Telegram has released user data to German Feds in multiple cases
twitter.com
twitter.com
Signal will hand over your data too if the police show up, but they don't have any data to hand over.
That's just plain incorrect.
> if local law enforcement comes knocking on their door with a warrant
How is German law enforcement relevant to an app HQ'd in Dubai? They've been openly criticised before for not cooperating with law enforcement.
All chats are unencrypted by default.
I read the FAQ and even skimmed the MTProto 2.0 docs but from where I stand this Server-Client encryption sounds like encryption in transit but the server still has the ability to decrypt.
This, from a privacy against law enforcement perspective (which is what the article and comments are about), is more or less the same as no encryption.
Edit: s/transport/transit/, add "perspective" to the last paragraph.
The encryption part [1] is covered in the FAQ, along with more details.
Also see the question and answer on “Fo you process data requests?” [2]
Telegram has a feature called secret chats, which are only person-to-person. That uses end-to-end encryption.
[1]: https://telegram.org/faq#q-so-how-do-you-encrypt-data
[2]: https://telegram.org/faq#q-do-you-process-data-requests
Also they should now update that FAQ answer where they say:
> To this day, we have disclosed 0 bytes of user data to third parties, including governments.
In fact, if the OP is indeed true, they should probably update the entire answer since it's misguiding at best, and an outright lie at worst.
I suppose there are some people pit there that think "unencrypted" here means everyone can listen in, but certainly not the hackernews crowd.
Heh, we've come far. True unencrypted chat was once popular, and technically still exists (although most IRC networks now default people to TLS.)
For E2EE, you need to open seperate 1 on 1 chat, which is optional, not default.
And what it comes to group chats or channels, none supports E2EE.
It's like going outside in the rain, getting wet and saying "Well, it's not actually raining, I didn't get a pint of water in my boots."
We have clearly talked about E2EE (end-to-end encryption) and server side encryption is not that. E2EE means that it is encrypted between you and the message target. Server is the middle man, which should not have the access.
Almost everything is already encrypted with TLS on the current world during transmissions and regulations require server side encryption. It is not even our main interest to talk about that anymore, we are past that.
The main issue on the original post is the lack of E2EE.
If you put the key next to a locked door it doesn't matter if you lock the door.
Real encryption means that even Telegram couldn't decrypt it.
If you want to discuss E2EE, do so but it does not make it more "real" than other encryption.
Unencrypted is false. Not E2EE is true. Most use the former to wage war against an app they don't like because they prefer an app like Signal that satisfies their desirable qualities. Moxie actually started this trend and it is despicable. I'd say the exact same thing if Durov started referring to E2EE as "pedo-encryption" or anything else that distorts meaning.
Don't distort meaning. Use precise language.
It's an abuse of language to call that encryption because if you say encryption you imply security. But this is not secure and if it's not secure encryption is useless because security is the reason for encryption. Encryption is not used for the sake of encryption but to protect the content of a message from unwanted access.
Yes, that is what Telegram is doing. It may not be protecting the contents from who you want it protected from (everyone but you and the message recipient) but it does protect the contents from other (notice I did not say all) adversaries Telegram and its users don't want accessing.
It is still encrypted so use correct language, please and do not weaponize words to your own designs.
It is more likely that you are trying to weaponize the words for your own designs.
> It is more likely that you are trying to weaponize the words for your own designs.
Please point to where I have weaponized a word because on its face that accusation doesn't make any sense. I have not decided encryption means unencrypted. I have doggedly insisted words be used appropriately and even went so far as to give an example of mischaracterization of E2EE where I would call someone out.
During the transportation of the information for the target recipient, the data in this case is on plaintext at some point on Telegram's server, and therefore it is not encrypted for the whole duration, going against the idea of transferring or holding information only for authorized parties in ciphertext format.
If we think that Telegram is the targeted party, then it would be encrypted as data is transferred or hold in ciphertext format for the whole process. However the Telegram is no the target, and the encryption is removed in the middle of process.
> Please point to where I have weaponized a word because on its face that accusation doesn't make any sense. I have not decided encryption means unencrypted. I have doggedly insisted words be used appropriately and even went so far as to give an example of mischaracterization of E2EE where I would call someone out.
