Investigation by investigative journalism outlet IStories (EN version by OCCRP) shows that Telegram uses a single, FSB-linked company as their infrastructure provider globally.

Telegram’s MTProto protocol also requires a cleartext identifier to be prepended to all client-server messages.

Combined, these two choices by Telegram make it into a surveillance tool.

I am quoted in the IStories story. I also did packet captures, and I dive into the nitty-gritty technical details on my blog.

Packet captures and MTProto deobfuscation library I wrote linked therein so that others can retrace my steps and check my work.

  • Lucy :3@feddit.org
    link
    fedilink
    arrow-up
    15
    arrow-down
    3
    ·
    2 days ago

    I hate how 50% of ‘news’ is literally like “1 equals 1” to me. It’s fucking obvious.

    • ideonek@piefed.social
      link
      fedilink
      English
      arrow-up
      24
      ·
      2 days ago

      Well, it was obvious to you. I’m a casual user, who tries to “do his best” and consider himself “somewhat informed” - obviously not by your standard. It was all news to me, and I find tremendous value in this article.

      • rysiek@szmer.infoOP
        link
        fedilink
        arrow-up
        14
        ·
        2 days ago

        Thank you, that means a lot. For people working in information security it really feels sometimes that a). a lot of stuff is obvious, b). people just don’t listen and don’t care.

        Your comment shows how incorrect this is. That really helps keep motivated.

        • ideonek@piefed.social
          link
          fedilink
          English
          arrow-up
          10
          ·
          2 days ago

          No, I can’t stress enough how much I appreciate it. What I do right now is sending this article with TLDR to all my friends and family.

    • rysiek@szmer.infoOP
      link
      fedilink
      English
      arrow-up
      22
      ·
      edit-2
      2 days ago

      I know, right? That’s why investigative journalism is such a thankless, frustrating job. You need to prove beyond any doubt things that are often pretty obviously true.

      Roman Anin and the rest of the IStories team did an absolutely amazing job. Found court documents going years back. Dug up signed statements and contracts. They did something nobody in the infosec community seemed to have done: actually looked at the IP addresses used by Telegram and followed that lead to its logical conclusion. And then published all of the receipts!

      And still people will say this is “unsubstantiated” or find other ways to wave this off.

      And yet this does move the needle. There is now proof of things we kinda sorta knew was probably true for years. It doesn’t sound like much perhaps, but it’s really important.