Thoughts on the Durov Arrest
prestonbyrne.com
prestonbyrne.com
If you literally have plaintext documents responsive to criminal inquiries in a jurisdiction you are subject to, we don't reach the "internet censorship wars". You're in a place not dissimilar to a 1970s telephone company; the "random people can't simply declare themselves above the law wars". Don't be in that place. Encrypt end-to-end.
Q. How do I know that Tarsnap is secure?
A. Read the source code.
Q. Ok, but you're really smart, what's stopping you from putting in a backdoor and hiding it really well?
A. I don't want to get tortured, and ensuring that I can't decrypt your data protects *me*.A canny torturer would read the Smart People on a public forum red-teaming cperciva's mind.
All it does is, should that occur, prevent you from giving the torturer what they want to end the torture.
OTOH, convincing the torturer by, among other means, public statements in advance that you have failed to consider this anhd believe that not having that ability prevents torture, and that for this reason you do not have it, might prevent torture. But that's a big gamble on potential future torturers believing your public statements of motivation.
But I can't be coerced into adding a backdoor into past versions of Tarsnap, because I don't have a time machine.
That is to say, it's entirely possible that you were already tortured and the backdoor is already there by using the same logic - no time machine needed
Like already said unfortunately the only safety would be reading the code
And then wait for a scheduled backup with the backdoored client.
Though XZ says that's impossible, so I won't lose sleep over that scenario.
Honestly, I really wish the Tarsnap server was open source. I imagine it has not been released as such because that would probably hurt the business a lot, especially given that the costs per GB are currently approximately 50 times more than I would pay for simple object storage on B2.
I built our company's first backup solution on Tarsnap, but when I projected out what deploying that to our entire fleet would cost, I rebuilt on Restic. We currently pay something like $250/mo for our backups, as opposed to the approximately $12,500/mo they would cost on Tarsnap.
By the way, I absolutely love spiped. It beats the pants off stunnel in both stability and performance. Maybe Colin should close-source that and start charging $0.25/GB for traffic that flows through there too? :P
He's been doing this long enough, I'm not even prepared to dunk on him for picodollar pricing anymore.
Surely some three letters organization probably could pull that off, but it add risk to their operation that the operation could be leaked.
This is basically a point I've made in a few of my talks about security and cryptography: The point of cryptography isn't to guarantee that your data is safe; it's to raise the cost of an attack to the point where a potential attacker decides not to attack. In particular, there's usually a human involved somewhere (sending or receiving information, or both) and humans are squishy and fragile; but torturing people attracts far more adverse attention than torturing data.
In either case, you'd have to fool the internet army, who are watching the source code of projects such as this like a hawk.
Q. How do I know that Tarsnap is secure?
A. Read the source code.
This is a "good enough" but less than reassuring answer in the post-Solar Winds world. (It wasn't before, but less so since the advent of "package managers" and the like.) How would someone evaluate the quality and security of the build process and minimal dependencies (which might have their own problems [0])?As a non-security person thinking of how might one could evaluate this: Could adversarial builds (say performed in and using tools commonly available in several locations with different types of government spying) generate the same binary? Could that act as a sort of proof of an untainted toolchain? Or a canary for where a build process is tainted?
There is a line in RickAndMorty about this, which I won't repeat here. To paraphrase: the one thing worse than bring tortured for information you have is being tortured for information you don't have.
In the phantom secure story the intent was crystal clear. In the Telegram case it seems that the refusal to cooperate with investigations cast enough doubts to arrest the CEO and put him in similar shoes.
https://www.fbi.gov/news/stories/phantom-secure-takedown-031...
That's a distinction between end-to-end encrypted applications and cosmetically "secure" apps like Telegram.
Although, ironically, if the French are arresting him now that says good things about Telegram and their willingness to dob customers in.
Do we have any proof they aren't also doing that besides being on telegram and every other messenger?
