On telegram security and libertarian messaging platforms

English version (translated):

I have been working professionally with messaging for over 15 years.

We set up messaging for banks, healthcare, sports clubs. We have customized, completed and installed a self-hosted Signal server for a large corporation.


A few theses:

  • Modern messaging systems are always a compromise: convenience & functionality VS security. There were and are several decentralized fully secure messengers, but they do not survive. Not because they were destroyed by the special services, but because users are uncomfortable, and the demand for security is not so great that users are ready to pay with money and comfort.
  • A simple example is push notifications. It is convenient and usual for everyone that when someone writes you a message, you will see a quote from this message in your notifications, even if the messenger is not currently running. Users don’t care that these message texts go almost openly through external Apple and Google services. All more secure options lead to inconveniences: either a notification without a quote, or the smartphone’s battery drains faster / it heats up more because a custom push server that is not supported by the OS is used.
  • I can provide at least 10-20 such examples where the average user will always choose convenience between security and convenience.
  • Everyone who really wants secure messaging understands that you have to pay for it and own a server. There is no such thing as free security.
  • The most secure messenger widely available is Signal. It’s even better to run your signal server with Intel SGX support, as well as your push implementation, your TURN server, etc. We know how to do it, but there are literally 20-30 such companies or engineers who know how to do it in the whole world. The forum of the open-source version of Signal is almost silent, someone writes a question once every few months, and there are even fewer answers.
    Not because it’s rocket science, but because there is little demand.
  • The Telegram server is not open source. No one can verify how secure it is, unlike Signal, any XMPP server (Ejabberd, Tigase, Openfire, Prosody), Matrix or Mattermost.
  • Similarly, WhatsApp, FB Messenger, Viber, etc. – none of them provide an open source server, but they are popular because they are convenient and promoted. Personally, when I use messengers, I simply believe that, if necessary, my correspondence can be read by the CIA (WhatsApp, FB Messenger), the CIA, Mossad and Japanese intelligence (Viber), as well as the FSB (Telegram). N.B.: with Signal in the standard consumer version (public server) there is also the possibility of CIA access, but I have no secrets from the CIA or Mossad, so I find it acceptable to use WhatsApp and public Signal. If there were, I would use my messaging server.
  • End-to-end encryption exists, but when the developer has de facto control over the application without regular external audits of the code, I personally do not think that it improves security in any way.
  • In particular, there is experience with Telegram, for example, opposition activists from Belarus to whom KGB showed fully printed telegram chats that had been deleted a long time ago. Durov himself confirmed that their server is not secure. To hope that this will not happen to you because you know how to use secret chats and will carefully monitor the icons of frogs and dogs on the screen and ignore that your end-to-end is inside an already compromised platform, seems to me infantile.
  • Telegram does not equal freedom of speech. It can be said that as a platform it facilitates the existence of channels that can provide information faster and less censored than conventional mass media. But the channels are closed without problems at the request of law enforcement, that is, it is a very incomplete and centrally controlled freedom of speech.
  • Telegram has nothing to do with libertarianism. It is a centralized platform with an opaque ownership and governance structure. You cannot audit the code or run your server. The platform and its token are promoted with the money of Russian oligarchs. The platform token is not governed by an open committee or DAO. All this has nothing in common with libertarianism.
  • If you do not pay for your server and your messenger is not Signal – you do not have secure communications.
  • Don’t look for libertarianism and security in popular centralized platforms. It will not be there by design.
  • If you want secure communications and libertarianism – (1) prepare to pay with money and comfort; (2) run your messaging server on Signal, one of the XMPP servers (I recommend Ejabberd), Matrix, etc. Or build your hypertext quantum fidonet.
    He finished the report.

Ukrainian version (original):

Професійно працюю з меседжингом вже понад 15 років.

Ми ставили меседжинг для банків, healthcare, спортивних клубів. Ми кастомізували, доробили та встановили self-hosted Signal сервер для великої корпорації.

Декілька тез:

Сучасні меседжинг системи це завжди компроміс: зручність & функціонал VS сек’юрність. Було і є декілька децентралізованих повністю сек’юрних месенджерів, але вони не виживають. Не тому що їх знищили спецслужби, а тому що юзерам незручно, і попит на сек’юрність не настільки великий щоб юзери були готові платити грошами та комфортом.

