Telegram will now hand over phone number and IP for criminal suspects
theverge.com
theverge.com
Yeah Google and Facebook are all losing money in those liabilities.
No theyre not, they're printing money because user data is an asset. Stop repeating silly sound bytes.
Which government, such as the French government for all Russian users, the Russian government for all Ukraine users, or the USA government for all users?
Whose standard for warrants, and how much use of coercion and force are they allowed to use for enforcement. Can the USA kidnap the owners for non-compliance, can the Russians?
>Can the USA kidnap the owners for non-compliance, can the Russians?
Jailing someone/holding a company in contempt that does business in your country for ignoring legal warrants isn't kidnapping. Trying to frame it that way is pretty silly and disingenuous.
Of course, the fact that something is ridiculous doesn't prevent a sovereign country from trying to do it anyway. Iran can threaten to assassinate you for communicating with their citizens, and France can threaten to jail you if you ever travel to France or extradite you. Both of those threats are unjustified in my opinion and should not be supported or condoned by other countries (particularly not the US), but like I said; they're sovereign countries so we can't do much to stop them if they want to be unreasonable.
If you are serving people in Iran or France then you are operating in those countries regardless of where you or your servers are and so you do have to comply with their laws or risk facing the consequences.
Now, depending on where you are at the reach of the consequences can be negligible and not impact you at all or can be a major problem.
At minimum you will get your service banned in those countries.
If someone physically flew over from Iran and talked to me in-person instead of over the internet would you make the same argument? That I'm "operating in Iran" and should be subject to Iranian law because I'm talking to an Iranian citizen? What if it was via a letter? How about a phone call?
In any case, a court in any particular state will be responsible for issuing the documents entitling the law enforcement to particular data. There's also the process to dispute issuance or legitimacy of such documents, again, through courts.
So, obviously, there isn't a single answer to your questions. But, obviously, they aren't without answer. Any specific case will produce a potentially different set of answers.
If you want to not be subject to the laws of a country you need to blackhole that entire country.
Basically if you want to operate in a country, you probably need to obey their laws, no matter what you think of those laws. If you ignore them, you can't really be surprised if you get blocked or penalized from doing business there.
Big Tech has basically spent the past twenty years pretending their global status made them above the law of any one nation, but in reality, being a global company just means you're subject to all the laws of all the nations.
Like what most darknet markets use.
Here: https://www.asil.org/sites/default/files/benchbook/jurisdict...
This is both a reasonable exposition and fairly short.
But also keep in mind data collection and transmission and sharing and rule enforcement are not really a jurisdiction thing.
This feels like one of those hn discussions where everyone will end up talking past each other because of terminology failure.
That's some Barlowesque[1] thinking that would play into the hands of big tech.
If Telegram didn't want to answer to French law, they should've blocked French phone numbers from registering users. Problem solved.
[1] https://disconnect.blog/reclaiming-sovereignty-in-the-digita...
It depends entirely on where you land in your private jet.
a) don’t collect the data (signal approach)
b) hire an army of lawyers and compliance people (big tech approach)
c) ban users from entire countries where you don’t comply (common in crypto)
d) risk jailtime or asset forfeiture
[0] https://signal.org/bigbrother/central-california-grand-jury/
Do you have any source for Signal supplying IP logs?
This all somehow leaves perhaps not-so-big list of particularly interesting gentlemen then certain countries will undergo a lot of trouble to get to. No wonder then they did so this time, but wonder which particular among these is the culprit this time...
SimpleX comes to mind
I think you are confusing "privacy-oriented" and anonymous! Signal is pretty privacy oriented since it has E2EE by default (and so does Whatsapp). Telegram would be much more privacy oriented if it had E2EE by default.
it is easy to prove what your app collects from OS's permission model and web traffic. People are less interested in whether you store it for future use or discard it immediately after receiving.
Even if you claim you don't persist any of user data, you would still be collecting it
If I live in Germany, and I do a channel with offensive content against the government of an Arabian shitty country, let's say UAE for example. The content might be legal here but illegal there.
