Information that telegram gives to law enforcement

I was reviewing a recent legal case in which Telegram provided info on a US individual.

It appears they only provide:

User ID
Username
Currently attached number
Last login IP

They don’t appear to provide IP history/creation IP. The FBI also acknowledges they cannot obtain search warrants for messages due to how Telegram infrastructure spreads across multiple jurisdictions. Despite not being e2e by default I find this impressive.

Unrelated, this affidavit really brings to light how important it is to use email aliases that conceal subject lines (SimpleLogin), temp phone verifications, and an encrypted email provider.

6 Likes

I wonder what was requested by LE.

1 Like

Considering this is the FBI I’m going to assume they asked for way more than what they were given. I can’t see any scenario where they only request the “last login IP”.

Their subpoenas are always drafted with lots of specific details. Unless they’ve learned that telegram isn’t gonna budge anything else.

3 Likes

Hmmm, did a quick search and found this article.

It seems Telegram’s privacy policy does reflect what they would handover (woah, their TOS and privacy policy becomes so long now, when I last check (shortly after Durov’s arrest in 2024), it was very…….. brief,

This is a relief, tbh.

If this is the case I am impressed as well.

This public court document serves as further proof that Telegram only provides the limited info I mentioned to US law enforcement.

4 Likes

Telegram refused to provide a certification of authenticity despite being asked twice.

The subject deleted the Telegram app before seizure and although he provided his passcode to law enforcement, no meaningful chat history, cached messages, or relevant artifacts were recovered from caches, or hidden storage on the device.

1 Like

Another interesting thing I found was this

“Please be advised that due to Telegram’s technical structure a phone number is generally required to obtain from the system the private data of users who have not been subject to moderation. However, following your request, we were also able to activate additional logging for the accounts in question. Thanks to this, we were able to obtain the following data”

  • “Activate additional logging” This implies Telegram does not keep full or long term logs by default for most users. When they receive a valid request, they can turn on extra logging specifically for the target accounts. In other words, they generate new records that might not have existed otherwise.

  • “Bypassing the normal phone number requirement” Normally, Telegram says they need a linked phone number to pull private data. Here, they made an exception and used the additional logging to get data anyway.

2 Likes

That’s why I see so many activists using Telegram.

The good thing about it is that content like videos stays there for a long time and can be used as evidence when the situation calls for it.

Even though the image says it’s from 2024, situations can change at any time if they arise.

The image in my original post is from a 2026 case.

Can you share that information? In the image (screenshot), you can see that the content is from the year 2024.

This is more about the incompetence of LEA and Justice system than Telegrams cryptographic design. When e.g. the Miami data center receives a message from Alice, the message is stored into the server’s database. Encrypting a plaintext is a repeated operation of adding per-round key, shifting rows, mixing columns, and substituting values as per a lookup table.

For the adding of round key to work, that key must be present in the registers of the CPU in Miami data center.

The key can not be in the RAM of a data center in another country.

I’m not sure what the law says about whether the key has to be stored on a disk for it to be something they could hand over, but I’d imagine informed judge could hold Telegram in contempt of court if they claimed the reason they won’t comply with the request if because they can’t be arsed with adding print statement for taking out the key. Bernstein vs US considered code speech so it might violate the first.

Plus Telegram absolutely could hand out messages because they have access to the keys. So it remains a mystery how strictly the first applies here.

But do not think for a second Telegram is private or safe for dissidents to use. The servers are fair game to every major nation state’s hacking team to exfiltrate any information from, and given Telegram lacks the know-how of deploying ubiquitous E2EE, how likely is it that they know how to harden their servers against every zero-day out there.

3 Likes

American judges don’t have the time or technical expertise to dive into Telegram’s backend architecture. They rely on what the company claims and whatever expert witnesses are presented. The problem is that the only real experts on how their servers, keys, and MTProto actually work are Telegram’s own staff, who aren’t easily summoned to court like Meta or Google employees would be.

Yes anything can happen, but endpoint/account compromises are much more likely than server/MITM attacks.

Also if 2 people want to avoid their data going through Miami DC they can use OctoGram - DC Status to see which country code prefix will land them at another DC (permanently) during account creation process.

1 Like

Question in regards of Octogram. Does Telegram sometime ban user using Octogram or other 3rd party unofficial client ?

Activist using telegram is not a great idea. You would have to use a VPN or public wifi IP every time. Because, as written they log IP adress. You also would have to obviously use anonymous phone number for registration.

1 Like

I was only mentioning the specific datacenter status page. I know nothing about octogram itself.

I would certainly hope a activist has a VPN on at all times and doesn’t use their real number on social media. The main reason I use Telegram is because it’s the closest thing we have to a private discord. And it allows silent message deletion for both parties in private chats, with no time limit which is very important to me.

Exactly.

And if possible, use it on the web, not through the app.

2 Likes

Citation needed. There’s 800,000,000 more reasons to go after the server. You get access to everyone’s communication with single zero day chain and with good luck persistence.

The reason we don’t hear of Telegrams’s server side exploitation, is that the agencies doing that aren’t telling, and Telegram has every business reason to not tell. It would ruin their reputation overnight. There wouldn’t be a “hold on guys we’ll deploy E2EE for everything to make sure this never happens give us a few years” response. Everyone would flock to Signal that’s already doing it.

And the server side MITM is not necessary because ~nobody is using secret chats because their UX is garbage. Most people run Telegram also on their desktop computers and when you can’t continue the chat there, you revert to non-E2EE chats. Because the friction of pulling out your phone hundreds of times per day, unlocking it and navigating to the chat to reply is way too much work.

Also nothing is E2EE by default so 99.9% of user’s aren’t using E2EE I’m the first place, and enabling it leaks metadata about intent to hide from Telegram.

And you can’t have E2EE at all for groups which is where most of buddies gather.

Way too much work to obtain foreign prepaid SIMs. Unlesss you’re running disinformation or drug ring, that’s just not happening. And the main threat is Telegram service itself which is indistinguishable from an FSB honeypot in how it’s advertised and how much data it’s collecting. They still see your messages and probably can put two and two together.

3 Likes

I had no idea Telegram had a user ID number that was not your username or phone number. That means that even if you change your phone number and username, you can always be identified as the same account holder.

Something I do wonder is if lurkers can be prosecuted for crimes?

If the only evidence against them is that they are a member of an illegal group, but there is no evidence of them participating in said group.

I will never understand why people keep trusting Telegram.

1 Like

Social engineering remains the biggest threat. All you have to do is review the top cybersecurity incidents for social media platforms. We’re talking about multi-billion dollar companies not some junior sysadmin that just opened his linux server to the internet.

That’s a good thing. Will encourage them not to keep secure convos all over the place. All that E2EE marketing gets unexperienced users too relaxed and it catches them at the worst moment.

Most people use a cheap sms verification service like @SMSPool and pair it with 2FA when they don’t want to use their real number.

1 Like