Also, in my country they usually just write the ordinary website name on the wall and add "VPN Tor" whatever that could mean. Maybe they try to hint that Tor and VPN are apps for drug trade? Do Tor and VPN have moderation and do they cooperate with law enforcement?
> Telegram uses the MTProto 2.0 Cloud algorithm for non-secret chats[1][2].
> In fact, it uses a split-key encryption system and the servers are all stored in multiple jurisdictions. So even Telegram employees can't decrypt the chats, because you'd need to compromise all the servers at the same time.
is false? If so can you cite a source? (The claim is just a summary of the FAQ https://www.telegram.org/faq#q-do-you-process-data-requests)
At least one employee must have the ability to intercept the code.
(Unless the user has 2fa enabled, but that is not the default configuration.)
There are probably easier ways if we knew more about how the administrate their infrastructure.
However I think the real question is: even if that's possible, can law enforcement compel Durov or an employee to do so?
The E2E encrypted comms are a red herring. There is plenty on Telegram that is public, plaintext and presumably illegal.
If Telegram refused to respond (note: not bend over and comply, just respond) to French legal requests in respect of plaintext criminal behaviour the way any other company would and should, that’s somewhat damning. If Durov went above and beyond and interacted with that content, his goose—as the author put it—is cooked.
Telegram does not store messages in plaintext. Period.
No matter how shrill the cries from Moxie Marlinespike and his adherents, E2EE is not the only form of encryption.
MTProto 2.0 is fully documented and everything the user linked described is true.
So far the best I've got is something along the line of: if you can get your chats when you log in with a new device, then so can a Telegram employee. With no proof of the claim of course.
For example the company servers could be hosted on an island with armed guards instructed to burn everything if anyone approaches and the decryption happens only on those servers: sure they have access by definition, but they really don't.
The guards could decide they’re not getting paid enough and steal the data. Or the government could arrest them. Or the government could MITM the data center. Or any hundreds of different scenarios.
At the end of the day, the only thing preventing somebody from accessing the data is that they just… don’t.
This is very weak security and it is why cryptographers and security professionals call it “effectively plaintext.”
I mean, having to modify server code in order to access data that is "effectively plaintext" is not so different from installing a backdoor inside the client: it's not like the user has any choice of client, so even for apps like whatsapp and signal that run E2EE one is still making a leap of faith.
If we add the fact that everything runs inside an os built by companies who may or may not be constantly spying on their users we could say that by definition there's a lot of stuff in our lives that lives in "effective plaintext".
I also want to repeat the original point that started this whole conversation: the point was how easy it would be for Telegram to access the chats and if the justice system can compel them to do so.
When people say it has the data in plaintext, I take as a "they can access them whenever the want right now without changes", and yes of course the could ultimately access the data (in fact they don't claim to be unable to). What they claim (and I believe it feasible) is that even if a judge seized all the assets and servers under his/her jurisdiction it would be impossible to decrypt any user data.
The point is: even if they could, should they do so when compelled by authority?
For example, since we are in the realm of speculations, I propose the following alternative to the plaintext or accessible decryption keys: the decryption could happen inside a nitro enclave making it essentially impossible to access the data without changing the application code.
I'm not saying that this is what happens, just that I don't think that one can so easily deduce that "they can access the data" just from the fact that "they send you chat history to you".
Messages are not stored in plaintext. The claim they are stored in plaintext is false.
One can have cogent arguments about one's preference for E2EE or not but the repeated claim here and elsewhere that messages are stored in plaintext is simply hearsay.
[1] https://core.telegram.org/mtproto/AJiEAwIYFoAsBGJBjZwYoQIwFM...
This was not a case of a user confusing encryption in transit, as you claim.
Do not use Telegram.
> As another HN user pointed out Telegram does not store messages in plaintext: https://news.ycombinator.com/item?id=41348228
Telegram does not store messages in plaintext.
