39 comments

[ 4.1 ms ] story [ 87.3 ms ] thread
"Won't somebody think of the children!" over and over and over as the rallying call and justification for tyranny. These proposed technical schemes are both incredibly invasive and will be completely ineffective. Another trait of "think of the children" inspired violations. The unprecedented arrest of founder Pavel Durov to force this on the company further confirms what this is and what it isn't: it is not about child safety.
> The unprecedented arrest of founder Pavel Durov to force this on the company further confirms what this is and what it isn't: it is not about child safety.

What?

He was arrested for running a service that was hosting CSAM (illegal, and correctly so by most people's ethical systems) and not giving reasonable effort to take it down (illegal, and correctly so by most people's ethical systems).

I think you're just reflexively anti-moderation because it's the chic thing these days, but you're kind of ideology-ing yourself into an awkward corner on this particular case.

>awkward corner

Is that awkward corner "let the government (pick any) censor your platform, or you're a pdf file"?

It's all so tiresome.

No, but hosting CSAM and not moderating it does make you liable of certain crimes in many jurisdictions!
To @superkuh's point, I would believe that part of his bail negotiation package was to make Telegram more "transparent" for governments.
If you are defending digital free speech and privacy, against the wishes of governments, you are defending the opportunity to spread CSAM.

Necessarily. Data is data.

You may not like that, but you have to choose which is your higher priority: A world that contains platforms which permit digital free speech & privacy despite the preferences of government, or a world with a little less CSAM.

We could always try and prosecute the extraordinarily rare child sexual abusor who is highly social (spreading/selling evidence against them), just like we try and prosecute terrorism or left-wing social activism: With an abundance of enthusiastic government infiltrators and investigators eager to build a case against somebody, rather than with prescriptive automatic filters or with mandatory enthusiastic private-sector infiltrators.

"If you're defending the right for women to leave the household and work in co-ed spaces, you are defending the opportunity to rape."

This is what you sound like to me.

There's lots of rape inside households. Most, even.

The only prescriptive, airtight solution is surgically modifying males so that they can't rape any more. Not a fan, but I suppose that depends on how certain we have to be that rape isn't occurring. How important is it to you?

We could do a halfway thing where we install cameras in every room of every house to gather evidence against rapists.

The latter is what we do with most digital communication platforms right now in order to try and track down CSAM. Durov got arrested for not paying people specifically to watch those cameras and call the police.

Uhhh no, he got arrested for not taking down content even after other people (including nation states) reported it to him.

From the indictment:

> JUNALCO's cybercrime unit (J3) was informed of Telegram's near-total lack of response to judicial requests, particularly by OFMIN (National Office for Minors). Other French investigation services, prosecutors, and Eurojust partners, notably Belgian, shared the same observation. This led JUNALCO to open an investigation into potential criminal liability of the messaging service's leaders.

> The only prescriptive, airtight solution is surgically modifying males so that they can't rape any more.

Your solution only works if you think that women can't and don't rape people, including other women. Reality strongly disagrees.

Ultimately it all comes down to freedom vs security. We could force people to have surgery and lock them indoors to keep them safe, or we can accept putting ourselves in some amount of risk in exchange for giving ourselves more freedom.

Actually we have empirical disproofs of this called "nearly every major social media network in existence."
What are you talking about?

Most social media networks base their entire business model on selling your data. On practically none of them does privacy exist. And most of them would close up shop or sell out overnight if banned by a government.

Large American social media platforms stand up to hundreds of data requests from governments, both foreign and especially American, every day. Get a grip.
I would say in this moment highly moderated spaces (bluesky, mastadon) are more 'chic' than anything-goes spaces (4chan, twitter)

there are plenty of techies who believed in freedom from being surveilled by government censors without any social pressure to be cool or rebellious or whatever. It's just a principal someone can hold, doesn't have to have anything to do with peer pressure

Bluesky moderation is largely consensual (as is Mastodon moderation in theory, though unless you run your own instance you deputise it to whoever runs your instance in practice); to a large extent, if you don't use blocklists or moderation services, it's almost unmoderated, except for illegal content. I'd argue less 'moderated' than Twitter, really, in that it doesn't by default do things like downrank links.
I know libsoftikok and TERFs are lightning rods, but it is untrue that bluesky leaves moderation to the individual. Accounts posting squarely legal content are removed by the site administrators because the community demands that they not have to deal with 'nazis and bigots'

I like the architecture of bluesky a lot but it doesn't fulfill its promise until third-parties go through the trouble of hosting relays and appviews so that people whose opinion the first party admins finds objectionable could still communicate.

