[HN Gopher] Telegram will now hand over phone number and IP for ...
       ___________________________________________________________________
        
       Telegram will now hand over phone number and IP for criminal
       suspects
        
       Author : anigbrowl
       Score  : 132 points
       Date   : 2024-09-23 19:28 UTC (3 hours ago)
        
 (HTM) web link (www.theverge.com)
 (TXT) w3m dump (www.theverge.com)
        
       | ElonChrist wrote:
       | Previously posted:
       | 
       | https://news.ycombinator.com/item?id=41629437
       | 
       | https://news.ycombinator.com/item?id=41628467
       | 
       | https://news.ycombinator.com/item?id=41628381
       | 
       | https://news.ycombinator.com/item?id=41628019
        
         | metadat wrote:
         | The only relevant link with discussion is the last one:
         | 
         | https://news.ycombinator.com/item?id=41628019 - 3 hours ago (6
         | comments)
         | 
         | And it's not a dupe, only a related submission (different
         | article / link).
        
       | bediger4000 wrote:
       | About time. Criminals hiding behind some technicalities!
        
         | lostlogin wrote:
         | If you've got something to hide, you're guilty!
         | 
         | /s
        
           | compootr wrote:
           | We don't need privacy! Only criminals want those pesky
           | "privacy policies,, to protect their operations! 1
        
         | JadeNB wrote:
         | There is a difference between "criminal" and "criminal
         | suspect."
        
       | ChrisArchitect wrote:
       | [dupe]
       | 
       | https://news.ycombinator.com/item?id=41628019
        
         | anigbrowl wrote:
         | Dupes are submissions of the same article. I thought this one
         | was better than the others I had seen on this topic.
        
           | ChrisArchitect wrote:
           | You can't submit the same article twice for the most part.
           | Dupes are duplicate _discussions_. There 's an earlier
           | article with some discussion and eventually maybe mods will
           | merge them. No need to split up the discussion. Share your
           | thoughts over there! You could even suggest this link in that
           | thread as a better article option.
        
             | anigbrowl wrote:
             | You totally can, the HN dupe detector is less than
             | reliable. Submit something interesting at night and you'll
             | often see it submitted the following day by someone else.
             | 
             | As a more general point, the fact is that if a discussion
             | doesn't take off while an item is on the front page shortly
             | after submission, it probably never will. The page sorting
             | algorithm ends up prioritizing recency and traction. I
             | agree this isn't ideal.
        
       | Cody-99 wrote:
       | This shouldn't surprise anyone. If a company collects info about
       | some user and the government comes to them with a legitimate
       | warrant they have to handover the information about that user (or
       | risk going to jail/other action by the court) . There is a reason
       | other companies like signal go out of their way to collect as
       | little as possible.
        
         | lostlogin wrote:
         | User data is a liability, not an asset. However this is untrue
         | when breaches, leaks and misuse aren't prosecuted. It's a shame
         | we have ended up here.
        
           | bdjsiqoocwk wrote:
           | > User data is a liability, not an asset.
           | 
           | Yeah Google and Facebook are all losing money in those
           | liabilities.
           | 
           | No theyre not, they're printing money because user data is an
           | asset. Stop repeating silly sound bytes.
        
             | sonofhans wrote:
             | User data is only an asset if your business model demands
             | it, like Google and Facebook. If you don't have, and won't
             | create, a way to monetize it then yes, it's strictly a
             | liability.
        
             | idle_zealot wrote:
             | It's not that it _is_ a liability, it 's that it _should
             | be_. Likewise, it currently is an asset, but shouldn 't be
             | monetizable.
        
           | BadHumans wrote:
           | This is only true if the cost of storing user data is greater
           | than the profits it generates. When companies are allowed to
           | sell out users and punishment for data leaks are just seen as
           | the cost of doing business then why would you not store
           | whatever data you can get your hands on?
        