Your claim:
> That user seems to be misinformed, and appears to be discussing client-server encryption, not end-to-end encryption
Is categorically false. You do not get to redefine what encryption is. That is not your right.
You've been corrected repeatedly. If you continue to insist you have not made a false claim, you are then lying.
It looks like the author failed to grab that Durov asked for the French nationality and therefore is a French citizen who must comply to French law.
> Telegram is not the only company in the world which has a social media platform used for unlawful purposes
Except Telegram is the only one of those companies which intentionally doesn’t answers to legal requests. All other social networks are cooperating with law enforcers in the countries they operate.
Even Signal is cooperating when asked too. The difference is that unlike Signal, Telegram owns its users data in plaintext.
Also the author fails to understand that the complicity here doesn’t mean that companies in Europe are responsible for their users content. Like in the US, they are responsible if they fail to comply to laws in a reasonable time. Telegram doesn’t comply in a reasonable time since they voluntarily don’t comply at all. That’s a huge difference.
The law professor bit is shocking, given the article basically revolves around it making “zero sense for Durov to do any of these things,” as if criminality is always rational. But crypto has broadly come out in support of Durov [2].
[2] https://www.nytimes.com/2024/08/27/technology/telegram-crypt...
I mean, he got French citizenship despite not fitting any legal requirements, and nobody in the French government has given any explanation on why he got it.
In this case "crypto" in the title is confusing, since it could be also/instead about the cryptography industry...
This is pure conjecture, btw.
>If Telegram receives a court order that confirms you're a terror suspect, we may disclose your IP address and phone number to the relevant authorities. So far, this has never happened. When it does, we will include it in a semiannual transparency report published at: https://t.me/transparency.
In the EU, every company is responsible for what their users post on their service. There's a reason you won't find any (or very few) comment sections on the website of EU media and news companies. No one wanted to pay for the moderators needed, so when the law came around most comment sections were shuttered.
A legal request comes from a legal authority: a judge.
>Cooperating with law enforcement
Law Enforcement (that's the police, right?) are not judges and are not authorised to rule on legal matters.
Hate has not logic.
So you are trying to cover the whole spectrum of things to ensure your belief that Durov is being legally detained.
Sorry for editing instead of answering. Reddit says I "post too fast".
It's a pretty straightforward logic.
What if it wasn't even encrypted, and was just so many gigabytes of data that the government doesn't have the skill or manhours themselves to wade through it? Can they demand big data tools tailor made per company?
Why can't companies submit software and data to these requests so covered in "cookie consent style popups" that nobody could ever get through it in multiple lifetimes?
What makes Telegram unique is:
1) They have access to almost all the content
2) They try to use arguments about jurisdiction to avoid helping law enforcement with lawful requests
All the other messaging platforms (WhatsApp, Signal, iMessage) have started to use end-to-end encryption to avoid being in this position in the first place. But they also comply with law enforcement and share the data they do have, and don't hinder lawful investigations.
The biggest issue with Telegram is that due to the lack of end-to-end encryption it is a huge security risk; how do you know the operators aren't selling access to your chats to some criminal actor or a repressive government agency? You don't.
What's weird is that there aren't really technical blockers to E2E encryption anymore (maybe different 10+ years ago), and with such a weak alternative, you'd expect Telegram to want to switch. The fact they haven't for so long, and have essentially doubled down on their flawed approach suggests that there's a reason we're not privy to as to why they don't want to move to E2E encryption. I'd hope not, and I don't want to throw around conspiracy theories, but when a decision doesn't make sense that's usually due to missing information, and I do wonder what we're missing.
There are several disadvantages, and Telegram would lose its key features:
1. Cloud Sync
2. Instant Multi-device login
3. The ability to create large group chats, like thousands or hundreds of thousands of people in a single place.
4. Sending files up to 4GB.
[1] Signal is working to support an encrypted "cloud backup feature" (some hints on this are on their code base), as per "sync" that's already done in the forward direction by Signal (by sending all new messages to all your devices) I'm sure you could provide some sort of backward sync as well. [3] Signal already supports groups up to 1000 people iirc, I'm sure a read-only channel larger than that could also be doable. [4] I'm not sure why that would not be possible.
