Of course we launched our Telegram channel just this weekend, so I am feeling pretty happy that I enforced a 15-year old SOP that says "never email links to 3rd-party domains ; always use a redirect"...
Swapping the redirect now for telegram.me, which hopefully won't go down simultaneously
I think you also misunderstood, they are suggesting OP redirect to a telegram domain that isn't on the .me TLD, as the other .me is potentially at risk of also being taken down.
I found this post:
"I contacted Identity Digital, the registry operator for the .ME domain zone, to request the reason why t.me was placed on "serverHold".
The company has now responded and confirmed that the domain was suspended due to OFAC-related compliance requirements.
The domain t.me has been placed on serverHold due to OFAC-related compliance requirements
Identity Digital also stated that, under its agreements with accredited registrars, it cannot provide further details directly to third parties. Any additional communication regarding the registry action must go through the domain's registrar, GoDaddy." [weird response, this is a serverHold, not a client lock]
As you can see, the Montenegrin government is NOT at fault. It’s a decision made by the two biggest stakeholders in the .ME registry, which together hold over 70%: the American companies GoDaddy and Identity Digital. In my opinion, it’s extremely sad that the countries managing TLDs have so little autonomy and are also constantly accused of doing wrong when it’s not their fault.
OFAC just announced sanctions against a VPN provider that had a t.me link listed as its website. I wonder if that's what triggered the t.me ban? They saw the domain in the filing and went, "Yep, ban the whole thing."
I think you're being sarcastic? Because you don't believe they are responsible for the actions of their agents?
If I hire someone to file my taxes, and they lie/cheat/steal. I'm still going to jail.
I don't think they should be required to answer for this fuck up, but if they not angry at their chosen agents, it's because they're on the wrong side, and deserve some blame too.
I must have completely read your comment backwards. I thought you were suggesting they didn't have any fault. But you're saying it'd be better if managed their domain themselves, that I completely agree with.
Curiously enough, .me's whois record does not list Identity Digital as a contact (as seems to be standard practice with externally-managed ccTLDs, such as .gi), and .me is not listed on Identity Digital's "TLD Portfolio"[0]
On the other hand, all of their infrastructure (registry websites, nameservers, whois server) are hosted on Identity Digital, Godaddy, and Afilias IPs. Does anyone know what the relationship between .me and Identity Digital is?
Absolutely.
According to a recent Montenegro government document, doMEn is owned by:
GoDaddy.com LLC 38.352%
Identity Digital Limited 36.848%
ME-net (local montenegrinian network) 24.8%.
I thought this was a long solved problem: the server syncs encrypted data, and the user provides the decryption key from another device (via QR codes, BLE, …)
Since when did registars care about the political positions of its clients? They could have registered on cloudflare or namecheap and I doubt they'd bat an eye. Telegram is mainstream enough that nobody is going to cancel them, unlike kiwi farms or 4chan.
registrars are bound by the political whims of those that allow them to exist there have been multiple domains that have been shut down at the behest of certain governments even when its well beyond their jurisdiction
kiwi farms and 4chan are relatively harmless compare to what Telegram enables yet kiwi farms was taken offline at the behest of a political camp that has certain opinions about very basic stuffs that shouldn't even be grounds to be considered.
>kiwi farms and 4chan are relatively harmless compare to what Telegram enables yet kiwi farms was taken offline at the behest of a political camp that has certain opinions about very basic stuffs that shouldn't even be grounds to be considered.
For most people, the % of content that's "harmful" matters more than absolute harm numbers. This is a good thing, because otherwise after telegram, the next app to be canceled would be signal.
> kiwi farms and 4chan are relatively harmless compare to what Telegram enables yet kiwi farms was taken offline at the behest of a political camp that has certain opinions about very basic stuffs that shouldn't even be grounds to be considered.
Literally what the fuck is this take? Kiwifarms' central purpose for existing is to organize doxxing and harassment efforts. It has harassed multiple people into committing suicide, and celebrates these murders as achievements. It is shameless to downplay that in the way you're doing.
4chan and Telegram are completely unrelated. They are low-censorship platforms. People can misuse them to commit harm, as they can misuse any place they're allowed to speak with privacy/anonymity, but the platforms do not exist for the explicit purpose to cause harm.
News outlets have been reporting on how the Terrorgram, O9A, 764, and murder loving European fascist groups have been organizing on Telegram (it's in the name!) for years.
