• lnxtx
    link
    fedilink
    English
    5521 days ago

    I hope they don’t arrest them too.

    • @mipadaitu
      link
      English
      7121 days ago

      Not that the action against Telegram is right, but there’s a big difference between what Signal and Telegram is doing.

      • Otter
        link
        fedilink
        English
        3221 days ago

        Would you have more info on the differences? I was wondering the same thing, but I don’t know enough about Telegram to compare

        • @[email protected]
          link
          fedilink
          70
          edit-2
          21 days ago

          Signal always responds to authorities when they ask for data, and they give them all they have: the day they registered, their phone number and the timestamp they last used the app.

          Telegram has unencrypted channels of drug dealing, and what I heard is a lot of illegal porn too. The authorities want information on certain users there and Telegram doesn’t comply. This is directly against the law Signal is not breaking, because they always send all the data they have to the law enforcement.

          • @rottingleaf
            link
            1821 days ago

            Telegram is a propaganda weapon in some sense, between two worldviews - one is “a good service doesn’t require trust, because they physically can’t sell you”, another is “a good service you can trust because they won’t sell you”. And Telegram helps the latter.

            So frankly - kill it with fire. Sadly I’m in Russia and everybody uses it here.

          • sunzu2
            link
            fedilink
            721 days ago

            while not wrong context matters, US social media companies also enable human, weapons, and drug trafficking. they play a role in a few genocides too.

            but the western regime does not care.

            • @[email protected]
              link
              fedilink
              26
              edit-2
              21 days ago

              But they give their data when the officials ask. That is all that matters. And I seriously hope none of us uses Telegram or WhatsApp to any discussions. Use Signal because that is so far pretty unbreakable.

              Telegram is already in the hands of that tiny Russian old man and WhatsApp is owned by a lizard.

              • @rottingleaf
                link
                521 days ago

                Yeah, try telling your family, friends, colleagues, therapist to use Signal.

                • @[email protected]
                  link
                  fedilink
                  421 days ago

                  Did so years ago. Everybody uses it from my family and friends. I’ve had a very active group chat there for eight years with friends. My mom uses it actively, even calls me using Signal. My partner knows it is the best chat app and actively uses it.

                  I just asked ages ago for everybody to switch to signal, they valuated the features and for a group chat automatically deleted messages and strong encryption were really interesting for everybody. Now we can shoot shit in a group chat without needing to worry that the logs are stored somewhere forever.

                  • @[email protected]
                    link
                    fedilink
                    220 days ago

                    Same. I also sell the fact that it works xPlatform perfectly, so no more Android/SMS/iMessage fuckery happening.

                  • @[email protected]
                    link
                    fedilink
                    119 days ago

                    Yeah, I’m trying to convince everyone to start using signal before the slide towards fascism turns into a drop

            • Pasta Dental
              link
              fedilink
              2
              edit-2
              21 days ago

              All of the illegal stuff like that that I’ve seen around on social media always linked to telegram channels. Most of the time what you see on regular social media are bots advertising the telegram channels, where the real people are at

          • @inbeesee
            link
            320 days ago

            Hilarious that it’s impossible. They don’t even horde your data.

        • @[email protected]
          link
          fedilink
          1421 days ago

          I’m no authority on it but from what I’ve read it seems to have more to do with the social features of telegram where lots of content is being shared, both legal and illegal. Signal doesn’t have channels that support hundreds of thousands of people at once, nor media hosting to match.

          • socsa
            link
            fedilink
            English
            13
            edit-2
            21 days ago

            Right, the French authorities are going to present evidence that this dude was aware of specific illegal activity and refuse to comply with a legal warrant involving said actively, making him guilty of obstruction at best, and possibly conspiracy. Signal complies with warrants, they just don’t have anyone’s keys. Telegram has everyone’s keys, and theoretically could turn them over but they refuse. That’s a huge difference from a legal perspective.

            • @[email protected]
              link
              fedilink
              1321 days ago

              Thank you. I’m going to restate your explanation to be sure I’ve got it:

              • authorities want platforms to comply with legal requests
              • when Signal gets a subpoena, they open the key locker and show that it’s empty. They provide the metadata they can (sign up date and last seen date, full stop) and tell authorities they can’t do better.
              • when Telegram gets a subpoena, they open the key locker and show all the keys, then slam it shut in the face of the investigator, telling them to get bent.
              • conclusion: it’s easier to never have the keys in the first place than to tease the government with them
              • @rottingleaf
                link
                121 days ago

                It’s easier, but Telegram’s authors are from Russia. They psychologically can’t accept that “never have the keys” thing. They want to have control and they want to be able to tell “yes” to the investigator, possibly for something in return.

          • @rottingleaf
            link
            221 days ago

            And it’s sad that it doesn’t. Because that’s why people use Telegram.

            Media hosting - we-ell, I suppose something similar to bittorrent (or just sharing encrypted files over bittorrent) would do to back such a system?

            Telegram’s channels are like blogs, they have reactions and comment links leading to a groupchat associated with a channel.

            It’s basically a social network in an instant messenger format.