I'm not sure exactly what [2] refers too but nevertheless I have some doubts that would cause a blocker.
I used Signal as an example since it's a well known encrypted messenger; although I must acknowledge it's not really a Telegram competitor and vice versa (one is a secure messenger and the other is a social media app).
That said, (proper) E2E encryption makes everything harder to do - again, you can take Signal as example and their development speed. But, I'd argue, is not impossible
Which is where the practicality fails. This is why Telegram is the only app that works in large protests, unlike Signal.
Time and again, Telegram proves that the lack of E2EE actually becomes its strength, as proven by the protestors in Myanmar, Hong Kong, Iran and more countries: https://x.com/Pinboard/status/1474096410383421452
I'm not really against E2EE, but many of us fail to see how E2EE can hurt the usability of the app sometimes, and in cases where it is needed the most too.
Many Telegram groups have thousands of people, which is impossible to do on Signal at the moment. WhatsApp copied Telegram's features, large groups with topics and channels too!
> I'm not sure exactly what [2] refers too but nevertheless I have some doubts that would cause a blocker
1 and 2 are related. You can quickly login on Telegram and have your chats sync instantly, instead of waiting for manual backups or devices to sync. The devices run independently.
> But, I'd argue, is not impossible
I too don't think it's impossible. It's just computationally expensive and comes with limitations for now.
Durov does not want to use the Signal protocol either because he's been approached by the US agencies multiple times to include certain algorithms or libraries inside Telegram, not to mention that Signal itself is funded by the government.
Matrix could be better but it leaks tons of data, has been hacked multiple times in the past too.
And what do you imply 'funded by the government' means for Signal? It's a nonprofit org, app has e2e encryption and clients are open-source. How is it worse than an app owned by an LLC in UAE, with no e2e encryption by default, unknown funding sources and no information about what's going on on the server?
Because it works and because real world is not theoretical.
> And what do you imply 'funded by the government' means for Signal?
I'm not implying anything. I just listed the reasons why Durov doesn't trust state funded american encryption systems.
> unknown funding sources
What do you mean unknown? They're pretty known.
> no information about what's going on on the server
All server side code is unverifiable. In fact, Signal itself was running a totally different codebase than what it made public, for a whole year.
I mean, you don't believe the fairy tale that he actually paid for everything himself?
Unless you use your server or a trusted one.
> has been hacked multiple times in the past too
Any links? Looks like it was long ago.
Cloud Sync of what? WhatsApp doesn't seem any less "cloud synced" than Telegram to me.
> 2. Instant Multi-device login
What does that mean?
> 3. The ability to create large group chats, like thousands or hundreds of thousands of people in a single place.
MLS scales very well to such large groups: https://datatracker.ietf.org/doc/rfc9420/
> 4. Sending files up to 4GB.
How so? WhatsApp, Signal, iMessage and others all support sending files. File size isn't a factor (assuming you're fine with leaking the metadata of who has received the same file).
Put differently, if you wanted to put together a charge list for the head of a large social media company you didn't like, this is what it would look like. If you wanted to put together a charge list for someone actively running the group chat of a terrorist group... this is what it would look like. And same for pretty much every level in between.
Deciding which of these scenarios is more likely is more indicative of your priors of the scenarios than it is of the evidence. Is this the French government going after a fairly innocuous service because they don't like what they provide? Or is it the government going after a service saying "neener neener your laws can't touch us"? Or is it the government going after an individual with tenuous connections to criminal organizations? Or one with solid connections to criminal organizations? Truthfully, we don't have the evidence to distinguish between these scenarios yet, and we should reserve judgement until such evidence comes to light.
That said, for high profile cases they tend to give some information to control rumors and the media.