You brought it up in the first place with a twisted definition.
> You brought it up in the first place with a twisted definition.
I did no such thing. You appear to be confusing idealism with the definition of encryption.
In any case we already have words for transport encryption, encryption at rest, and end to end encryption when referring to modes of encrypted data. Those are sufficient to cover the spectrum of encryption which exists. Calling encryption of one mode "unencrypted" which is not your ideal mode of encryption is disingenuous at best.
A better rain analogy would be someone saying 'I'd like to go for a smoke, is it raining', and you reply 'yes' because there is somewhere in the world where it is raining (just not there). You would be technically correct, but in the context of the question, the person was clearly interested in whether it was raining _there_.
Telegram is outright lying of course. I can't remember if WhatsApp uses E2E encryption by default still or not. If not they are equivalent, but telegram isn't better in any meaningful way.
Rather, this is more of a debate of what the layman expects, and frustration with misleading marketing. A great example of this is the whole Zoom debacle; they claimed it was encrypted, people assumed it was E2EE, and got a lot of blowback for that to the point that they ended up implementing E2EE.
Another great example: a few of my friends were using Telegram for a while, and thought it was E2EE until I pointed out that only their "Secret Chat" feature is E2EE.
And if the wording wasn't precise enough, context still matters more in this case. I'm sure everyone here knew what was meant, despite the familiarity with cryptography. Telegram claims your messages are "heavily encrypted" which is just false, aside from their very limited secret chat feature.
HN prefers substantive discussion, not nitpicking over semantics.
It is the only relevant one. Nobody who cares about protected messages would be satisfied with untrustworthy encryption.
Sure, technically even a messenger using Caesar cipher is encrypted, but most people expect more than a ticked checkbox. No real user cares about what technically still counts as encryption, just like nobody outside of biology cares whether walnuts are actually nuts.
By default nothing is E2E encrypted.
So yes, we can say it is mostly unencrypted.
Telegram has transport layer encryption, like literally everything else in 2022. For all intents and purposes telegram can read and access a majority of your conversations on it.
This isn't a super big deal because telegram is aiming to be a social media platform, rather than an encrypted comms platform, and e2ee on groups over a certain size is pretty useless.
I think telegram can still improve by making private messages e2ee by default.
Not literally everything. By and large everything, sure. Effectively everything, even. But not literally everything.
For instance, take a deep dive into how e2e encryption works in the Apple ecosystem…
https://support.apple.com/en-us/HT202303
… and why allowing iCloud Backups for usability becomes the weakest link for Apple Messages:
https://support.apple.com/en-au/guide/security/sec3cac31735/...
To save a click:
Messages in iCloud, which keeps a user’s entire message history updated and available on all devices, also uses CloudKit end-to-end encryption with a CloudKit service key protected by iCloud Keychain syncing. If the user has enabled iCloud Backup, the CloudKit service key used for the Messages in iCloud container is also backed up to iCloud to allow the user to recover their messages, even if they have lost access to iCloud Keychain and their trusted devices. This iCloud service key is rolled whenever the user turns off iCloud Backup.
If you are in this ecosystem, and feel your potential loss from disclosure is greater than your potential loss by losing/damaging your device, go turn off iCloud Backup — and make sure your keychain is secured to your needs.
Centralised or decentralised means little compared to a lack of encryption.
You can't give up that which you don't have access to.
“federated” = servers can talk to each other; eg email, xmpp, sip, activitypub
“decentralised” = data is replicated between servers; eg matrix rooms are replicated equally between the participating servers; usenet
“distributed” = data is replicated between p2p nodes; eg git, p2p matrix, bittorrent.
https://hongkongfp.com/2020/07/05/exclusive-telegram-to-temp...
The headline you linked makes it clear it was temporary. Which mean they do of course cooperate in normal situation. Otherwise they would be blocked everywhere, you cannot maintain a service such as a chat application without cooperating with governments.
There is no story here, Telegram shared information with BKA in cases of terrorism and child abuse, as every service operating in Germany would and should do.