> Accounts posting squarely legal content are removed by the site administrators because the community demands that they not have to deal with 'nazis and bigots'

I'm not sure that that is true. I subscribe to a blocklist of transphobes, which has literally thousands of people on it. I suspect that libsoftiktok et al were getting performatively banned by putting bigoted content in their _profiles_, which _are_ somewhat heavily moderated.

(Though, actually, that libsoftiktok arsehole does sometimes sic her followers on named people, which is verboten, so maybe it was that.)

Hm, fair, thanks for the counterpoint. I do think the people who got kicked got kicked because they were coming with the intent to troll and harass, but the fact that the site admins intervene in these cases is evidence that they don't have confidence in the community moderation tools so far, and theyre still curating access, which is fine, it's just not very distributed of them.
> It's just a principal someone can hold, doesn't have to have anything to do with peer pressure

Other cultures: All about signaling

Mine: All about real principles

(comment deleted)
Maybe it isn't about child safety, but something else. But in that case the whole thing is a conspiracy, where some top politicians push for it for some secret reason under the disguise of another reason. How broad would such a conspiracy be?

Such thing would be more common in domestic politics I feel, because there are tighter circles in the governance of a country. But for something Europe-wide it must be much harder to pull off under some false pretense.

Marijuana is illegal in most of Europe. And we got the reason for that policy straight from Nixon campaign strategists: it made for an easy justification to crack down on and vilify minorities and left wing counter culture groups. So yes, they use Big Lie in europe as well.
The only people who need to be in on the conspiracy are those who 1) see through the superficial narrative and 2) have any power to change the course of its implementation. I suspect that list is quite small.
A plausible source of these sorts of things is that some government(s) fund their intelligence service to do signals intelligence, but intelligence services commonly have no morals or accountability because they operate in secret and claim national security whenever anyone comes to question their activities.

So they use the money to lobby for mechanisms to have backdoors or chokepoints installed, or require vulnerabilities the equivalent of backdoors, and use dirty and illegal tricks under the table to get them passed. The governments they're lobbying usually aren't even the ones paying them, though maybe sometimes they are.

It's basically the equivalent of Dual EC DRBG but targeting the legislative process instead of a standards body, and obviously an inherently difficult thing to prove in an individual case, but the response to it should be the same in any case: Don't pass laws that would be to the advantage of a foreign intelligence service. You certainly don't want to give them the damn thing whether they're the ones pushing for it or not.

The most effective propaganda has an element of the truth in it.

The usual tech argument I see in cases like this are about how important encryption is and how that can't be given up for law enforcement. That doesn't work so well here, because Telegram doesn't really have a good E2E encryption setup, just the reputation for it.

But even where that argument does hold, people being people, it's completely coherent for 90% of politicians to believe that this specific crime is genuinely the real cause, when the actual cause is something know only to ministers aware of certain state secrets.

For example, compare and contrast:

1. If the real reason is "this specific government is actually banana republic", governments doing this is bad and allows their preferred people to engage in further corruption and destabilisation of said government while spying freely on anyone who would oppose them.

2. If the real reason is "there's several dozen foreign governments and organised criminal groups who are all using platforms like these to try to destabilise us", then it's important to lie about it as much as possible so that those foreign governments and organised criminal groups don't catch on.

Encryption that a nation can't break, does not merely enable free association to organise democratically against the nation, it really does also allow various crimes against the laws of a nation. That includes this specific crime, but that being true doesn't require this specific crime to be the real reason behind the push.

I have absolutely no idea how this is all going to play out. States can't really function long-term if they permit encryption they themselves can't break, it's not stable; at the same time, economies can't function without encryption that foreign states can't break because that's unstable in a different way. And then there's smart dust, coming soon to paint tins near you.