I think it's CP that gets Telegram in hot water. Prostitution or drugs bothers noone but pedophiles trading stuff wakes everyone up.
(Also, maybe it’s nitpicking, but there are very obvious reasons why it’s better to have the Taliban using WhatsApp and the US getting all that metadata and maybe more, rather than the Taliban finding some other channel. If Washington wanted WhatsApp banned in Afghanistan it would’ve happened long ago.)
What I can’t figure out is, are these commentators naïve or just piling on for attention or what?
There are some very obvious opportunities when the Taliban (or enemy de jour, like drug cartels) feel the need to be "finding another channel".
https://en.wikipedia.org/wiki/Operation_Trojan_Shield
"Hardened encrypted devices provide an "impenetrable shield against law enforcement surveillance” and are in high demand by TCOs (transnational criminal organizations), thus the shutdown of Phantom Secure in March 2018 left a vacuum for TCOs in need of an alternative system for secure communication.
Around the same time, the San Diego FBI branch had been working with a person who had been developing a "next-generation" encrypted device for use by criminal networks. The person was facing charges and cooperated with the FBI in exchange for a reduced sentence. The person offered to develop ANOM and then use his contacts to distribute it to TCOs through existing networks. Before the devices were put to use, however, the FBI, and the AFP had a backdoor built into the communication platform which allowed law enforcement agencies to decrypt and store the messages as the messages were transmitted."
I'm still seeing drug busts here in Australia that're attributed to An0m (or which look extremely likely to have used An0m as part of the investigation).
If you make a mockery of the law enforcement's requests made within the scope of the local laws then yes, you should get out. Especially if you show your middle finger to the country you visit and hold citizenship of.
Durov has money to buy citizenships that allow him access to most of the world without needing to obtain a visa so I'm sure he has a well-paid legal team that proactively monitor the situation. He may have been informed of the legal noose tightening around his neck and chose to go to France for one reason--France does not extradite its citizens and he happens to hold French citizenship. This puts him out of the reach of other jurisdictions (e.g. the US) and he may be hoping for a deal and better food. We should wait for official information from the French authorities as well as for news of people connected to him and his businesses falling out of windows. The former will explain the latter.
This completely ignores that the amount of criminal activity on Telegram in Europe as well as parts of Asia in itself has been escalating. The author is coming at this from a US-based point of view, which is fine, but unless you're particularly interested in the topic it's difficult for Americans to be aware of the scale of Telegram's role in criminality elsewhere, as this does not seem to be the case in the US. Maybe someone here knows why Telegram is not as core to organized crime in the US, and what communication methods are used there. But it's clear that in Europe and parts of Asia, its role is massive, and has been growing and growing without a limit in sight. This is easy to underestimate.
In these parts of the world, the scale of it is of a completely different magnitude than criminal activity on e.g. Facebook, which the author brings up but is a misguided comparison. And that's ignoring the relative percentages of legit vs criminal activity, which are inverted (if not worse) between the two platforms, because that's not as important.
Scale and absolute numbers, the absolute detrimental effect on society, matter.
I don't see this as an escalation because there was always going to be a line somewhere. A line where the amount of criminal activity on a platform, which when crossed , was going to cause arrests. Telegram's continuous growth in this aspect means that the line has now been crossed.
And in reality, this line exists anywhere even in the US. It might be higher, but it's still there. The idea of not having such a line is clearly insane - that would mean no matter if something completely destroys society, we're going to let it pass. Such lines are almost never enshrined in law, for obvious reasons. They only become visible to everyone as they are crossed.
Do you have any official source that criminals on telegram are more? Or is it just a feeling you have?
In Finland, stuff seems to be more on Telegram than on dark web as well
Do you have a source or no?
I was hoping for something more substantial, that showed telegram is used and other apps aren't, for that purpose.
Reading the article I was baffled to see all this talk about section 230 of communication and decency act. Telegram moved from Russia to Dubai and Durov was arrested in France.