Discord at least attempts to do some moderation about this.
Telegram's strategy to deal with violent extremist groups on its platform is to not ban them but just make it hard to discover. But this doesn't stop someone already in the groups from inviting their buddies. I bet they actually prefer it this way.
They subscribe to a belief that private speech should not be surveilled. I'm partial to their views. For all of human history, any two people could get together and privately talk. Talk about anything, including committing crimes. Now communication methods have changed but people still want to get together and talk about things, privately. Some of those things include crime, sure. The problem is it's not your freaking business what anyone is talking about privately. As soon as you open the door to surveillance "because crime", now you also have surveillance because you disagree with the government. And when it comes to internet surveillance, everything is preserved forever and also sold/leaked routinely, so you're really committing to leaking everyone's private life to anyone who is interested, forever. The internet is such an integral part of how most people communicate that "just don't say anything personal on the internet, ever" is not in any way reality.
I think this is not a line that can afford to be crossed. It is better for criminals and terrorists to be able to communicate privately than it is for no human anywhere ever to be able to communicate privately. It is not worth stripping the rights of billions of people to target a tiny minority of bad actors. And, given the trivial potential for authoritarian governments to misuse the power of absolute surveillance, I think the world we end up in would be much, much worse. Allowing nobody to privately communicate opposition to the government will lead to much worse outcomes than allowing nobody to privately communicate about crime, despite best intentions in short-term-thinking harm reduction.
In addition to the criminal groups you mention it being wanted in Europe for, Telegram is also being prosecuted in Russia for harboring anti-Putin-regime activists! Such is the inherent nature of private communication.
Do you want privacy, or do you want back doors into everything?
Usually, the backdoor on apply to "regular" citizens, while the governments and military get exemptions from it.
If the balance of power wasnt so asymmetrical I would be inclined to emphasize with the position that E2EE is a bit of an over-correction. We would be remiss to ignore the practical concerns about nefarious actors using it to organize.
HOWEVER, we would ALSO be remiss to ignore the imbalance of power it would cause if ONLY the governments are privy to secrecy...
Violent extremist groups can also meet in parks and go to a bars. Police should follow everyone around and make everyone wear mandatory surveillance devices. Let's call them portable telescreen.
> You won't die just because someone posts your passport online.
Jesus, do you have the object permanence of a 3-year-old? This part alone, no. But this then directly leads to hundreds of people harassing you, everyone you know, blackmailing you, etc. People get fired because their workplace doesn't want to deal with it, for fuck's sake.
GoDaddy is just a general clusterfuck of arbitrary decisions. I don't have anything ready offhand to point to, but the general consensus is that you should avoid GoDaddy pretty vehemently.
You can read an explanation of the status codes on the icann website.
The explanation for clientRenewProhibited was interesting:
"This status code tells your domain's registry to reject requests to renew your domain. It is an uncommon status that is usually enacted during legal disputes or when your domain is subject to deletion."
Similar language for some of the other statuses like serverDeleteProhibited.
No, not being able to renew the domain due to the max renew ahead policy (it's registry-specific but also 10 years for .me) does not result in the clientRenewProhibited flag for .me.
(Yes, but it expires at 2035-05-20. If you count years by rounding up to integers, there's not enough time room to renew it an additional year. It would make it 11 years.)
Same for dog years, but why are we inventing ways to make it seem more than 10 years out when registries, quite reasonably, just use the date normally?
> To the best of my knowledge, a domain can only be renewed in advance for up to 10 years.
That is the rule for COM/NET/ORG. ccTLDs can do what they please.
That said, as a registrar I highly recommend people renew important domains for 9 years. It gives you maximum buffer but allows you to transfer to a new registrar even if your old or new one has the same misconception hard coded.
The DNS isn't 50 years old. There's absolutely no certainty your payment for the last year's will mean anything. Also if you're older than 35, you'll probably be dead. If you're not dead you probably won't care about the domain any more. Certainly all current politicians and the current political and economic systems will be dead. It's unclear there will be any reason to still have the domain and that it won't be blocking some innovative economic activity. It's unclear there will still be an internet.
It won't protect you against the country hosting the registry being nuked but it will likely shield you from future price hikes because not honoring pas renewals would quickly get the registry a reputation for being a fraud. Which is probably also why there is a limit - no registry wants to be bound by arbitrary long timed liabilities.