            Telegram is socially , in terms of finding a market niche, the smartest thing of what’s happened in the Internet recently. Durov really is a good businessman.

        • @toasteecup
          link
          English
          2121 days ago

          Are you developing your opinions based on vibes or have you actually audited their software yourself (you are free to do so both client and federation server code)?

          If you audited it, have you produced an actual report with metrics and points of reference for your data points?

          • southsamurai
            link
            fedilink
            1521 days ago

            This person has been running around spreading FUD in every post about this

            • @toasteecup
              link
              English
              621 days ago

              It’s what Ive come to expect from the lemmy.ml instance and I finally blocked the entire instance.

              • @rottingleaf
                link
                321 days ago

                It’s actually sad, even though I’m a libertarian, tankies and in general marxists could have made a good input into our future. But if they can believe in Telegram being secure because of vibes and not even doing basic research, they’ve already lost.

                • @toasteecup
                  link
                  English
                  220 days ago

                  Heeey I am also a libertarian, I just tend towards left libertarian. Back to the point of discussion, I find it difficult to ha e a meaningful conversation with the tankies or in general anyone from lemmy.ml . The discussions tend to lack any real data and feel entirely vibe based OR it’s apologist bullshit for Russia.

                  Like it’s cool if you like communism and have a philosophy based around why you think it’ll help humanity. I can politely disagree but still listen and discuss. It’s quite another to just be a complete dipshit and say “Ukraine had the invasion coming” (actual quote I’ve seen).

                  • @rottingleaf
                    link
                    219 days ago

                    I’m actually sympathetic to anyone having an ideology not to help their identity, but trying to imagine a structure that works.

                    Ancaps are expected to be good in that regard, tankies are expected to be bad in that regard, but in general there are good and bad people in any group. I’ve met almost (the premise of racial difference in quality is still wrong obviously) reasonable Nazis, and not alt-rights at that, but real honest Nazis.

                    I’ve been excited about Trotskyism at some point, because while there are problems with their proposed ideal state (which is similar to what’s described in Norbert Wiener’s “Cybernetics”), they have a proposed mechanism and it’s been even tested in Rojava (their bigger issue is with armed apes around them though, and also with the USA abandoning them after not needing them against ISIS).

          • @[email protected]
            link
            fedilink
            113 days ago

            Doesn’t take away the fact that not being on F-droid is a huge issue and says a lot about how much they care about privacy and security.

        • @gedaliyah
          link
          1321 days ago

          The folks at F-Droid have said that Signal would certainly qualify, but Signal doesn’t want multiple channels out there. F-Droid is just honoring their wishes.

        • @[email protected]
          link
          fedilink
          1121 days ago

          Assuming you’ve audited Signal, can you tell us what your findings were and why you think Signal must be up to something pretty bad? I’m very curious and would love to be enlightened by someone as knowledgeable as you.

          • poVoq
            cake
            link
            fedilink
            7
            edit-2
            21 days ago

            I’ll leave it up to you to decide if that is bad or not, but one of the reasons the Signal app can’t be put unaltered on F-droid is because it loads in external dependencies from Google at run-time, which can also be altered by Google at will with any Android update.

            • @[email protected]
              link
              fedilink
              3
              edit-2
              21 days ago

              How significant is it that the server code is open-source or not? It’s possible for Signal to publish their server code while running completely different software on their servers. The point of the client is being open source and audited on a regular basis by the community, which is why it doesn’t make sense to trust the server-side software.

              The entire point is that we don’t have to trust the sever at all. The client is open source and regularly audited by the community. As long as the client stays fully open source, everything’s fine. Also, the closed source dependencies are part of a spam reduction effort which IMO is well worth it. Prior to this, Signal had a spam problem and the client itself remains fully open source.

              Signal could have very well not even told people that they added a closed source dependency on Google to its servers and just lied by publishing fake server code that omits the closed source dependency., but instead they were very transparent about the spam problem. In terms of they “why?” regarding the closed source dependencies, their argument is that making it open source would almost immediately result in all anti-spam measures being thwarted. Frankly I’m inclined to agree and again, as long as the client is fully open source and regularly audited, the server code is irrelevant to user privacy/security.

              https://community.signalusers.org/t/spam-scam-on-signal/26665

              https://signal.org/blog/keeping-spam-off-signal/

              • poVoq
                cake
                link
                fedilink
                6
                edit-2
                21 days ago

                The external Google dependencies I am talking about are loaded into the client not the server, so that’s an entirely different issue.

                • @[email protected]
                  link
                  fedilink
                  621 days ago

                  Every app from the Play store requires GCM though, and Signal functions even if a user disables GCM. It pertains to a phone’s ability to notify a user of a new message. But again, users can disable GCM and the app itself will continue to work just fine.

                  For what it’s work, the APK on Signal’s website (obviously) doesn’t have the external Google dependencies. Personally, I really don’t see this as an issue at all.

                  • poVoq
                    cake
                    link
                    fedilink
                    821 days ago

                    There is also Google maps integration. Sure, it’s not mandatory anymore, but if you install the official Signal app on a phone with Google play services installed, you are effectively not running an open-source app anymore and this potential backdoor is also not noticeable with reproducible builds.