         | molticrystal wrote:
         | >the government comes to them with a legitimate warrant
         | 
         | Which government, such as the French government for all Russian
         | users, the Russian government for all Ukraine users, or the USA
         | government for all users?
         | 
         | Whose standard for warrants, and how much use of coercion and
         | force are they allowed to use for enforcement. Can the USA
         | kidnap the owners for non-compliance, can the Russians?
        
           | cpa wrote:
           | So what? Legitimate warrants cannot exist? Companies exist
           | somewhere, and they follow the rules that can be enforced on
           | them. I'll take warrents by imperfect democracies over
           | autocracies and dictatorship any day.
        
           | Cody-99 wrote:
           | Where ever they want to do business at. If they expect to be
           | allowed to operate in France/the EU they will have to comply
           | with legitimate French/EU warrants. No one is saying they
           | can't fight it if there is a reason to.
           | 
           | >Can the USA kidnap the owners for non-compliance, can the
           | Russians?
           | 
           | Jailing someone/holding a company in contempt that does
           | business in your country for ignoring legal warrants isn't
           | kidnapping. Trying to frame it that way is pretty silly and
           | disingenuous.
        
           | crabbone wrote:
           | This will depend on how the company is registered and
           | represented in the states it operates in. It will also depend
           | on the citizenship of the kidnapped owners (and whether it
           | will be even necessary, as maybe extradition would also
           | work).
           | 
           | In any case, a court in any particular state will be
           | responsible for issuing the documents entitling the law
           | enforcement to particular data. There's also the process to
           | dispute issuance or legitimacy of such documents, again,
           | through courts.
           | 
           | So, obviously, there isn't a single answer to your questions.
           | But, obviously, they aren't without answer. Any specific case
           | will produce a potentially different set of answers.
        
           | colechristensen wrote:
           | You have to follow the laws in the jurisdictions in which you
           | do business.
           | 
           | If you want to not be subject to the laws of a country you
           | need to blackhole that entire country.
        
           | russdpale wrote:
           | You ask these like they are some kind of gotcha moment, but
           | all of these very simple questions have been answered for
           | decades by international law. You think yourself clever but
           | show yourself ignorant.
        
           | kortilla wrote:
           | You're asking very basic questions that the answers to have
           | been the same for hundreds of years. If you do business in a
           | country you have to answer to its laws or you risk asset
           | forfeiture or arrest.
        
             | standardUser wrote:
             | That would only be true if you step foot in that country or
             | posses assets in that country, right? Though I imagine the
             | US government can reach a lot farther than the Russian or
             | Chinese governments.
        
               | stvltvs wrote:
               | Or the countries you live or travel in have extradition
               | treaties with the other country.
        
             | mistrial9 wrote:
             | remarkably, these are not very basic questions, and the
             | answers are not the same for hundreds of years since this
             | is electronic records that cross international boundaries
        
               | pixl97 wrote:
               | I mean if you were shit talking France when living in
               | England a few hundred years back you're likely to get put
               | on the enemies of France list, even if your pages were
               | for consumption in England. Now if you never left England
               | there wouldn't be much to worry about, unless they
               | suddenly became friends and decided to export your corpse
               | for goodwill.
        
           | limit499karma wrote:
           | > Which government ... Whose standard
           | 
           | It depends entirely on where you land in your private jet.
        
           | dkasper wrote:
           | I think you answered why the only real solutions are
           | 
           | a) don't collect the data (signal approach)
           | 
           | b) hire an army of lawyers and compliance people (big tech
           | approach)
           | 
           | c) ban users from entire countries where you don't comply
           | (common in crypto)
           | 
           | d) risk jailtime or asset forfeiture
        
             | AyyEye wrote:
             | Signal has both phone numbers and IPs.
        
           | hartator wrote:
           | Ha! The devil of the details.
        
         | beefnugs wrote:
         | yep, and reading the news lately "legitimate warrant" means
         | things like "has a harris poster on their lawn"
        
         | krick wrote:
         | Every time someone brings up Signal in these threads I cringe.
         | One can make up stories about spam protection as much as he
         | wants, but given how little (basically none) control one has
         | over him phone number, no messenger strictly requiring a phone
         | number can be considered "privacy-oriented" by any sane person.
        
