Which government, such as the French government for all Russian users, the Russian government for all Ukraine users, or the USA government for all users?
Whose standard for warrants, and how much use of coercion and force are they allowed to use for enforcement. Can the USA kidnap the owners for non-compliance, can the Russians?
>Can the USA kidnap the owners for non-compliance, can the Russians?
Jailing someone/holding a company in contempt that does business in your country for ignoring legal warrants isn't kidnapping. Trying to frame it that way is pretty silly and disingenuous.
Of course, the fact that something is ridiculous doesn't prevent a sovereign country from trying to do it anyway. Iran can threaten to assassinate you for communicating with their citizens, and France can threaten to jail you if you ever travel to France or extradite you. Both of those threats are unjustified in my opinion and should not be supported or condoned by other countries (particularly not the US), but like I said; they're sovereign countries so we can't do much to stop them if they want to be unreasonable.
If you are serving people in Iran or France then you are operating in those countries regardless of where you or your servers are and so you do have to comply with their laws or risk facing the consequences.
Now, depending on where you are at the reach of the consequences can be negligible and not impact you at all or can be a major problem.
At minimum you will get your service banned in those countries.
If someone physically flew over from Iran and talked to me in-person instead of over the internet would you make the same argument? That I'm "operating in Iran" and should be subject to Iranian law because I'm talking to an Iranian citizen? What if it was via a letter? How about a phone call?
In any case, a court in any particular state will be responsible for issuing the documents entitling the law enforcement to particular data. There's also the process to dispute issuance or legitimacy of such documents, again, through courts.
So, obviously, there isn't a single answer to your questions. But, obviously, they aren't without answer. Any specific case will produce a potentially different set of answers.
If you want to not be subject to the laws of a country you need to blackhole that entire country.
Basically if you want to operate in a country, you probably need to obey their laws, no matter what you think of those laws. If you ignore them, you can't really be surprised if you get blocked or penalized from doing business there.
Big Tech has basically spent the past twenty years pretending their global status made them above the law of any one nation, but in reality, being a global company just means you're subject to all the laws of all the nations.
Like what most darknet markets use.
Here: https://www.asil.org/sites/default/files/benchbook/jurisdict...
This is both a reasonable exposition and fairly short.
But also keep in mind data collection and transmission and sharing and rule enforcement are not really a jurisdiction thing.
This feels like one of those hn discussions where everyone will end up talking past each other because of terminology failure.
That's some Barlowesque[1] thinking that would play into the hands of big tech.
If Telegram didn't want to answer to French law, they should've blocked French phone numbers from registering users. Problem solved.
[1] https://disconnect.blog/reclaiming-sovereignty-in-the-digita...
It depends entirely on where you land in your private jet.
a) don’t collect the data (signal approach)
b) hire an army of lawyers and compliance people (big tech approach)
c) ban users from entire countries where you don’t comply (common in crypto)
d) risk jailtime or asset forfeiture
[0] https://signal.org/bigbrother/central-california-grand-jury/
Do you have any source for Signal supplying IP logs?
This all somehow leaves perhaps not-so-big list of particularly interesting gentlemen then certain countries will undergo a lot of trouble to get to. No wonder then they did so this time, but wonder which particular among these is the culprit this time...
SimpleX comes to mind
I think you are confusing "privacy-oriented" and anonymous! Signal is pretty privacy oriented since it has E2EE by default (and so does Whatsapp). Telegram would be much more privacy oriented if it had E2EE by default.
Yeah Google and Facebook are all losing money in those liabilities.
No theyre not, they're printing money because user data is an asset. Stop repeating silly sound bytes.
it is easy to prove what your app collects from OS's permission model and web traffic. People are less interested in whether you store it for future use or discard it immediately after receiving.
Even if you claim you don't persist any of user data, you would still be collecting it