Using the US hammer on a foreign nail gives vibes of Team America - World Police parody.
That the article wound up being circulated to a bunch of Europeans who thought it was an article about French law after someone posted it on HN is something of an accident; the article isn't for them (unless of course they're planning on starting a social media company, in which case leaving Europe and setting up shop in America on a permanent basis would be recommended). The very fact of his arrest is enough for Americans to know to steer clear of the EU going forward.
Without any information on the legal background for France, how can anyone seriously make that claim?
The conditional immunity under the DSA is also not as comprehensive as the broad immunity under Section 230, but that was out of scope so I didn't get into it. I do admit the piece assumes some familiarity on the part of the reader with the existing problems around the EU regulatory schemes relating to speech and content removal.
If you have any constructive suggestions I'll be happy to consider including them and giving you appropriate credit, just chuck them in the comment section. tl;dr though, in my view, France is not a great place to incorporate and run a social media company.
Telegram is FSB project, lost all my doubts about.
Furthermore, after his failure with his crypto project in the United States, he returned to his homeland, and the Kremlin immediately "unblocked" Telegram. The next day, Durov promised investors to pay off the debts. Quite a coincidence.
Telegram also has taken down various channels from one side of the global conflict and not others. For example, he took down the channel of Iranians protesting against the dictatorship in 2017, but he refuses to take down the channels that sell child *pornography, drug$, human trafficking, or Ru$$ians posting videos of beheading Ukrainian POWs, etc.
This whole situation is really complicated, to say the least. Freedom of speech is paramount, but in times of global information warfare, it's not really possible to stay neutral as the owner of the top communication platform. Especially given the horrific stuff that’s being done on this platform.
He says he is neutral, but the facts indicate that it's not quite true. And it’s understandable from the aspect that his life is probably at risk if he doesn’t cooperate. So, it seems he's just trying to navigate a delicate balance, maneuvering between conflicting pressures. Prison is not great, even if it’s French, but Europe is less likely to give him novichok tea, so he apparently chose to work with the other side.
I'm not saying the French aren't serious about the charges they've published but they're hardly the main point.
There's plenty in the media about the use of Telegram by the the Russian military and intelligence services, as well as politicians. For example: https://www.politico.eu/article/telegram-ceo-arrest-pavel-du...
1) Russia uses Telegram for military communications.
2) Russian military bloggers use Telegram for detailed updates, including graphic pictures.
3) Ukrainian military bloggers do the same.
4) Russian mercenaries use Telegram in former French colonies in Africa.
France may want to shut down 4), but I would think that Western intelligence services would not want to shut down the uses in the Ukraine conflict because they can track everything. So maybe they just want a better tracking API.
They would want to shut it down in preparation for a large Middle East war though. In that case, they'd prefer hand picked CNN embedded journalists and not have graphic pictures appear freely.
Lavabit was mentioned here. Perhaps Durov should just announce to shut down Telegram and find out if certain forces beg him to continue the service.
Telegram us being used by both sides of the conflict. It is as populat in Ukraine as it in Russia. (or other ex-USSR states for that matter)
Ukrainian military bloggers use it, their public persons use it and while there is probably an an order that dictates not to use it - I really doubt it is being followed completely considering the vast majority of Ukrainian military are yesterdays conscripts and not professional soldiers. Some of them drink, some of them sell their equipment, some of them gamble.
I really doubt they don't use telegram. Maybe it is not systemic but neither this is for Russia.
Nobody who's got a secret to keep would use it.
2. Presumably Durov was in a meeting with Putin.
2. 1. But there is no war, the war against Ukraine is not a war in legal terms.
2. 2. And there is no charge of meeting with the enemy or anything like that.
2.3. So you are saying that we are talking about the charges in vain, because the political underground is obvious.
2.4. Yes, you are right, that is why we are talking about the charges.
Maybe it's because I live very close to Russia and most of the people here probably don't think about the war every day, but the strategic reality of this situation makes all these privacy arguments so trivial.