It's just disabled by default, unavailable in group chats or channels, and enabling it reduces usability (i.e. you can't use multiple devices to chat if you enable E2EE).
Telegram as a chat app has the best UX of any chat app out there in my opinion, so the lack of proper E2EE is simply disappointing. I don't really trust either, but I consider WhatsApp more secure than Telegram, despite Meta mining my metadata.
Ha, I still prefer Telegram. I just use secret chats by default and enjoy the awesome UX
Is it? How would you go about confirming that?]
Why is that? With WhatsApp client being closed source, we simply don't know if it really is doing E2EE at all.
Why don't we know? Isn't it trivial to set up a MITM test setup and snuff the traffic and analize it?
Problem is that you don't know of the app is leaking your keys somewhere else.
https://oneandroid.net/whatsapp-will-read-your-last-5-messag...
It's not really about breaking e2e encryption but rather "reveal the identities of following users please". That could be due to all sorts of illegal activities (eg. hate speech, sale of banned substances, terrorism, child abuse, etc.)
> Since version 3.15.0 Signal for Android has supported reproducible builds.
https://github.com/signalapp/Signal-Android/blob/main/reprod...
I haven't tried to compare a local Android build to the published version myself, so can't directly confirm the accuracy of this document.
Either way, I agree that a released build can slip by unnoticed by most users. This is not a problem unique to Signal though.
At least with Signal you have the option to verify a build before updating. You can also build and run the entirely open source client yourself, which makes verification redundant.
Telegram probably figured if they don't at least share information on child abuse and terrorism, they'll just motivate regulatory action.
Why is that unfortunate? If I patronize a company, I want to be damn sure they are only giving up info to LEO when it's absolutely necessary.
The standards to turn over such information should not be decided by a private entity but by democratically enacted and enforced laws. Is enforcement of child porn prosecution "absolutely necessary"? Are death threats ok? Where's the line? I don't think a private company sitting in an unaccountable jurisdiction should make that decision. I trust German courts a lot more in that regard.
The uncomfortable truth is that if a communication method isn't secure for child molesters and terrorists, it isn't really secure for anyone.
And this concerns an area of crimes were the perpetrators don't very actively evade detection. There are other means to do so. And in the case of Germany, openly and publicly criticizing against the state is no problem as long as you don't propose to violently overthrow the state.
I'm not for total chaos. It's just that the world is a very complicated place.
Depending on tech companies to protect your data from authorities is a shitty strategy. At best it works the other way around. If not, you're screwed.
Does that include gas stations, supermarkets, utility companies, sporting goods stores, book stores, clothing stores? Each sells things that are used to aid in crimes. That doesn’t mean the government should spy on everybody who visits them
Of course they do and have been doing it for the longest time.
that's why they are forced to keep a record of what they sell and hand over that information upon request.
It's the authorities it's not some random dude passing by
Congrats, you're a criminal.
Is crime in Saudi Arabia anything that MBS doesn't like?
In the 30s and 40s in Germany, just being Jewish was a crime.
Whether you need modern or historical references, the problem is the same.
Don't do business in France? Russia? Saudi Arabia? China?
Are there any countries which have never changed the rules?
No, don't do business in Russia, Saudi Arabia or China, unless you plan on turning in your clients. Greed makes companies overlook these problems. They tend to eventually regret it, because they can't even make a decent profit when, for example, Russia does what it just did.
But this allows Telegram itself to see the content of the conversation when it arrives on their servers. This has piked the interest of LEA, who want continuous, real-time access to that information.
In a sense, yes. In case you don't speak German, the article [0] touches on this:
> Dass Telegram überhaupt Auskunft über Nutzer an Behörden erteilt, markiert zumindest eine vorsichtige Kehrtwende im Kurs des 2013 gegründeten Unternehmens. Lange bekamen deutsche Ermittler keinerlei Antworten, wenn sie wissen wollten, wer hinter Telegram-Konten steckt, die strafbare Inhalte im Netz verbreiten. Die Betreiber erklären auf ihrer Seite weiterhin: »Bis zum heutigen Tag haben wir 0 Byte Nutzerdaten an Dritte weitergegeben, einschließlich aller Regierungen.«
In a nutshell, this is considered a turning point because Telegram's official stance is (even today) that they don't share data, not even with any government. And now they did, apparently. So yes, this definitely news, if not a bit surprising.
