The Arrest of Pavel Durov Is a Reminder That Telegram Is Not Encrypted
gizmodo.com
gizmodo.com
A small section of Russian students were floored, and responded that they thought Telegram was banned in the country at the time (circa 2017-2018). The state officials laughed and responded that it wasn't any concern because they could read everything in any chat they wanted.
I've avoided the app ever since. I can't say how, why, or when the app became compromised, but anecdotally, I was told that it was and that it was no longer a concern in Russia.
Maybe it was some dry joke, maybe those students were woefully misinformed, who knows. But it certainly broke any confidence I had in the security of any existing messaging app.
I personally use Signal, but that's mostly just because I have personal friends who use it and it's convenient to use on my PC.
Edit: Kinda funny, I only just logged into this site again, and some of my last previous comments were about the same thing.
Telegram (like everyone else) has a great, responsive web client.
What's even more frustrating is that Signals desktop app is just an electron app, meaning it's generally designed for the browser.
1. Enable backups. 2. Point it at a folder on your phone which gets synchronized somewhere 3. Note the 30 digit passphrase in your password manager.
https://support.signal.org/hc/en-us/articles/360007059752-Ba...
Have had no issue restoring to replacement phones.
Also, Facebook Messenger recently added e2ee, which made it glitchier, fussier, and not really any more secure given that the key is a short numeric code.
Here’s a couple of solutions, Signal:
1. Generate a long paper key that can be stored in a password manager. Use iCloud to store an encrypted backup.
2. iCloud now has optional e2ee. Let me just say my threat model trusts that e2ee and use iCloud directly.
If Isolated Web Apps (IWAs) take off, it may become an option.
The Russian state stopped blocking Telegram after the state investments in the platform, that tells you everything you need to know about its security and the deals they must have made with the Kremlin.
If something isn't blocked in Russia right now, it's because they have access to it.
Where are you getting this from? Russia has seen Telegram as an enemy since day 0, and probably had to lift their block because it didn't work at any point, Telegram was available in the country the entire time.
Have these "state investments" been reported on by some reputable organizations?
So WhatsApp is also controlled by Russia?
2. They can dox and eliminate any real threat if they can monitor the most popular communication tool
According to many sources, Telegram is a vital communication tool of the Russian military in the war with Ukraine. If that's true, then there can be only two primary interpretations: 1. Russian gov is astoundingly incompetent 2. They are able to monitor Telegram
> If that's true, then there can be only two primary interpretations
There is a third possible explanation:
3. This particular war is full of misinformation and lies from both sides. Telegram can be used as a tool to spread your disinfo, masking it as truth.
I really doubt that russian military uses Telegram to coordinate anything, and if they do - it could be rare cases where soldiers haven't gone through any special training. But I can see how Telegram can be used to share other non-vital data. If it's true, then surely it's not incentive from above, but initiative from below.
You should keep in mind that it's not professional specialists on the battlefield, but mostly people who've been regular citizens just a few years ago.
> Telegram can be used as a tool to spread your disinfo, masking it as truth.
So can TV, newspapers, local websites, etc etc. And yet we know what happened to all Russian media that tried to spread messages contradicting the official position. I don't believe Russian gov (or Soviet for that matter) is confident enough to allow dissenting opinions to be spread on such a massive scale without a high degree of influence and/or monitoring.
I know usually the burden of proof is on the side of the conspiracists, but in this case I am not taking any chances. If it's a Russian company that is widely used by the Russian ideological state apparatus, I have zero trust in whatever their encryption promises are.
This is the gist of it. Telegram is mostly like an uncensored blog platform at this point. Probably the only platform to host official channels of Navalny, Zelenski, Dmitry Medvedev, Russian and Ukrainian milbloggers at the same time.
And for public channels, E2E is pointless - everyone can see it anyway.
But until someone actually published any hard evidence demonstrating weaknesses (ideally with a PoC), do we have anything else to go by?
I wouldn't say I know for sure Telegram is 100% secure against government interception, but I also wouldn't claim the opposite, because neither ends/claims have been demonstrated and proven in a verifiably way.