I need to see this happen to someone other than Durov to consider that it's not about the war. While it's only Durov then I really don't think he's discussing privacy issues with the French - they are discussing his access to Telegram's systems and his ability and willingness to give that to the allies of Ukraine. Likewise in Russia they are not discussing the privacy issues, they are trying to lock Durov out Telegram's systems and the military and intelligence services are working on alternative ways to communicate, and meanwhile the effectiveness on the battlefield of the Russian army is compromised.
Now, of course that this happens just after the arrest of Durov might just be a coincidence, but you would also think that Macron might want to try to postpone that visit, especially considering the heating up political situation at home :
After Macron dissolved the assembly after very bad for his party European elections, the Left bloc won the legislative elections... but then Macron, after nearly 2 months, just declared that he refused the prime minister they selected, leading to an obviously pissed off Left bloc, most of which is calling for manifestations, and its leading party - basically starting an impeachment procedure against Macron !
And maybe I misread it, but this thread also argues about that possibility.
I don't know him but the idea that an individual CEO would be handled in this way seems extreme and calls into question the actual motives of the French government.
> For all we know he could have been completely complicit.
I guess he could be an international terrorist drug dealing pimp.
> Hold your horses people.
The French governments actions and communication on the subject has created this environment. They can easily alter it if they choose.
"Durov was naturalized as a French citizen in August 2021, giving him European Union citizenship. Le Monde described the naturalisation as "mysterious", since Durov had not resided in France apart from brief visits. Le Monde suggested that Durov was naturalised via the rarely used "merit foreigner" procedure that is awarded directly by the French government to people viewed to have contributed exceptionally to France's international influence or international economic relations." [1]
Seems obvious that there is much more than meets the eye...
I would hope that it is pretty normal, that a CEO can be treated exactly that way.
"Importation d'un moyen de cryptologie n'assurant pas exclusivement des fonctions d'authentification ou de contrôle d'intégrité sans déclaration préalable."
- Import of a cryptographic mean that does not exclusively perform authentication or integrity control functions without prior declaration.
This to me is a deeply disturbing charge, would that mean that using full disk encryption I'd be liable to be charged with that? Did the maintainers of LUKS do a prior declaration? If not are they likely to be charged if they ever travel to France?
After all, I can fully imagine a server being seized in a data center being encrypted with LUKS. In that case, is it the fault of the maintainers?
Interesting take, what counts as «importing» for software ? Is a copy (with source) of open-source software more in danger of being deemed so ?
> Did the maintainers of LUKS do a prior declaration? If not are they likely to be charged if they ever travel to France?
I would assume yes, but the likelihood might depend on their specific circumstances ?
It wasn't that long ago that the USA considered cryptography to be on the same level of danger as weapons wrt export...
The public non-encrypted aliases or bio of users often contain wordings that explicitly spell out they sell drugs or sex.
For instance, one alias is "WEED COKE MDMA SPE..."
I don't have a clear opinion on whether drugs or selling sex should be illegal or not, can see pros/cons, but my opinion is irrelevant, my point here is that Law Enforcement, might find this very problematic, that there is obviously no moderation here.
They aren't more near you than the ladies in "meet single women in..." are.
The point is to emotionally manipulate the audience into complicity. To cause people not to question the underlying privacy and legal issues.
Instead they want the reader to have thoughts of large numbers of people, in organized networks presumably, that want to cause terror to them or harm to their children.
This causes a reaction in many people to forget about basic rights and focus on the fear they have been given instead.
I'm sure France and the U.S. have a million reasons to want this data from the Ukraine war, to probably some cases of the things they claim. However, it is definitely exaggerated and no one should be willing to trade the ability to communicate privately out of some fear that people who want to harm you are also able to communicate privately.
None of it really makes any logical sense because at the end of the day, to end all encryption means the Government would have to basically criminalize math.