> If the real reason is "there's several dozen foreign governments and organised criminal groups who are all using platforms like these to try to destabilise us", then it's important to lie about it as much as possible so that those foreign governments and organised criminal groups don't catch on.

If this was the real reason then they couldn't be advocating for bills to compromise the security of those systems, because the actual bad guys can perform logical deduction and conclude that the same compromises could be used against them and then switch to some other system.

> States can't really function long-term if they permit encryption they themselves can't break, it's not stable

This has been the case for quite some time and it's not only completely fine but in line with historical norms. Historically governments didn't have the capacity to intercept communications en masse, and the majority of communication took place in person with no record of what was said outside of the minds of the people in the room.

Meanwhile targeted interception will always be available because governments can, in the limit, physically install bugs to record the target's conversations or passwords. And to the extent that you're dealing with a sophisticated adversary that knows how to scan for bugs, you're well past the point that legislating backdoors in messaging apps is relevant because a sophisticated adversary can use already-existent open source messaging systems without them.

(comment deleted)
Nearly every single measure anyone ever proposes to address child abuse, regardless of its merits or lack thereof, gets immediately dismissed as a generic "Won't someone thing of the children!" situation.

That isn't really useful and is probably a good part of why the people making such arguments are ignored by the people who actually make the laws.

The fact that we're having this discussion at all is because Telegram is not end to end encrypted by default (and groups chats are never E2E encrypted).

I tried to explain this fact to a lot of my friends but I always received of pushback, "it can't be true", "of course it's encrypted, it says on the web page it's secure!", etc. I cannot think of any other occasion where the reality of a situation is the exact opposite of what people think.

How did Telegram achieve perpetuating this lie? And more importantly, how do we stop it? What is a good resource to provide to people who think this is true? I usually send them an article written by Matthew Green[1], but it has always been dismissed as just "some dude's blog".

A lot of people are technical just enough to become dangerous. When I explained the problem to a lot of my friends they ran wireshark on the network connection and they saw gibberish. From this they have erroneously concluded they are safe...

[1] https://blog.cryptographyengineering.com/2024/08/25/telegram...

I'm impressed someone knows to use wireshark without knowing what HTTPS is (specifically, a connection the server decrypts).

But yeah, similar experience around telegram, I guess somehow it's bucketed as a competitor to Signal and people just expect feature parity ?

> How did Telegram achieve perpetuating this lie?

They never actually lied about it as such. They just used terms around security a lot in their marketing, and people assumed.

That's what's usually called a lie of omission.
Yep, but it's notoriously difficult to prosecute.
> How did Telegram achieve perpetuating this lie?

Marketing. Specifically, very aggressive marketing that used a combination of "you can't trust them, we're the only ones keeping you safe" messaging re: WhatsApp and exaggerating+exploiting complaints about Signal and Moxie Marlinspike, to get support from earnest-but-uninformed tech types who went on to evangelize it to others, thinking they were doing a good thing for the world (like the early days of Firefox). It was a very cynical campaign and depressing how well it worked, even after their hand-rolled crypto was broken like a day after the initial fanfare-filled release.

As we know, there’s no such thing as an expert, everyone is equally ignorant or knowledgeable about everything, and there’s no reason to trust anyone’s opinion over anyone else’s opinion, especially if they disagree with your preconceptions or their opinion is inconvenient to you. They “did their research” themselves with Wireshark.
> A lot of people are technical just enough to become dangerous. When I explained the problem to a lot of my friends they ran wireshark on the network connection and they saw gibberish. From this they have erroneously concluded they are safe...

To me, that doesn't sound like technical "enough". And that's not more dangerous than non-technical people trusting a website saying "we secure your data with military-grade encryption".

From my anecdata I don’t know anyone who thinks group chats are E2E encrypted or even “safe” in general. In my circles it’s sorta common knowledge even among non-technical people that secret chats are the safest ones. That said - nobody seems to care either way just because it’s too damn convenient (for now - Telegram has been actively enshittifying for years now)
(comment deleted)
The title is misleading. It implies that Telegram was not moderating content at all, but from the article:

> Telegram says that before becoming a member of IWF it removed hundreds of thousands of pieces of abuse material each month using its own systems. The IWF membership will strengthen its mechanisms, the company said.

They were already removing this kind of content. The decision was to partner with IWF.