The German government has even made hints that they will seek to ban Telegram from app stores if they continue to refuse to comply with law enforcement [1]
[0] https://www.spiegel.de/netzwelt/apps/telegram-gibt-nutzerdat...
[1] https://www.spiegel.de/netzwelt/netzpolitik/faeser-will-tele...
If you care about your privacy the "official stance" alone is close to worthless. That includes governments and corporations as well. I think we already learned that. Just like on security you need in defense in depth on privacy(i.e. hardware, software, and "official policy" as well).
... doesn't really matter.
This is something I find surprisingly difficult to get through to people at both a personal and professional level (as I often work in security-related projects).
People speak of whether they trust this or that entity. Reality is that it's an irrelevant discussion. Trusting an organization is always misplaced, no matter who they are. If you hand over data to an organization, you must immediately assume that data is compromised. Yes, that's all SaaS and all cloud providers, for example. Any party who could see the data in unencryted form, you need to assume they have it and can potentially at some point abuse it.
This has nothing to do with the ethics of whoever is running the given organization at the moment. There are many points in time in various organizations where they truly protect the data. I thank you. But it's not a stable situation. Things can change. Less ethical management can come in during a reorg and suddenly everything is fair game and the consumer won't know until it is too late. And always there is the threat of governments demanding the data, at which point no matter how ethical the organization may be, nothing matters since there is nothing they can do.
For any data that could at any level be potentially sensitive, you must make sure it is either not sent through third parties at all, or be encrypted with keys that only you control. Otherwise, assume it is compromised and sold to every bidder.
I don’t see how these are connected. All messengers will hand over all metadata they have to comply. The chatgroups in focus themselves are mostly public groups, you don’t have to play james bond to read what’s there. LEAs are arriving to the scene from that vector, not the other way round. “The NGO CeMAS monitors 3,000 German-language channels & groups for "disinformation, antisemitism, and right-wing extremism." - it’s literally in the tweet, man.
Metadata logging is unrelated to encryption, not sure what’s the sensation is without comparing what messengers will actually have on hands in case of a warrant, minus publicly accessible info.
Especially the case of Telegram was quite simple, since SEC filed a complaint we could clearly see who are the main investors. It's not necessarily about the country or investors either.
You can choose only the place where things are stored and expect the company to act according to local laws (for e.g. Protonmail doing its proton things in Swiss judiciary).
And, I guess, a thing we have to teach people is something vague and unclear like post-privacy scene, like how one has to operate knowing that pigeon mails can always be spoofed, no matter how encrypted the conversation is.
don't use chats
meet in person
like all respectable criminals do
Anyway it would still mean that you're being investigated for something and the court authorized the request
Now imagine what would happen if US law enforcement got hands on the chats of the Texas shooter.
Truth is they didn't do anything even though he posted publicly about what he was going to do.
https://www.cbsnews.com/live-updates/texas-school-shooting-u...
So maybe the idea that anyone is spied and controlled by law enforcement or governments is not exactly true.
They collect everything, illegally and without any ethics.
Then they’re incompetent as well, so action doesn’t happen when it should.
Instead we get capricious, haphazard enforcement, and a dark future with all of this stored in permanent record to be retrieved using the search tools of 2040 and weaponized later when we later make nuisances of ourselves in response to future legislation.
https://telegram.org/faq#q-do-you-process-data-requests
>To this day, we have disclosed 0 bytes of user data to third parties, including governments.
Such a weird way of saying they haven't disclosed data. They might say they disclosed the data by writing the user's details on a piece of paper and submitting that to the government.
Telegram says with the E2E chats they had no data to share, but that only refers to the content of the chats, obviously not the IP address or the linked phone number, which Telegram says it can also share with governments. When they mention later in the paragraph that they didn't share any data from unencrypted chats, that's with the caveat.
That Telegram has shared _more_ than just metadata I think is unlikely.