So of course they rely on the reliable methods of emotional manipulation. I mean, they should have a blank check to go after this guy and anyone else, right? You don't support terrorism do you???
> In a subsequent statement, Paris prosecutor Laure Beccuau said Durov was arrested as part of a probe into an unnamed person launched by the office's cybercrime unit on July 8.
So the probe was launched in July, but the warrant was issued in March? I do not understand that. Was warrant issued on a different case? Is information about warrant incorrect?
[1] https://www.france24.com/en/france/20240826-telegram-ceo-pav...
[2] https://www.politico.eu/article/exclusive-telegram-ceo-broth...
But specifically, the issue with the likes of today's Facebook and Twitter (no idea about Telegram) is that they do NOT «just passively host the content», in fact they started to actively engage into its editorializing as soon as they switched to using «algorithmic feeds» !
This has even been a pretty big legislative battle in EU a few years ago, when there were attempts to try to legislate «3rd way(s)» between the extremes of dumb hosting and online newspaper :
https://communia-association.org/wp-content/uploads/2019/03/...
(Anyone has an up to date chart with the current situation, ideally in English ?)
https://communia-association.org/2024/06/10/article-17-five-...
https://www.theregister.com/2024/08/28/tiktok_blackout_chall...
Is there a difference between telegram and other social media messenger hybrids?
Do they allow anti Russian content the same way they allow pro Russian content?
Is that a problem?
Which is simply wrong. Telegram is heavily banning users, channels and groups (if reported I assume) the difference is that they don't apply American morals but something a bit more open than that.
To give you a concrete example, it strictly follows basically the same morality terms for porn as onlyfans or pornhub (except the copy right that is)
Here, the French government is accusing Durov of being complicit with – i.e. aiding and abetting – criminal activity and also unlicensed provision of “cryptological” software, with encryption products subject to prior government authorization before their use in France will be approved.
- at Apple's demand Telegram made adult-themed groups unaccessible by default
- at Apple's or Google's demand Telegram removed an animated emoji of an exploding eggplant
Though those requests resemble censorship rather than preventing crime.
I think TFA is ignoring the usual practice of prosecutors everywhere to stack accusations with a bunch of things which won't stick.
Nonetheless, France has been flirting with extended internet censorship for a while.
Do you have sources?
Yes, France is more and more corrupt, the fact that they deny anticor the right to pursue lawsuit against companies and politicians since 2023 is proof, but this arrest in particular seems well within the legal system (if he is kept under surveillance for more than 96 hours however I will agree with the author, but frankly it's a 'broken clock right twice a day' kind of agreement)
Durov is being persecuted for his role as a CEO of Telegram. Telegram is a legal entity that has nothing to do with France
That's obviously false. Telegram is providing services to French and EU citizens.
The Netherlands, the host country of the ICC, in 2021 made a law that anyone that works in a job with an obligation to secrecy cannot be prosecuted for lying under oath in a court. They cited an example of a lawyer client confidenially. They did not however, talk about the fact that now everyone in government can lie under oath in court. This undermines the very functional principle of a court of law. Lovely for the ICC.
In addition, they created an organisation called the RIEC, with does not have a natural person as it's presentative, which under Dutch law means that it cannot be taken to court by anyone. The gave this organisation control over not just criminal investigations but "interventions", which have no definition and can be anything. They can do anything against anyone and not be held accountabile. And typically they do this through weak civilian proxies for further deniability.
There's a 6x part Dutch documentary where it shows that 9 innocent people were sent to jail on fabricated evidence. One committed suicide. The Dutch will not re-open this case and the responsible person (The former head of the organised crime unit in Arnhein) is not the president of the court of Maastricht. Not fired, promoted.
https://npo.nl/start/serie/de-villamoord/seizoen-2/de-leeuw-...
So the Netherlands has clearly loss a functional democracy.
It's the way all of Europe is going.