           | maxwell wrote:
           | What do you advocate for an alternative identifier and how do
           | you combat spam without verifying a phone number?
        
             | pier25 wrote:
             | no IDs, only connect to the users you choose to connect
             | with
             | 
             | SimpleX comes to mind
             | 
             | https://simplex.chat/
        
           | fragmede wrote:
           | they have usernames now
        
           | Cody-99 wrote:
           | Huh?
           | 
           | I think you are confusing "privacy-oriented" and anonymous!
           | Signal is pretty privacy oriented since it has E2EE by
           | default (and so does Whatsapp). Telegram would be much more
           | privacy oriented if it had E2EE by default.
        
         | upofadown wrote:
         | The incentive is to _claim_ to collect as little as possible.
         | What a company _actually_ collects is between them and any
         | influential state actor that can manage to make use of the data
         | in secret. A company can 't support the needs of such an actor
         | and law enforcement at the same time.
        
           | slt2021 wrote:
           | you care confusing _collecting_ data with _persisting_ user
           | data.
           | 
           | it is easy to prove what your app collects from OS's
           | permission model and web traffic. People are less interested
           | in whether you store it for future use or discard it
           | immediately after receiving.
           | 
           | Even if you claim you don't persist any of user data, you
           | would still be collecting it
        
         | whycome wrote:
         | "Legitimate warrant" is a flexible and fluctuating idea. When a
         | new government takes over, they may want information on all
         | potential opposition.
        
         | chemmail wrote:
         | But my crypto bro friends said they would only communicate by
         | Telegram because it is 1000% secure!
        
       | TZubiri wrote:
       | Sounds good to me
        
       | sharpshadow wrote:
       | Good that the company is able to continue functioning with the
       | CEO being trapped and under charges. Shame on France for pulling
       | a nasty warrant mid air.
        
         | bdjsiqoocwk wrote:
         | Well, the fact that Telegram wants to cooperate to me suggests
         | that they previously could have been cooperating but weren't,
         | which makes a charge of complicity make a lot more sense now.
         | Thanks France!
        
           | maipen wrote:
           | You are part of the problem.
           | 
           | Suspect, try to find excuses to arrest and then go look for
           | evidence.
           | 
           | Suggests, implies, I believe, blablabla. All nonsense.
           | 
           | That's tyranny.
        
             | rmbyrro wrote:
             | It looks like we need tyranny from time to time so that
             | people learn why lots of people died to earn basic
             | rights...
             | 
             | It's always tempting. "We're only doing it to get the bad
             | criminals!"
             | 
             | Sounds great. Until a tyrant decides you're bad.
        
       | harryf wrote:
       | It's sad to see HN become so full of bots.
       | 
       | > prompt: There's an article on Hackernews titled "Telegram will
       | now hand over your phone number and IP if you're a criminal
       | suspect". Generate a comment in Hackernews style that supports
       | this decision, implies that it's because they didn't encrypt the
       | messages and uses Signal as an example of doing it right because
       | "look! They haven't had problems"
       | 
       | Not surprised. Telegram doesn't encrypt by default, so of course
       | they're handing over phone numbers and IPs. If you don't lock
       | things down like Signal does, you're going to have problems.
       | Signal can't hand over what they don't have--encrypted end-to-
       | end, no metadata. Simple as that.
        
         | handity wrote:
         | I guess I'm a bot then.
         | 
         | Yes, channels and groups are most likely what makes Telegram a
         | threat where Signal isn't. That's an excellent argument for
         | decentralized social media.
         | 
         | You're probably exasperated that others don't see what to you
         | seems like an obvious truth. Rather than mocking the opposing
         | argument, it's probably still worth rehashing yours when the
         | topic comes up, even if it feels like banging the same drum
         | with nobody listening.
        