Will the UAE gov be entitled to get my IP address and other info? Leading them to be able to use that to harass me, like targeting me with Pegasus for example?
Policy will never be the key to digital privacy, it must always be accompanied by cryptography. The status quo of allowing a third party read and store your messages forever, slurping up all the metadata along the way, is insane.
Example: Signal can't handle more than one phone logged in, and if for some case you don't open the desktop app for more than 30 days, it logs you out there and you can never get these messages to the desktop.
although E2EE chats do take more computing and storage especially with very large groups
I have a feeling he will continue on the same path as before, as soon as he can travel outside of the EU.
As a more general point, the fact is that if a discussion doesn't take off while an item is on the front page shortly after submission, it probably never will. The page sorting algorithm ends up prioritizing recency and traction. I agree this isn't ideal.
I would imagine any serious criminal org will have their own messaging infra by now.
I'm guessing they do not -- that would be inconvenient, expensive, unreliable, insecure, and/or conspicuous.
[Edit: "serious" criminal orgs run, e.g., custom-built submarines, so private comms infrastructure is clearly within their technical abilities. But having all org members communicating to a private centralized mothership seems risky from a surveillance perspective]
Some do run their own platforms or share a self hosted platform set up by people in a non cooperating country. Sometimes the platform admins find out they were being MitM by mistake tech or law enforcement make. [1] Or not using the MitM detection Jabber is capable of. Jabber scales to millions of users per cluster, big enough for probably most criminal organizations. I doubt the cluster in question was specifically meant for criminals, but the smart criminals will find solutions best suited for their needs. In this case I think they chose poorly given VM's can be live migrated and snapshot including memory contents without interrupting the platform or raising suspicion.
In my humble opinion the big shared corporate platforms will attract the ultra-lazy arrogant and cavalier criminals and I'm sure law enforcement are fine with it. Easy busts still look good to justify big budgets. There are probably people that say they don't know anyone that's been busted on those platforms but they are probably not moving enough volume of illicit goods to warrant immediate attention. That information would be quite useful for getting a warrant however if the target was suspected of something else or if they were an influencer thinking or saying the wrong thing in public.
[Edit] Updated link to the snapshot describing potential mitigations including SCRAM PLUS which was not configured in this incident.
[1] - https://archive.ph/4wi5t
Even when deleting messages how can you trust these are actually being hard deleted?
I would imagine the inconvenience and cost are worth it but what do I know... I'm not a criminal :P
There have been a few big busts the last years by the Dutch police of criminal rings, caught because of their choice in messengers.
The ones using Signal or Whatsapp are the smarter ones.
At least the Chinese they know that all their conversations are being monitored and read by the government.
In the EU many people still live under the illusion of GDPR, data privacy, democracy etc...
/s
I dont think a warrant canary is really useful, it implies “we just got 1!” instead of “we just got an additional pile of 200 secret requests from G-7 national governments, one of which is already trying to incarcerate us for not being so forthcoming about compliance”
https://news.ycombinator.com/item?id=41628019 - 3 hours ago (6 comments)
And it's not a dupe, only a related submission (different article / link).
> prompt: There’s an article on Hackernews titled “Telegram will now hand over your phone number and IP if you’re a criminal suspect”. Generate a comment in Hackernews style that supports this decision, implies that it’s because they didn’t encrypt the messages and uses Signal as an example of doing it right because “look! They haven’t had problems”
Not surprised. Telegram doesn't encrypt by default, so of course they're handing over phone numbers and IPs. If you don't lock things down like Signal does, you're going to have problems. Signal can’t hand over what they don’t have—encrypted end-to-end, no metadata. Simple as that.
Yes, channels and groups are most likely what makes Telegram a threat where Signal isn't. That's an excellent argument for decentralized social media.
You're probably exasperated that others don't see what to you seems like an obvious truth. Rather than mocking the opposing argument, it's probably still worth rehashing yours when the topic comes up, even if it feels like banging the same drum with nobody listening.