Here you go:
I think you might confuse what the mud puddle test aims to demonstrate. It's to be able to confirm E2E encryption, which if you do that test with Telegram + Secret Chats (which is the E2E encryption feature in Telegram), you'll see you cannot recover those messages.
It depends on what you mean by "as a whole". I mean that Telegram by default can read all your private chats, unless you manually enabled e2ee and suffer from related bad UX. On Linux desktop (and phones) it doesn't even allow to enable e2ee at all.
There's "New secret chat" option on my Android client. Or what do you mean by "phones" here?
Yes, this is the expectation. You use someone else's platform that doesn't have E2E, you assume they can read your messages and will help law enforcement to do the same. No surprise there.
Doesn't mean their E2E feature isn't secure, or that the platform as a whole isn't secure. Facebook surely shares their Facebook + Whatsapp data with US law enforcement, we wouldn't call Facebook/Whatsapp insecure just because of that.
I and many others certainly would.
I mean, if nothing else, that's a bad default. This makes it worse than, say, WhatsApp or the apple messaging thing, nevermind the likes of Matrix or Signal.
The weakness is that e2e encryption is disabled by default, and is a giant pain to enable.
E2E is only for Secret Chats, yes. And yeah, I don't think people use Secret Chats by default.
> and is a giant pain to enable.
Starting a Secret Chat takes one more tap than starting a normal chat.
Hmm, the article says this:
>As John Hopkins security researcher Matthew Green pointed out in his blog on the subject, it’s also a pain in the ass to activate. “The button that activates Telegram’s encryption feature is not visible from the main conversation pane, or from the home screen. To find it in the iOS app, I had to click at least four times—once to access the user’s profile, once to make a hidden menu pop up showing me the options, and a final time to ‘confirm’ that I wanted to use encryption. And even after this, I was not able to actually have an encrypted conversation, since Secret Chats only works if your conversation partner happens to be online when you do this,” Green said.
Telegram doesn't even claim to have end-to-end encryption by default (you have to enable it explicitly on a per-chat basis), and doesn't have it at all for group chats. Like, unless they are lying and secretly _do_ have e2e by default, it is clearly worse than many alternatives from this pov.
It's kind of weird that it has come to be known as a secure messenger, but it certainly isn't.
The security researcher cited in the article used a different flow by going to an existing contact's profile first and opening the hamburger menu there, and claimed the feature is "hidden" because of that (the hamburger menu), when in fact it isn't. Maybe it's different on iOS though, I don't know.
Try to do it on a desktop Linux. There is no such option.
I am using it on Matrix just fine.
WhatsApp made E2E the default only in 2016, i.e. 7 years after it was founded. Telegram is 11. The whole thing reminds me of http vs. https. Chrome started marking http as "Not Secure" only in 2018. I remember at some point the wisdom was that using http is OK as long as you don't use it to access your bank account etc. So https was like an opt-in ("if you want additional security"). But now it's the default. Telegram resists making E2E the default reportedly for UX reasons (easier data sync on multiple devices).
The main page says Telegram is "secure" without elaborating, though. I can see people can be misled, but they're not lied to.
Their website also used to say that they are forever free, no ads, and that they were going to open source all their code, including the server code. Now they have a free tier, but even they couldn't call it "forever free" anymore. I wouldn't trust anything they write there =)
Aside from that, I don't trust Telegram or its CEO at all, partially because of what you said about open-sourcing (or not) and partially because of his ties to Russia and Azerbaijan.
Shouldn't it at least provide some guarantee that what you receive is what was sent?
And then there is even stuff like OMEMO, which is E2E, but intentionally does not do authentication of messages, quite the opposite: It's protocol is designed such that you can always deny having sent such a message...
