-patients-...
Now imagine all the private messages you've shared to your SO or dearest friends. I bet there's gazillion times more stuff to extort you with for the rest of your life, than the notes about few sessions with your therapist, have.
So yeah, get the hell out of all "private" messaging platforms that aren't E2EE by default. You deserve the peace of mind of never having to feel like the TENS OF THOUSANDS of Vastaamo case victims.
>but stop telling people not to use a thing because you believe E2EE is the next Jesus Christ
Stop telling people to ignore best practices wrt security just because they cause your privileged life -- where you don't have to worry about actual oppression -- slight inconvenience. There's a good reason majority of top vendors for secure comms like Signal, Jitsi, Wire, Element, iMessage, Threema, Briar, Cwtch all default to E2EE.
Telegram is free to not E2EE, but they should be UPFRONT about it. Not say things like "heavily encrypted" when in reality it uses the messaging industry's bare minimum, that is client-server encryption.
Telegram devs also actively mislead by presenting two facts next to each other "Telegram uses E2EE called MTProto" and "All Telegram chats use MTProto". What a novice can't understand is "Telegram also makes the idiotic choice to call its non-E2EE cloud messaging protocol ALSO MTProto."
So it's not wonder why a LOT of my contacts have been flabbergasted to learn Telegram isn't actually using E2EE for everything like WhatsApp. Telegram's marketing had succeeded in telling them it was more secure than WhatsApp, and thus E2EE.
Whether or not this misconception was intentional, it's now Telegram's job to either make a public statement and correct the record, or preferably, make it E2EE:
There is no reason for Telegram to deploy E2EE for everything except supergroups. If all the other vendors can pull that off, so can they. Pavel Durov has so much money but the only cryptographer he ever hired was his brother Nikolai who isn't even a cryptographer but a geometrician. Durov has the money to hire Moxie for a year to deploy Signal protocol, yet he won't. You should be terrified of both why he won't, and what his foolishness in the context of Vastaamo can, and eventually will do.
* The CEO isn't a developer
* We know practically nothing about their developers, they're all anonymous
* The server has access to overwhelming majority of messages (among fellow CS students only ~10% said they use secret chats, and most likely even they don't do that for every 1:1 chat. Furthermore, groups can not be E2EE at all, and neither can Win/Linux desktop chats)
* Journalists that went to see Telegram's offices at Dubai found an empty office, and their office neighbors said they've never seen Telegram developers let alone anyone enter the offices https://www.youtube.com/watch?v=Pg8mWJUM7x4 They did speculate Telegram might be using Dubai for tax evasion.
* That being said, we know absolutely nothing about Telegram's financials, nothing official has ever been reported by the company. Yet the system manages to stay afloat year after year with 600M+ users.
I'd love to be able to give good reasons why Telegram can't possibly be an op, but hand-waved opt-in E2EE for some clients, is the only one I can find, and that encryption has been most effective in online debates defending Telegram's bad security model.
As a Canadian talking to Canadians in Canada, I hope it’s an FSB front. They seem like my most secure option.
True, but I don't really "get" Chinese style UI.
https://en.wikipedia.org/wiki/State_Security_Committee_of_th...
"Along with its counterparts in Transnistria and South Ossetia,[1] it is one of the few intelligence agencies that kept the Russian name "KGB" after the dissolution of the Soviet Union, albeit it is lost in translation when written in Belarusian (becoming KDB rather than KGB)."
Telegram was in Berlin for a while but moved out of Germany for privacy/legal reasons as well (good call, considering that Germany is discussing trying to outlaw them) and moved to Dubai iirc.
Yes, because if you're an FSB operation, the rule #1 is to operate from Russia, that way nobody suspects you.
>moved to Dubai
Yet journalists who went there only found an empty office https://www.youtube.com/watch?v=Pg8mWJUM7x4
https://www.reuters.com/article/russia-vkontakte-idUSL5N0KY3...
I gave Durov a benefit of the doubt in 2013, but as I saw their E2EE stayed as a bolted-on gimmick, as opposed to forming a solid foundation, that image of a philanthropist fighting against surveillance capitalism disappeared real quick. Telegram's security model is indistinguishable from Facebook: Parent company gets everything except opt-in E2EE messages, and neither company encourages their use.
* all Telegram chats by default
* all Telegram group chats
* all Telegram Win/Linux desktop chats
is indistinguishable from end-to-end encryption where the service provider has a backdoor (ANOM[1])
In both cases the service provider, and anyone who hacks them, can read your messages.
[1] https://www.pcmag.com/news/fbi-sold-criminals-fake-encrypted...
I don't buy this. Maybe it's true about FBI, but other agencies have the keys for right or wrong reasons.
"can render 25 days of iMessage lookups and from a target number."
I thought iMessage was E2EE and with all the iJunk turned off this isn't possible?
They can still do an actual investigation on the person and try to dump from the physical devices they find (whether it requires a court order first, or not).
Of course, this is expensive, and often it is not possible to know who to go to, or whether they can access that person, or they don't have enough information yet to determine if a crime has been committed. But that's the point. In the US, for example, the constitution was constructed specifically to be an alternative to how England and its colonies were governed.
Governments have had a small window of time where electronic communications had a combination of: existing, not being private, and being understood by law enforcement. That window is closing and is just a reversion to the mean.
Of course they are going to say "everyone using this convenient poorly implemented system without privacy helps us greatly in investigations", but thats not the point. They have to do an actual investigation now and target the devices itself physically, and even after all that only sometimes that will yield anything, depends on the OS version and app used, and app version.
Security always requires a certain amount of trust. If you can't get that trust, meet in person and keep your electronic communication vague.
thats when i revoked all my keybase information.
> Search warrant: Provides address book contacts and WhatsApp users who have the target in their address book contacts.
> Pen register: Sent every 15 minutes, provides source and destination for each message.
Implying there are illegal ways to access?