“This status code is set by your domain's Registry Operator. Your domain is not activated in the DNS.”
Also the serverDeleteProhibited status is active, which ICANN also admits is a weird and rare one:
“This status code prevents your domain from being deleted. It is an uncommon status that is usually enacted during legal disputes, at your request, or when a redemptionPeriod status is in place.”
Mind you, this is ICANN's description, which applies to global domains and not country domains like .me. Country registries can (and do!) assign different meanings to these statuses; for example in .pl clientRenewProhibited has a completely different meaning.
Telegram is currently the target of legal/regulatory investigations by Russia (alleged extremism), France (likewise), and India (alleged facilitation of national exam leaking/cheating). I'm guessing the latter since it's the most recent and arguably has the most fiscal heft.
Also very surprised to see Telegram was reliant on GoDaddy, notorious for its lack of transparency.
But Telegram hasn't engaged in that, some of their users have.
I think the issue might be that although Telegram has a lot of abuse takedown activity, they do not permit access or direct action by authorities. If I recall, they have reiterated many times that some level or types of messages always remain private.
Maybe that's the issue is that a lot of illicit activity is going on in private channels and whether or not their filtering addresses it at all, authorities see the activity and have no access for court cases or direct action against it, so they can imagine it is quite rampant.
Other platforms either don't have the requested data (Signal) or willingly hand it over when they get a court order to (Facebook). When Telegram gets a court order it ignores the court order and then makes Pavel Durov hard to physically find and therefore arrest. One can only guess what motivations he has for this.
So courts seek alternative enforcement mechanisms.
I'm not making an argument about who's right or whether these disputes have any merit, I'm just trying to guess who might have had the inclination and legal resources to make this happen.
I always figured telegram got the screws turned on them all the time because their lack of E2E encryption meant it was viable to demand they proactively police the platform in the first place. Maybe Signal would just be outright blocked in these locales if it was anywhere near as popular, though.
I don't think anyone cares about E2E encryption as much as tech people think.
For all of the much-vaunted complains about their lack of it, I am not aware of any proof or credible claims that Telegram the company has ever revealed the contents of non-encrypted messages or group chats.
Meanwhile, I don't think any authorities actually care about to what extent E2E Encryption makes it harder for Signal the corporation to extract message data. There's plenty of other ways to skin that cat - on-device compromises, abuse of backup mechanisms, abuse of mechanisms to manage linked devices, etc. They'd go after them just the same if they thought there was anything they really wanted on there.
If there's any real difference, I think it's most likely because many more of the group chats that such authorities are aware of and find "interesting" are on Telegram because basically nobody really does E2E well in medium-large groups right now.
That's vague to the point of being completely meaningless. Do you have any examples of a time they've been in "very big trouble", whatever that means? Exactly how often constitutes "all the time"? Do you have an example of a valid court order in any jurisdiction that they have failed to comply with? Do you have any examples of a court not mandating similar compliance for Signal, iMessage, or any other E2EE platform due to that? There is no exception in the law for E2EE and it will not save you from consequences from failing to comply with a valid court order.
Famously, Pavel Durov (owner of Telegram) was arrested in France a couple of years ago and held in custody until he complied with one he'd received earlier.
Famously, Signal complies with court orders by giving up all the data that's requested that it has, which isn't very much. This is what you expect from E2EE platforms.
A court order to do the impossible is invalid. Telegram gets in trouble because it's possible for them to comply but they choose not to. Subpoenas are usually worded as "you must provide all information you have, relating to ..."
But as long as Signal controls the client app, there are very possible court orders to provide access to "encrypted" user chats even if courts haven't made use of those yet (as far as is publicly known).
The published reports of the exact things requested of them in the French arrest seem pretty vague. If they're related to the security of private messages and chats, it would seem to prove the point that they do infact refuse to provide that for anybody. The details around his release seem even more vague. We have only speculation and no actual proof that he or Telegram caved on such a request. As far as I know, we've never seen any charges that definitely came from Telegram revealing the messages of a private group chat.
Meanwhile, if you believe that any Governments actually refrain from prosecuting Signal executives due to their refusal and/or inability to produce the messages from private chats because they have E2EE, well, I've got a nice bridge to sell you.