                    F-droid has strict rules in place to prevent these sort of things for good reasons, thus the original comment is not entirely wrong in saying that an app that claims to be open-source, but can’t be made available on F-droid is a red-flag.

              • Possibly linux
                link
                fedilink
                English
                121 days ago

                It would still be nice to have the server code. I want to run my own server on my own hardware

            • @gedaliyah
              link
              221 days ago

              Lots of apps have slight modifications in F-Droid. Like Telegram for instance.

    • @[email protected]
      link
      fedilink
      2021 days ago

      She has her hand in too many strategic places, unlike Telegram.

      employed at Google for 13 years

      speaker at the 2018 World Summit

      written for the American Civil Liberties Union

      advised the White House, the FCC, the FTC, the City of New York, the European Parliament, and many other governments and civil society organizations

      • @rottingleaf
        link
        -120 days ago

        It’s a pleasing thought, of course, that an influential person may have morals and good goals (and nice looks).

        But since there’s no way to know for sure, I think I’ll just stop trying to classify those names into good and evil.

    • Possibly linux
      link
      fedilink
      English
      -2
      edit-2
      21 days ago

      She’s in the US

      Say what you will about US but they are pouring money into the cyber security industry

      • @[email protected]
        link
        fedilink
        320 days ago

        Dude, it’s a non-profit, and their biggest contribution is money that was made by selling WhatsApp to Facebook. Cuz the guy just couldn’t live with what happened to his creation.

    • @TCB13
      link
      English
      -32
      edit-2
      21 days ago

      They won’t there’s no need. Their clients are garbage and they’re most likely backdoored anyways. This action against Telegram is only happening because they can’t get inside it, they can’t backdoor it nor corrupt anyone. If they were able to do that they wouldn’t be doing this.

      • @[email protected]
        link
        fedilink
        1121 days ago

        No matter how good the protocol or client encryption, your privacy is only as good as your own physical security for the device in question.

        Given that if you lose your private key, there is no recovery, I would be surprised if there were real back doors in the clients. Maybe unintentional ways to leak data, but you can go look for yourself: https://github.com/signalapp/Signal-Android

        They have one for each client.

        • @[email protected]
          link
          fedilink
          English
          821 days ago

          As an example of this, I believe SexyCyborg got in trouble for reporting on leaks via people’s 3rd party Chinese language keyboards. So her theory is that the keyboard apps people had installed leaked data when Hong Kong protesters were communicating with the press, rather than the actual Signal app. But… as stated above, people have to take responsibility for their device and in this case, they had chosen to install apps with leak issues into the communication process.

          • socsa
            link
            fedilink
            621 days ago

            This is precisely why opsec is more than just an app.

            Leaky keyboards are a possibility, but what is actually far more likely is just that someone on the signal group chat was a mole who was archiving the traffic for the party. Signal has since made efforts to bring anonymous accounts to the platform, which will help thwart such attacks. Though against a state actor it is still not enough unless you take additional measures to obfuscate traffic. And then that still doesn’t protect you against some CCP brownshirt from tailing you and then snatching your phone out of your hand when you unlock it.

            • @[email protected]
              link
              fedilink
              321 days ago

              Leaky keyboards are more than a possibility. Sogou, the biggest one for Chinese typing, got found out a year or so ago for having terrible client-server encryption. They fixed it in an update, but many people didn’t get the update - not to mention it’s still sending every keystroke to Tencent (are the owners I think?) so they could also be saving and analysing private typing anyway.

        • @TCB13
          link
          English
          321 days ago

          Maybe unintentional ways to leak data,

          Yeah, that’s what I think it may be. Just like Apple reporting on all apps you open on un-encrypted HTTP calls and a few other things.

          • sunzu2
            link
            fedilink
            221 days ago

            are you talking about phone notification bullshit and google got caught reporting to government with no warrants.

            • @[email protected]
              link
              fedilink
              220 days ago

              Signal’s defaults are pretty good about that. Push notifications are both opt-in and the information they send can be selected by the user. You can have it say “new message” and that’s it. Or the senders name. Or the whole message.

              I agree that it’s not intuitive that that’s a leak to most people, but push notifications are kind of wonky how they work.

              • sunzu2
                link
                fedilink
                120 days ago

                signal is all around very strong… my main criticism is the “trust signal bro” cult pretending like Signal would not log chats if ordered by the spooks. which is naive AF and feels like they are trying to make normeis comfortable so they don’t demand better.

        • @TCB13
          link
          English
          -2
          edit-2
          20 days ago

          If you don’t turn on the secret chat feature it wont be, yes. However if E2EE was the only deciding factor for a gov to go against an App then they woudln’t be going after Telegram. The fact that govts are going so hard at telegram simply proves that even when the company has access to all our chats they don’t actually provide them to said govts.

          I’m not saying telegram is good from a security perspective, I’m just saying that event without E2EE and all the modern wonders govts can’t still get in because the company doesn’t indulge their requests.