Простий приклад – push notifications. Всім зручно та звично що коли вам хтось напише повідомлення, ви побачите в себе в нотіфікейшенах цитату з цього повідомлення навіть якщо месенджер наразі не запущений. Юзерів не хвилює що ці тексти повідомлень майже відкрито йдуть через зовнішні сервіси Apple та Google. Всі більш сек’юрні варіанти ведуть до незручностей: або нотіфікейшен без цитати, або батарея смартфону швидше садиться / він більше гріється тому що використовується кастомний пуш сервер, що не підтримується ОС.

Я можу навскидь надати 10-20 таких прикладів там де пересічний користувач між безпекою та зручністю _завжди_ обере зручність.

Всі хто дійсно хочуть сек’юрний меседжинг розуміють, що за це треба платити і володіти сервером. Не існує безкоштовної сек’юрності.

Найбільш сек’юрним месенджером з широко доступних є Signal. Ще краще запустити свій сигнал сервер з підтримкою Intel SGX, а також зі своєю реалізацією пушів, своїм TURN сервером тощо. Ми вміємо це робити, але таких компаній або інженерів що вміють це робити буквально 20-30 на весь світ. На форумі open-sourсe версії Signal майже тихо, хтось напише питання раз на декілька місяців, а відповідей ще менше.
Не тому що це rocket science, а тому що _мало попиту_.

Сервер Телеграм не є опен-сорсним. Ніхто не може перевірити наскільки він сек’юрний, на відміну від Signal, будь-якого XMPP серверу (Ejabberd, Tigase, Openfire, Prosody), Matrix або Mattermost.

Так само WhatsApp, FB Messenger, Viber тощо – жоден з них не надає опен-сорсний сервер, але вони популярні тому що зручні та розкручені. Особисто я коли користуюсь месенджерами просто вважаю що за потреби моє листування можуть читати відповідно ЦРУ (WhatsApp, FB Messenger), ЦРУ, Моссад та японська розвідка (Viber), а також ФСБ (Телеграм). N.B.: з Signal в стандартному консьюмерському варіанті (публічний сервер) також є вірогідність доступу ЦРУ, але в мене немає секретів від ЦРУ або Моссаду, тому я вважаю прийнятним користуватися WhatsApp та публічним Signal. Якби були, я б користувався своїм меседжинг сервером.

End-to-end encryption існує, але коли де-факто в розробника контроль над додатком без регулярних зовнішніх аудитів коду, особисто я для себе не вважаю що це якимось чином покращує сек’юрність.

Конкретно з телеграмом є досвід, наприклад, опозіционерів з Білорусі яким гбшка показувала повністю роздруковані ТГ чати, що були давно видалені. Сам Дуров підтверджував, що сервер в них не сек’юрний. Сподіватися що з вами цього не відбудеться тому що ви знаєте як використовувати секретні чати і ретельно будете відстежувати піктограми жабок та собачок на екрані і ігнорувати що ваш end-to-end знаходиться всередині вже скомпроментованої платформи, як на мене це інфантилізм.

Телеграм не дорівнює свобода слова. Можна сказати що як платформа він фасілітує iснування каналів, що можуть надавати інформацію швидше та менш цензуровано ніж ЗМI. Але канали без проблем закриваються по запиту від law enforcement, тобто це дуже неповна і централізовано контрольована свобода слова.

Телеграм немає нічого спільного з лібертаріанством. Це централізована платформа з непрозорою структурою власності та governance. Ви не можете провести аудит коду або запустити свій сервер. Платформа та її токен розкручуються на гроші російських олігархів. Токен платформи не керується відкритим комітетом або DAO. Все це не має _нічого_ _спільного_ з _лібертаріанством_.

Якщо ви не платите за свій сервер і ваш месенджер не Signal – в вас немає сек’юрних комунікацій.

Не шукайте лібертаріанства та сек’юрності в популярних централізованих платформах. Там його не буде by design.

Хочете сек’юрних комунікацій та лібертаріанства – (1) готуйтеся платити грошами та комфортом; (2) запускайте свій меседжинг сервер на Signal, на одному з XMPP серверів (рекомендую Ejabberd), Matrix тощо. Або будуйте свій гіпертекстовий квантовий фідонет.

Доповідь закінчив.

Leave a comment

Your email address will not be published. Required fields are marked *