See also this excellent comment by another HN user: https://news.ycombinator.com/item?id=41348228
One of the links shared by the comment you're linking to points to a paper which concludes:
> We have presented the formalisation of the MTProto 2.0 protocol suite in the applied π-calculus, and its analysis using the protocol verifier ProVerif. This approach adopts the symbolic Dolev-Yao threat model: an active intruder can intercept, modify, forward, drop, replay or reflect any message. Within this model, we have provided a fully automated proof of the soundness of MTProto 2.0’s protocols for first authentication, normal chat, end-to-end encrypted chat, and rekeying mechanisms with respect to several security properties, including authentication, integrity, secrecy and perfect forward secrecy, also in the presence of malicious servers and clients. Moreover, we have discovered that the rekeying protocol is vulnerable to a theoretical unknown key-share (UKS) attack [ 5 ]: a malicious client B, with the help of another client E, can induce a client A to believe that she (still) shares a secret key with E, and instead A shares the key with B. The practical exploitability of this attack in actual implementations is still to be investigated. Our formalization covers also the behaviour of the users, when relevant; e.g., if the users do not check the fingerprints of their shared keys, a MitM attack is possible.
Which is completely besides the point when the question is "should you trust Telegram", given that they are still entirely under Telegram's logical control.
The only circumstance under which this is a meaningful difference is when somebody other than Telegram (law enforcement with a warrant, law enforcement without a warrant, criminals etc.) walks into a data center and pulls those servers' hard disks.
(Assuming the user has the default setting of no 2FA.)
There are probably more ways to get to the data.
Splitting keys in different jurisdictions seems like security theater.
They claim it only covers transport and not data at rest.
>"possible vector for child sex abuse material"
>"hub for various scams and crimes—but"
What is it? Setting up a mood to make sure people feel that Durov / Telegram are bad? This is anything but even a try to objective journalism. Whoever the author is - fuck you.
Well, let me rephrase it then. I respect author's right to express the opinion. Still "fuck said opinion". It reeks.
How can anyone think a damn picture on an Android/iOS/* phone could be considered private? People have Google Photos/iCloud auto-backups and do care about "the privacy of a messaging app"?
Beside that I do consider this arrests much less meaningful than most current press, yes it's a debatable act, but so far Telegram works in France, there is no state-enforced block, in user base size terms it's hardly be considered a significant hostile political/social actor, and actually the government is doing MUCH bigger things against the République and Democracy at a whole than arresting the funder of a messaging services based in Dubai...
But the traffic between you and the Telegram server is always encrypted and the "end-to-end encryption" can be enabled.
It's all great, also arguments a generation old.
Maybe I should add 'literate' on my resume too...
Telegram really has kind of pulled off a masterstroke in marketing by convincing people that it is e2e encrypted (honestly, as a non-user I assumed that its non-group messaging was until the current fuss), while not being, even where it would be easy to be (non-group stuff). One might reasonably question their motives there.
Most end to end capable systems degrade to trusting the provider when the user fails to verify the identity of their correspondent using some ridiculously long number. In other words, the user has to take an assertive action to become fully end to end where only the end users are trusted. Just like with Telegram secret chats. You can't just claim that such systems are not encrypted. Things are more subtle.
The headline here ("Telegram Is Not Encrypted") is misleading...
To an audience of laypersons, it's definitely much more accurate than saying "Telegram is encrypted".
Maybe a better way of phrasing it would be "Telegram can read your messages if they choose to, or if anybody is able to force them".
Exactly. I.e: Telegram is not encrypted.
It is an outrage machine: very useful for "divide & conquer" type of governance
The fact that they did all of that is precisely the reason why you'll find so many cryptographers and privacy advocates being very critical of it.
That is a strong, wrong, statement
For one thing, although I have my quibbles about the standard of journalism at The Guardian, I do not think for a micro second they are beholden to "war profiteers".
- Fourniture de prestations de cryptologie
visant à assurer des fonctions de
confidentialité sans déclaration conforme,
Providing cryptography services with
an eye to ensure confidentiality
features without a compliance
declaration. (Translation mine.)
- Fourniture d'un moyen de cryptologie
n'assurant pas exclusivement des
fonctions d'authentification ou de
contrôle d'intégrité sans déclaration
préalable,
Providing a cryptographic method
non-exclusively ensuring authentication
and integrity features w/o prior
declaration. (Translation mine.)
- Importation d'un moyen de cryptologie
n'assurant pas exclusivement des
fonctions d'authentification ou de
contrôle d'intégrité sans déclaration
préalable.
Same, but regarding import controls.