If they actually are refraining from going after Signal executives in a similar fashion, most likely either 1. Nobody is actually using it for anything interesting, 2. They are actually secretly cooperating somehow, or 3. Governments are already happy with other technical means of extracting the contents of Signal chats they are interested in. See the US FBI's curious sudden lack of interest in Apple's ability, or lack thereof, to extract a wanted suspect's iMessage messages.
They generally don't have to proactively police it, but they have to answer court orders in every country that has courts, or they'll be in trouble in that country. And countries are free to cooperate with each other to enforce these.
Pavel Durov was arrested when he traveled to France because Telegram was noncompliant with French court orders. You can ignore them in Russia... you can't ignore them in France. And you can ignore Russian court orders in France but not in Russia. And the Russian or Indian court is free to ask the Montenegrin government to suspend your domain name and the Montenegrin government is free to agree or disagree.
Signal is already well known to governments. In fact a few years ago there was a report in the UK media about how some governments used signal instead of official channels like email and did so because of Signals disappearing messages feature (ie making those MPs less accountable).
More recently, a Signal chat record leaked, between US national security advisor Mike Waltz, US VP JD Vance and others, regarding the ongoing illegal assassinations in Yemen:
I've been in quite many Telegram chats, none of which has enabled it. For most practical purposes you can just consider Telegram not to have e2e since it's no good if it's not used.
>But Telegram hasn't engaged in that, some of their users have.
Yeah, but government workers just want a legal slam dunk to call it a day and collect the glory, and it's always easier to go after the platform where the crimes are being discussed, rather than after the individual users actually committing the crimes.
It's how government, prosecution and law enforcement jobs are incentivized to operate.
It's more likely they did go after the individual users, by sending a demand to Telegram to identify the users, and Telegram refused despite having the ability.
Montenegro (.me) seems to be aligned with the EU. But I would have expected there to see a legal ruling in France before Montenegro would do this sort of thing.
I wouldn't be surprised if GoDaddy caved to request. They are known for giving up domains to anyone with a badge and a fax machine!
serverHold status means registry, not registrar, hold - the relevant protocol (not WHOIS) has the registry as the server, as you'd expect. But you are right about GoDaddy and they are a strange choice.
In Russia, "extremism" is being against Putin or the war. For example, posting photo of Alexey Navalny is "displaying extremism symbol". Also, there are people charged with extremism for posting a link to instagram/facebook domains (Meta is an extremist organization).
Also "facilitation of exam cheating" is the most stupid accusation. Why they cannot keep exam question in secret? Also why they do not shutdown scammer call centers which scam Westerners? So they want Telegram to be blocked but scammer call center to continue operating?
> So they want Telegram to be blocked but scammer call center to continue operating?
Obviously yes, follow the money. Call centers use BSNL which is a state-owned telco, the government gets a cut of every call made. Telegram doesn't give the government any incentive to keep it around.
>In Russia, "extremism" is being against Putin or the war.
In Russia, "extremism" is whatever the state decides it to be. "Give me the man, and I will find the crime" has always been its modus operandi. the last people who might have got fair trial were nobles under the Tzar.
Zulip is amazing. Nothing against that but what are your thoughts on fluxer and the others (recently chatto seems interesting, matrix, stoat are interesting options as well).
Also awesome initiative by the way, how did you end up making it and I'd love to know some backstory about it actually as well.
Not the original commenter, but Matrix is awful. I used it on and off, and self-hosted it too. It's slow, bloated (I'm pretty sure I tried other homeservers). The app UI/UX is not great either. The E2EE stuff got better by the end but adoption-wise I was able to get way more people on Signal.
Matrix the protocol is just fine, and all features you expect are there. Their problem is with actual apps that either don't support most of good features, are unpolished to the degree of being unusable, or both.
For matrix, I don't use the original client but rather cinny. This client is so good that I wish that other clients and it looks really good in UI/UX, honestly I have had some serious thoughts of porting this UI sometimes: https://cinny.in, so I would be curious what you think about this as well.
(Side note: Fractal and the matrix element fork called schildichat are interesting as well. It is also possible to run matrix in terminal for what its worth as well, and nhekochat is good as well. Fractal runs on gtk and nheko runs on qt. I do agree though that running matrix homservers is a bit bulky sometimes from what I have heard but the client scene is probably really good so I am curious what you think about cinny :-D )
I used Cinny at some point, but the issue for me was the mobile client. I liked Cinny, but wasn't a huge fan of a web-based client. I think I tried Fractal and whatever KDE was working on and neither was polished at the time of use.
