Hacker News new | ask | show | jobs
by ufmace 15 days ago
I don't think anyone cares about E2E encryption as much as tech people think.

For all of the much-vaunted complains about their lack of it, I am not aware of any proof or credible claims that Telegram the company has ever revealed the contents of non-encrypted messages or group chats.

Meanwhile, I don't think any authorities actually care about to what extent E2E Encryption makes it harder for Signal the corporation to extract message data. There's plenty of other ways to skin that cat - on-device compromises, abuse of backup mechanisms, abuse of mechanisms to manage linked devices, etc. They'd go after them just the same if they thought there was anything they really wanted on there.

If there's any real difference, I think it's most likely because many more of the group chats that such authorities are aware of and find "interesting" are on Telegram because basically nobody really does E2E well in medium-large groups right now.

1 comments

Telegram is in very big trouble all the time for refusal to comply with court orders they're capable of complying with, which is related to E2EE.
That's vague to the point of being completely meaningless. Do you have any examples of a time they've been in "very big trouble", whatever that means? Exactly how often constitutes "all the time"? Do you have an example of a valid court order in any jurisdiction that they have failed to comply with? Do you have any examples of a court not mandating similar compliance for Signal, iMessage, or any other E2EE platform due to that? There is no exception in the law for E2EE and it will not save you from consequences from failing to comply with a valid court order.
Famously, Pavel Durov (owner of Telegram) was arrested in France a couple of years ago and held in custody until he complied with one he'd received earlier.

Famously, Signal complies with court orders by giving up all the data that's requested that it has, which isn't very much. This is what you expect from E2EE platforms.

A court order to do the impossible is invalid. Telegram gets in trouble because it's possible for them to comply but they choose not to. Subpoenas are usually worded as "you must provide all information you have, relating to ..."

But as long as Signal controls the client app, there are very possible court orders to provide access to "encrypted" user chats even if courts haven't made use of those yet (as far as is publicly known).
The published reports of the exact things requested of them in the French arrest seem pretty vague. If they're related to the security of private messages and chats, it would seem to prove the point that they do infact refuse to provide that for anybody. The details around his release seem even more vague. We have only speculation and no actual proof that he or Telegram caved on such a request. As far as I know, we've never seen any charges that definitely came from Telegram revealing the messages of a private group chat.

Meanwhile, if you believe that any Governments actually refrain from prosecuting Signal executives due to their refusal and/or inability to produce the messages from private chats because they have E2EE, well, I've got a nice bridge to sell you.

If they actually are refraining from going after Signal executives in a similar fashion, most likely either 1. Nobody is actually using it for anything interesting, 2. They are actually secretly cooperating somehow, or 3. Governments are already happy with other technical means of extracting the contents of Signal chats they are interested in. See the US FBI's curious sudden lack of interest in Apple's ability, or lack thereof, to extract a wanted suspect's iMessage messages.