The first item implies that you're not allowed to provide others with software/services that provides confidentiality protection without registration -- without a statement that you comply with legal requirements!Presumably the compliance declaration is subject to prosecution for perjury or similar charges if they can twist the legal requirements after your registration.
The second item implies that you're not allowed to provide others even with something as innocuous as authentication and integrity protection software/services without first registering your intent to do so!!
In the context of the cryptowars of the 90s, and in the context of web browsers, all of this is just pure nonsense.
Where are the prosecutions of Mozilla, Google, and Apple (and Brave, and Opera, and...) for distributing browsers which all provide confidentiality services? Or did they all get approval from the French government?
> Or did they all get approval from the French government?
Presumably, since it seems to largely be a formality at this point.
I'm also very disappointed to see it being used in this case, since otherwise nothing in these charges is about cryptography.
2. A big reason why he got arrested is because there was evidence of illegal activity happening, and authorities submitted request for information, and he refused. Companies like Meta will 100% comply with legal requests for information about illegal activity on their platform.
3. You cannot have a decentralized system that "gives the power to the people" if you still have central servers where information is stored or goes through.
Every operating system now phones home and uploads copious event logs. Many users install custom "swipe" keyboards, ad blockers, toolbars, and even bios chips are now programmable.
There are just so many vectors and exfiltration paths, plus it's not enough for you to secure them all. The person you are talking to must also.
Often encrypted messaging gives a false sense of security. Messages can still be intercepted on either end, and an automatic app update is sufficient to silently disable the encryption without the user knowing.
edit: Since it seems that some are considering this baseless fear-mongering, here's just one recent example:
https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zer...
> Every operating system now phones home and uploads copious event logs.
There is nothing about telegram in there.
For awhile Canonical had a deal with Amazon that was highly questionable. https://www.gnu.org/philosophy/ubuntu-spyware.en.html
The most dangerous however is the auto-updates. Even if the software is safe today, how do you know what tomorrow's auto-update will bring?
The dude you just shook hand with might have had a glove and stole your finger prints. The post employee you just gave your check to mail might be a impostor. The guy you're about to meet from craigslist might steal your iPhone and cut your thumb to access your entire digital life.
Ah but no, you're an average Joe and nobody gives a flying fuck about any of these.
Even if the software is totally open-source: unless you also made the hardware: it doesn't matter, unless you compiled all of it (and at that point probably wrote the compiler yourself as well as the os you're using) and installed yourself: it doesn't matter, unless you actually went though every single line of code and checked for yourself that every thing is safe (which you cannot): it doesn't matter
but in seriousness, it doesn't need to be the OS itself of course, just any software that runs on the OS
Not Encrypted (x)
Not "Fully" Encrypted (o)
Of course telegram is actually encrypted, but just not end to end. Except the secret chat function which is very limited (only works between 2 participants, only between 2 devices and everyone needs to be online at the same time for the key exchange to work).
You could also maintain an index locally.
Why would I want to maintain a local index? How much of my compute and storage will it take? How well will it work across all my devices and clients (I have 3 clients just on my phone)? I personally am a part of over 700 conversions, some having millions of messages, and many of which I rarely interact with, but when I do, I know I have easy, instant access. It sounds highly inconvenient that I should have to constantly maintain any of that for the few times I may want to dive in to check on something and get out again. Might as well those conversations never existed in the first place.
And of course these considerations aren't just for me, but the nearly 1 billion users of the platform.
I am US based and have a US passport. I wonder if I would have to respond to police inquiries. When is this enough, and when would I need a court order? And do I have to respond to foreign police inquiries. Demand a court order? And accept one from France, what is next? Russia? China? North Korea?
I think in the end it was his French Passport that killed him. Now there are not so many options for him:
He can help with providing a kind of key, backdoor whatever and can walk or gets a small sentence. I thought Telegram is encrypted and if done, in the right way, he could not provide help at all, but this seems not the case. The other option is that he asks for help from Russia. I am sure Putin could get him out in 1-2 years. Trust me, Putin has his ways with this, see Vadim Krasikov. :-)
Let's hope he plays his cards wisely. Good luck.
If that is part of your threat model IMO better to have good OpSec understanding and continuous training in compartmentalization. Ideally travel guidelines and dedicated devices.
