Indian government bans 14 messenger apps including Element, Briar and Threema
news.abplive.com
news.abplive.com
If anyone reading this works at Google or has a contact there, please put us in touch (contact@briarproject.org). We'd love to know whether Google has received a blocking order, and if possible get a copy of the order so we can challenge it in court.
In the meantime, the app remains available from our website and F-Droid (https://briarproject.org/download). The app can also create a wi-fi hotspot to share the APK with people nearby.
Such bans are deliberate attacks targeting (parts of) the general population. Terrorists have nothing to do with this.
"Hahaha those stupid bureaucrats, they have no idea what they are doing" is a popular meme, but it couldn't be further from the truth. They do know what they are doing, and it's working. If you believe it isn't, that's only because you misunderstand what the real goal is.
https://telecom.economictimes.indiatimes.com/news/dangerous-...
Besides Pegasus and such and the interception issues with SMS, might be as well due to HUMINT and the weaknesses in verifying fingerprints.
Probably it would be best for people in some of these countries to do their work offline.
Criminals, terrorists, dissidents, politicians, even intelligence people sometimes... they're users. Just because they can sideload, or otherwise use more sophisticated methods doesn't mean they will. The margins are wide.
Imo, same thing is happening in India as is happening in most places with an active security-intelligence service. They receive valuable intelligence from PMs. Then they fret about potentially losing access or want to increase access.
If you read HN/Reddit/Twitter, you'd get the impression that all this stuff is fake. It's not. Intelligence agencies in 2023 are all about these sources, and jelously guard them. Once they have a source, they're not giving it up willingly.
Let's not forget people died there.
You can actually use VPN. But what if the vpn services also get blocked?
While achieving 100% of a blockage is not possible but achieving even a 30% is great.
many don't because terrorists in reality don't tend to be very smart. And if they do, its not that difficult to trick them and compromise that channel aswell (https://www.washingtonpost.com/world/2021/06/08/fbi-app-arre...)
The amount of people who get caught on insecure communication, including some famous tech CEOs, is staggering. Most people, criminal or not, are completely security/tech illiterate. Changing the default has a huge impact. Webs in these investigations tend to be wide so it's not just about literal criminals, if one suspect leaks info to anyone that may be enough for authorities to catch on, it's a statistical game basically and the harder you make it to not mess up the higher your chance to catch someone.
Gentle reminder that the US intelligence leaker was caught because he distributed the material on a gaming discord on an account with user info that was one Google search away from his father's instagram and steam profile. And that guy was US National Guard tech support staff.
That is, anything that's easy enough to detect in the traffic, I suppose? Or does it just affect App Store / Play Store?
> The step was taken after multiple agencies found that these apps were being used by terrorists to communicate with their supporters and on-ground workers
I wonder if it applies to members of general public, or to trained agents. For the former, the ban may work. For the latter, I suppose, there's less chance: they must have other means to install apps, various VPNs set up, and some opsec training.
> The government found that these apps did not have representatives in India and they could not be contacted for seeking information as mandated by Indian laws.
This, of course, should be by design for any really secure communication app. A legal entity representing a secure channel is a people to press on in cases like that, ans such pressure from law enforcement is and will be inevitable. I think Tor network has no legal representative anywhere.
No, this is because they have good security/privacy and don't allow the Indian government to control.
If internet operators have no means to stop these protocols, then the ban is unlikely to have any real effect beside some inconvenience.
I mean, those are legal issues. The point is they're banning them and if you use them you go against the law.
The concept that governments will love to push for is where citizens need to provide identification for accessing all web services and all web activity is linked to their identification. Digital infrastructure these days is sophisticated enough to handle this and it only takes for one country to enact this and get the ball rolling for everyone else.
This is why systems of checks and balances were invented, separation of powers, press freedoms, the democracy itself: these are systems that actively prevent the government from grabbing more and more power, just because it can.
When the government is able to suppress or diminish the influence of these counterbalances, usually on the grounds of enforcing security and safety of the citizens, the process can escalate and end up in an authoritarian rule.
Such (attempts at) power grabs will always happen, and will.always need a push back. It's a dynamic balance, when a balance can be achieved at all.
It's supposed to work in case the infrastructures are down by design.
So it can also work locally, meaning 2 Briar users can meet, and share messages from 1000 other users, and go on their way to propagate the update, without going trough the internet.
Now of course you can always enforce the ban, not through blocking, but through detection and punishment. However I doubt you want to spend that much resources for a single app.
Any client side ban can be easily circumvented with sideloading and network-level ban with a VPN (or less easily, TOR)
I’m sure in some cases these bans are indeed a feint but not everything is a game of 4d chess. I mean, look at the TSA in the US
For a high profile app like Signal (which more than just the Indian government cares about) I assume there are security vendors or US intelligence solutions to get access. I mean, for one, the US government and EU can make Google and Apple do anything by showing up to their offices with guns. It’s also a high value target for whatever you call those security firms that sell exploits to nationstates.