Hm yeah I understand, there were some issues in Fractal where it didn't support spaces sometime back (I am not sure about it right now), it was fun talking to the team at gnome though making fractal.
> I liked Cinny, but wasn't a huge fan of a web-based client.
I feel as if sacrifices must be made as Signal and most others are probably web based clients as well. Fractal probably comes as close to it tbh
> but the issue for me was the mobile client
Ah I see, I don't really run matrix on phone but yeah I understand what you mean, aren't there some clients like fluffychat and others for Android though? Certainly not as polished as Cinny I imagine but it should be workable (hopefully) from my time seeing some of its screenshots. another side nitpick of matrix protocol but I have heard from people that Matrix clients sometimes take battery consumption.
When I was making https://mirror.forum I had my fair share of trying various protocols and to be honest, I feel as if we have enough good open source solutions out there that the tech part just isn't the limiter anymore and FOSS solutions in general might be good enough but its the network effects which are the issues.
which is tangentially why I had built mirror.forum where you can add your discord, matrix, fluxer, stoat links all in one for a guy to join any of them by just changing the link from #discord to #fluxer among other things.
Though I do understand the overall frustration of wanting something which just works but Fluxer is an honestly good option as well and I would love to know if it fits your use case perhaps if not matrix, what do you think? IMO its a low hanging fruit to replace from discord to fluxer given how similar the overall UI/UX is. I also think that Fluxer also has a mobile client or is working on that.
I agree that Matrix has a lot of problems, at least when used with the Element app, but I've found that voice calls are much better with Matrix compared to Signal over a flaky network. It was as good as WhatsApp in my experience.
They're in a position to get their own TLD (e.g .tgrm - edited from .tg); they should probably do this and run their own supporting infrastructure for it at this point.
Well, almost all of them are ultimately controlled by the nations, but there are quite a few that private companies operate because they've paid the nation to gain control.
But then there's .io (and a few others: .ac, and previously .sh, .tm) where they were actually delegated to a British guy and are now controlled by the private company he started. And according to the British government, they have no agreement with the company, and they receive no revenue from the domain registrations.
2 letter TLDs/country-code TLDs, are determined by ISO 3166-1 alpha-2 country codes, and having a country code doesn't necessarily mean a country or a state.
There are a bunch on there that I wouldn't consider states, e.g. both UN/EU are exceptionally reserved and have `.un` and `.eu`. Antarctica also has `.aq`.
The Heard Island and McDonald Islands has `.hm`, and it's not a state (since it has no population) but I guess it is controlled by Australia.
Suspended means the "serverHold" status. I haven't found any official blog post/announcement yet, but the status is unambiguous, and the fact that it happened to one of the Telegram's main short links means that it might be related to legal matters.
Archive warrior's default project is mirroring t.me links. If you're running it you'll need to switch to a different project. It isn't handling the domain not resolving well, it stuck in timeout backoffs.
Didn't t.me also support showing previews of entire channels? Perhaps they got hit with a take-down of sorts due to content (e.g., CSAM) on any particular channel?
i really hope this is it from telegram. its downright causing havoc in countries without the jurisdictional power like korea and japan which have seen insane rise in drug related crime especially in
japan they have a new wave of crime from anonymous telegram operators running human cell crime ops
If telegram disappeared then others would immediately take its place.
Telegram also isnt device to device fully encrypted unless you use a more limited private chat and, as Telegram uses googles messaging service, so likely compromised to NSA anyway.
> If telegram disappeared then others would immediately take its place.
I'm not certain that's the case. Telegram has survived in large part because Durov is incredibly wealthy and can afford to shovel money into running the service more or less indefinitely. There's no obvious heir apparent.
>> they have a new wave of crime from anonymous telegram operators
I love how your solution isn't "country should decide for themselves and pass the law that suits them" but "let people that have nothing to do with that country take something away from them (sidenote: I also don't have nothing to do with that country)".
Drug abuse is a systematic problem, if telegram single-handedly enabling it to alarming rates, the solution should be at least to ban a tech stack.
Otherwise it will get replaced in a seconds.
Swapping the redirect now for telegram.me, which hopefully won't go down simultaneously