Most journalists/activists don't even have that (sadly). So the argument to just use better Technology is a dud because no amount of tech can solve them from themselves.
(poorly) Paraphrasing Grugq:
> Good OpSec will get you through a time of compromised encryption better than good encryption gets you through a time of poor OpSec.
Software based encryption (not using HW backed) appeals if the threat-model needs to protect against the case where you think (or know) the hw might be broken e.g. in your given example AES. That claim might be true especially when you're trying to build a solid solution without control of the hardware or the underlying OS (like e2e mobile messengers trying). That would be a good reason to ditch HW based encryption.
But unless you fully trust the OS or the hardware, or your own ability to compartmentalize (which IMHO you should not), why put trust in an app running on top of all this compromised garbage :D
Of course the common easy to use solutions are all backdoored or worse.
There's a good talk on it here: https://media.ccc.de/v/37c3-11761-all_cops_are_broadcasting
I feel that this is a pretty good summary of what's going on: https://youtu.be/39rBzRd4M0k and explains how the encryption works etc.
Also, there are issues with Telegram's E2EE mode, besides it being disabled by default. More than enough reason not to use it.
They can eavedrop by simply adding a device to a conversation and nobody will notice. Your device will gladly send them decryption keys and provide them with a copy of the message nicely.
The simple bad scenario I have in mind is when you're initiating a new chat and the mitm it from the start. Or they could do it halfway through, which would notify you that the other end's key changed, but that message is non-threatening enough and happens enough for random other reasons that most people would probably ignore it.
Edit: Meant to say, the web client needs to somehow be authorized by the phone, not that it takes the privkey exactly. Probably gets a new key that the phone stores, so the phone is still the "master" device. I wouldn't expect the phone client to happily send the chat history to a new device it didn't authorize locally.
i'm happy to know more about that topic if you've got some documentation.
Maybe there's some key derivation mechanism so the new pubkey is self-evidently owned by the first one, never heard of one though.
https://tsf.telegram.org/manuals/e2ee-simple
My own distrust for Telegram aside, I like how these pages seem to be written by an engineer and not a PR person.
Message secrecy does rely on being able to authenticate the recipient's public key.
Saying telegram is based in Russia is like saying the pirate bay is based in Sweden. Used to be true, but not so much anymore.
Regardless, I think it's totally reasonable to be concerned about having shared symmetric cryptography keys stored on servers in Russia while claiming your app is 'secure'/end to end encrypted (not sure if they're claiming the latter anymore or if that was even official claims to begin with vs internet BS), and is especially relevant for Ukranians or Russians politically opposed to Putin.
[0] https://www.facebook.com/help/messenger-app/1084673321594605
As of 2024, Russia-the-state has no problems with either Pavel Durov or Telegram. That's suspicious to say the least.
They only tried to ban it in 2018 and gave up in 2020 after failing to do so without cutting off access to other Internet services. The last time they blocked access to it was quite recently, on 21 August, after the Ukrainian incursion into Kursk oblast.
https://understandingwar.org/backgrounder/russian-offensive-...
And so? Durov happens to be the founder of VK...
This is not an empty accusation, there's been several stories which could not be explained by anything else than FSB having access to Telegram. That said, however, it's only FSB. There hasn't been a single suspicious act like that on behalf of Russian police, so we can assume that this access is only used in exceptional cases. So, unless you believe that Russian intelligence is targeting you personally, you're safe.
Could you share which "100% confirmed" stories this is about? Haven't really come across that before
If your device is compromised, all bets are off.
Example: FSB once leaked Navalny's emails. He used gmail. And no one suspects Google of conspiring with FSB.
What makes you feel that? Never seen that channel before, and the self-description of "High-intensity code tutorials and tech news to help you ship your app faster" doesn't really inspire much confidence when it comes to talking about more nuanced topics.
For example, Telegram isn't based in Russia, and I don't think it ever was. So if that's one of the takeaways from that video, it seems pretty misinformed even about the basics.
They are using Telegram for PR, same as Twitter or Instagram. It doesn't matter if the posts get decrypted by Russia – they are anyways meant to be public.