For intelligence purposes you’d rather centralize targets on a small number of platforms that they think are safe and not give them a reason to leave, rather than have them be fragmented across many platforms which each require some kind of backdoor/additional work to get access to.
I guess I’m getting downvoted for insinuating Signal has a backdoor without evidence, but an iOS or Android level exploit or backdoor would easily function as a signal backdoor, and depending on its implementation (like peaking at process memory) could be hard to get working for each and every random app. There’s also the risk of an app store itself adding a backdoor or a Signal insider sneakily creating one to sell the exploit. These all seem highly possible given the various NSO exploits that have hit the news.
So we aren’t always talking about comic book-style super villains here.
As per the source, the GoI has banned a total of 14 apps and they are as follows:
Crypviser
Enigma
Safeswiss
Wickrme
Mediafire
Briar
BChat
Nandbox
Conion
IMO
Element
Second line
Zangi
Threema
From : https://www.mysmartprice.com/gear/full-list-of-14-messenger-...1. Briar (decentralised encrypted chat app): https://briarproject.org
2. Crypviser (decentralised encrypted chat app): https://crypviser.network
3. Enigma (encrypted chat app): https://enigma.im/en/
4. Safeswiss (encrypted chat app): https://www.safeswiss.com
5. Wickr Me (discontinued encrypted chat app): https://wickr.com/me/
6. Mediafire (file hosting website): https://www.mediafire.com
7. BChat (decentralised encrypted chat app): https://bchat.beldex.io
8. Nandbox (unencrypted video/voice chat app): https://nandbox.com
9. Conion (encrypted chat app): https://play.google.com/store/apps/details?id=com.secapp.tor...
10. IMO (unencrypted video/voice chat app): https://imo.im
11. Element (encrypted chat app): https://element.io
12. 2nd Line (unencrypted VoIP app): https://www.2ndline.co
13. Zangi (encrypted chat app): https://zangi.com
14. Threema (encrypted chat app): https://threema.ch/en
Source: https://qz.com/india-has-blocked-14-messenger-apps-on-securi...
Are these more popular outside the US? Maybe I’m just out of touch? It looks like you asked ChatGPT to generate a bunch of fake app names.
Should we just do encrypted SMS at this point lol
I don't think that TLS to port 443 can draw too much attention, too.
element.io is working on Jio fiber here in j&K.
AMA
https://www.hrw.org/news/2022/12/23/india-data-protection-bi...
When a story does have political overlap, it's incumbent on commenters to stay within the site guidelines regardless of how strongly they feel, or how wrong they feel other people are. This is in the site guidelines: "Comments should get more thoughtful and substantive, not less, as a topic gets more divisive." That's not easy, but it's possible. For this forum to succeed at its mandate, we all have to work hard at it.
What people call "acknowledging blatant truths" can mean a lot of different things depending on their passions about a topic. It's hard to perceive one's own expressions objectively. Even the users who post the worst flamebait typically feel like they're simply stating the truth in a straightforward way.
There are ways of acknowledging truths that are more likely to lead to flamewar, and other ways that are less likely to lead to flamewar. We need commenters here to do the latter, not the former. That's an ongoing process that takes a conscious effort, at least when one's emotions are engaged, and people need to do this regardless of how right they are or feel they are.
Many apps in this list are also highly vulnerable. Threema, for example, was found to have serious security vulnerabilities due to rolling its own crypto implementations.
It is interesting to note that Signal, WhatsApp, iMessage and soon Twitter DMs – all of which claim to have E2E encryption – are not on this list.
Does that mean these companies have a way to break encryption and provide access to government when they ask for it? I suspect metadata is definitely accessible via these companies.
Interestingly these are all messengers that have mobile phone numbers as primary user handles whereas a lot of the banned messengers are not. So, its possible that there are phone number based zero-click exploits for these popular apps that governments across the world use (remember NSO?) whereas not for less popular apps.
The article says that the apps that were banned provided anonymity.
There is no way for the companies to break the encryption on their servers without compromising the client first.
We are talking about private, for-profit companies running closed-source service with closed-source client and with TLS-key-pinned client-server RPCs. And we are talking about closed-source phones running closed-source hardware, firmware, OS, and platform services. Even if the app was open-source (like Signal) there are plenty of injection points to do the above at the lower-levels.
However, I doubt that a private company whose business model was end to end encryption would secretly bake a back door into every client by default.
Any exposure of this by reverse engineering or whistle blowing would end the business. Why would a private company work against their own interests in that way?
I could imagine that specific clients got special back doored versions under some kind of secret court order, but I'm not sure what the delivery mechanism would be for that.
Edit: your final point that you could compromise a device independently of the app itself seems much more likely to me. Tools to do this exist and have been provided to governments.