For example, https://www.apple.com/legal/transparency/ Germany is at 11+k while the UK which is of similar size is at 2+k
As I said, the US can stop you from making such disclosures and they do, which we know because some such embargoes have ended in individual cases. We have no idea how many are still in place.
Quite simply saying "We have no idea how many are still in place" actually, we have an idea. That idea is not many. It's simply FUD to talk about the US' ability to stop disclosures when talking about who is making the most requests. Especially when the US is still pretty near the top for countries making requests.
You can believe that if you want, but I'm not remotely convinced. We consistently find that the US spies and abuses its power more than anyone imagines. By induction, unless anything profound changes, I'll bet on that trend continuing.
Spies, not law enforcement. Spies spy. It's kinda in their job description.
For example you can deny the Holocaust among a small circle of friends, and that would not be "public".
And it's extremely hard to get anything of the sort prosecuted on the internet. See "tatütata.fail".
EDIT: The comment below phrases it even better.
A quick glance at https://en.wikipedia.org/wiki/Legality_of_Holocaust_denial suggests that you may have made up the public advocacy requirement:
> (3) Whosoever publicly or in a meeting approves of, denies or downplays an act committed under the rule of National Socialism of the kind indicated in section 6 (1) of the Code of International Criminal Law, in a manner capable of disturbing the public peace shall be liable to imprisonment not exceeding five years or a fine.[36][37]
Of course the distinction you are trying to draw smacks of sophistry to begin with. From what I can tell, you can be anti-islamic in your own four walls and even discuss your secular ideals with your friends in Pakistan, beacon of free speech, as well[1].
[1] As long as you don't defile the name of a prophet. That seems to carry a mandatory death sentence (plus fine, to really rub it in), even if it occurs within your own walls.
I wonder why so many free-speech advocates are hell-bent on enabling fascists to spread their propaganda. They are certainly not the first but not the last group they will drag to their camps or shoot.
To compare this kind of law to fundamentalist religious law is a special kind of ignorant.
Do you also wonder why so many cryptography advocates are hell-bent on enabling not just fascists but also pedophiles and terrorists to plan and commit their crimes or are your difficulties of comprehension more selective?
> To compare this kind of law to fundamentalist religious law is a special kind of ignorant.
Pakistan (unlike, say, Saudi Arabia) has constitutionally enshrined freedom of expression. Can you point to some fundamental difference that makes the restrictions Pakistan places on this right incomparable to those Germany places on it?
Cursing someone or insulting someone online (calling an idiot) you can end up in jail for 2 years.
I am not supporting that kind of law or anything as I have no skin in the game :).
You’re right; in Germany, insult is illegal. I’m reading about it, and articles say that the majority of minor insults are not reported, and that generally insult claims are dismissed (for example https://www.latimes.com/world/europe/la-fg-germany-insult-la...) Nazism and Holocaust denial are also illegal, and for pretty good reasons. Since the OP’s comment didn’t mention insulting people, but simply having opinions and discussing them, perhaps this is what they’re referring to? That might be the only subject that is taboo without qualification, the rest of them (such as blasphemy) appear to hinge on whether it could affect the safety of people?
https://en.wikipedia.org/wiki/Censorship_in_the_Federal_Repu...
The US has similar restrictions, most of them for similar reasons.
https://en.wikipedia.org/wiki/United_States_free_speech_exce...
Watching Bill Maher first time was a eye opener for me on free speech. I couldn't imagine anyone doing it in my own country.
Probably OP is referring to Nazi stuff. But people do get fined for showing birdie at protests. Even though most are dismissed the process of going through the system is the punishment if you have no legal insurance.
All in all, I agree Germany is not a restrictive society and has honours tenets of free speech. But i won't compare it to USA. Which is light years ahead.
In Germany, there is Meinungfreiheit, which is freedom of opinion. This freedom cannot override others rights tho. So your right to an opinion may not infringe on someone else. For example, you can't insult others in a way that dehumanes them. However, you can insult people just not in a way that dehumanes them. A German court found an employer couldn't fire an employee just because they called them an autistic asshole in a text message. The employee was entitled to his opinion that the employer was an autistic asshole. It did not dehuman the employer because it was done privately and did not interfer with the operation of the business. So in Germany, private companies are not allowed to breach your rights, unlike in the US where it only applies to the goverment.