       | handity wrote:
       | This was entirely predictable and inevitable. I don't understand
       | what Durov thought would happen nor why he rejects E2EE as a
       | liberating technology.
       | 
       | Policy will never be the key to digital privacy, it must always
       | be accompanied by cryptography. The status quo of allowing a
       | third party read and store your messages forever, slurping up all
       | the metadata along the way, is insane.
        
       | pier25 wrote:
       | Honestly you have to be a bit dumb to write incriminating stuff
       | on popular messaging apps like Telegram, Whatsapp, etc.
       | 
       | I would imagine any serious criminal org will have their own
       | messaging infra by now.
        
         | quesera wrote:
         | > _I would imagine any serious criminal org will have their own
         | messaging infra by now._
         | 
         | I'm guessing they do not -- that would be inconvenient,
         | expensive, unreliable, insecure, and/or conspicuous.
        
           | LinuxBender wrote:
           | _I 'm guessing they do not -- that would be inconvenient,
           | expensive, unreliable, insecure, and/or conspicuous._
           | 
           | Some do run their own platforms or share a self hosted
           | platform set up by people in a non cooperating country.
           | Sometimes the platform admins find out they were being MitM
           | by mistake tech or law enforcement make. [1] Or not using the
           | MitM detection Jabber is capable of. Jabber scales to
           | millions of users per cluster, big enough for probably most
           | criminal organizations. I doubt the cluster in question was
           | specifically meant for criminals, but the smart criminals
           | will find solutions best suited for their needs.
           | 
           | In my humble opinion the big shared corporate platforms will
           | attract the ultra-lazy arrogant and cavalier criminals and
           | I'm sure law enforcement are fine with it. Easy busts still
           | look good to justify big budgets. There are probably people
           | that say they don't know anyone that's been busted on those
           | platforms but they are probably not moving enough volume of
           | illicit goods to warrant immediate attention. That
           | information would be quite useful however if the target was
           | suspected of something else or if they were an influencer
           | _thinking or saying the wrong thing in public_.
           | 
           |  _[Edit]_ Updated link to the snapshot describing potential
           | mitigations including SCRAM PLUS _which was not configured in
           | this incident_.
           | 
           | [1] - https://archive.ph/4wi5t
        
           | pier25 wrote:
           | More insecure than an app that keeps track of everything in a
           | database you cannot control and can be accessed by the
           | authorities?
           | 
           | Even when deleting messages how can you trust these are
           | actually being hard deleted?
           | 
           | I would imagine the inconvenience and cost are worth it but
           | what do I know... I'm not a criminal :P
        
         | rikafurude21 wrote:
         | catching low hanging fruit is useful for authorities too, but
         | the point is not catching criminals of any kind- western
         | countries want to be able to police speech and jail their
         | citizens for wrongthink.
        
         | standardUser wrote:
         | I know people who order drugs all the time via various
         | messaging apps, in the US and throughout Latin America. Often
         | the messages and menus are highly explicit.
        
       | janmo wrote:
       | In a sense the surveillance in the "west" and in particular in
       | the EU is worse than what you have in China.
       | 
       | At least the Chinese they know that all their conversations are
       | being monitored and read by the government.
       | 
       | In the EU many people still live under the illusion of GDPR, data
       | privacy, democracy etc...
        
       | sub7 wrote:
       | They are coming for you Tether
        
       | cb86 wrote:
       | Warrant canary removed:
       | https://opentermsarchive.org/en/memos/telegram-expands-forbi...
        
         | yieldcrv wrote:
         | Hm, given how many requests Meta and Google disclose annually
         | 
         | I dont think a warrant canary is really useful, it implies "we
         | just got 1!" instead of "we just got an additional pile of 200
         | secret requests from G-7 national governments, one of which is
         | already trying to incarcerate us for not being so forthcoming
         | about compliance"
        
       | sirolimus wrote:
       | Well that's a shame...
        
       ___________________________________________________________________
       (page generated 2024-09-23 23:01 UTC)