> DHS Authorities Are Buying Moment-By-Moment Geolocation Cellphone Data To Track People
> The Department of Homeland Security also argues that using the information is perfectly legal and that the agency does not need a warrant to purchase it, according to a memo obtained exclusively by BuzzFeed News.
https://www.buzzfeednews.com/article/hamedaleaziz/ice-dhs-ce...
> Intelligence Analysts Use U.S. Smartphone Location Data Without Warrants, Memo Says
> The disclosure comes amid growing legislative scrutiny of how the government uses commercially available location records.
https://www.nytimes.com/2021/01/22/us/politics/dia-surveilla...
A company can say "we don't share with the government" but if you get served a warrant (or subpoena?) telling them to provide X data, you don't simply get to say "no". You /could/ send your lawyer to a courthouse and have them argue the warrant/whatever is unlawful, or what have you, but if the court says it's valid then failing to comply is a unlawful.
The only way you can not provide data to law enforcement is if you never have it. But companies want data for all sorts of reasons. My assumption would be that even if you say "we don't keep data" you could be served documents telling you to store that data.
Of course IANAL, but this is all basic "function in a society" stuff.
And I was just starting to get traction in terms of bringing my network over from Whatssap. And that is huge as it was almost impossible before. Has been a sea change for me over the last year or two.
So groups and channels that were already public in the first case... No private chat data, no backdoors? I'm fine with that.
But it would be easy for Telegram to just hand out the telephone number, and in the majority of cases, the number would be registered to the offender. We're mostly talking about unsophisticated offenders here, people agitating for hate, neonazis, unsophisticated child abusers...
I personally find mass dragnet-like unsupervised surveillance extremely worrying especially in the US where federal authorities like to abuse gag orders. But that’s not what we are talking about here. In this case we are speaking about judicially supervised data gathering in the context of an ongoing investigation. I have no issue with this as long as there is proper limits and supervisions in place.
Depends on the laws they are enforcing. There is a very thin line between law enforcement and outright spying and authoritarian opression.
So they claim that Telegram cooperates... and then claim it does not cooperate. This is ridiculously vague.
Not to mention that the article doesn't clear up if it's data or metadata. Weird, poor journalism.
The operators of the messenger app Telegram have handed over user data to the Federal Criminal Police Office (BKA) in several cases - contrary to what has been publicly reported so far. According to SPIEGEL information, this involved data on suspects in the areas of child abuse and terrorism. In the case of violations of other criminal offences, it is still difficult for German investigators to obtain information from Telegram, according to security circles.
(Translated with www.DeepL.com)
This might be a 'germanism'. The article says 'according to SPIEGEL information' which translates to 'according to undisclosed sources that gave us information'
> cooperating and not cooperating
Recently there was a huge controversy about Telegram in Germany about them not disclosing personal information about accounts spreading illegal information according to German law. There were claims about banning Telegram in Germany, but after pressuring the app stores, Telegram seems to have given in slightly. So they are still not disclosing as much information as the authorities want them to, but it seems like they started to cooperate a bit.
>data or metadata
'Nutzerdaten' in my understanding means mostly personal Data(real name, ip, address) but you are right, it is quite vague.
> on suspects in the areas of child abuse and terrorism. In the case of violations of other criminal offenses, it remains difficult for German investigators to obtain information from Telegram, according to security circles.
So Telegram is not giving free access or follows German law, but did help out in some specific cases.
Telegram claims otherwise and says it never responded to requests.
Yes, they are protecting their source(s), so you have to take them on faith. Der Spiegel has, however, an excellent reputation and good track record.
Or you can spread FUD on the internet…
You can see that by reverse engineering the binary.
Typically it’s a combination of decompiling and traffic analysis.
E2EE only means stuff if you have a baseline of trust for the app developer.
— Commonly attributed to H. L. Mencken (1880-1956)
There has to be a balance, or at least recognition that encryption leads to situations never before possible.