India Orders GitHub to Block BitChat

India’s Cyber Crime Coordination Centre last night ordered GitHub to disable access to BitChat, the peer-to-peer messaging app backed by Jack Dorsey. The order, Notice No. 11072601011432, went out at 11:16 pm under Section 79(3)(b) of the Information Technology Act, 2000, read with Rule 3(1)(d) of the IT Rules, 2021.

It named three repositories, including the Android application and its release files, and gave GitHub three hours to take them down. It warned that failure would cost the platform its safe harbor and open it to criminal prosecution.

The government did not publish the order. The public learned of it from a post by Jack Dorsey, whose team develops BitChat, who wrote that “the government of India does not like technologies like BitChat and wants it taken down.”

BitChat is open source and uncensorable, and is one of Reclaim The Net’s recommended messaging apps for situations where the internet may be cut off. It carries messages from phone to phone over Bluetooth, hopping between nearby devices, with “no internet, servers, phone numbers, or accounts.” It keeps working when the mobile network does not.

Around this protest, the government, getting increasingly brazen with its blocking orders, has switched the mobile network off. Since July 17 the Ministry of Home Affairs has suspended mobile internet around Jantar Mantar in New Delhi about five times.

The most recent suspension ran from 4 pm to midnight on July 23, inside a 1.5-kilometer radius that takes in Janpath and part of Connaught Place. People at the site reported signal jammers, and walking two kilometers before a phone found a signal.

Inside that radius, a student separated from her group during a detention sweep could not send a message to say where she was.

The protesters are students. Tens of thousands have camped at Jantar Mantar since June, demanding accountability for the leak of the NEET medical entrance exam and the resignation of Education Minister Dharmendra Pradhan. Their march to Parliament was refused. Metro stations near the site were closed.

When the shutdowns cut the network, protesters turned to BitChat and other Bluetooth mesh apps to reach each other inside the dead zone.

The order did not name a single message sent on BitChat. It just objected to what the app can do. In the agency’s words, BitChat “significantly impedes lawful interception, attribution, and investigation,” and could be used during “public disorder, riots, terrorism, organized crime, or internet shutdowns.”

The order lists internet shutdowns among the dangers. The government has imposed one at Jantar Mantar. BitChat kept working inside it.

The order used Section 79(3)(b) to demand the block. In 2015, in Shreya Singhal v. Union of India, the Supreme Court held that Section 79(3)(b) lets the government require a takedown only through a court order, or a notice confined to the grounds in Article 19(2) of the Constitution.

India has a separate law for blocking an app, Section 69A, which requires a hearing and reasons set down in writing. The order against GitHub used neither. It went out through the Home Ministry’s Sahyog portal, the channel Indian High Courts are now hearing constitutional challenges against.

The order says the repositories hold information prohibited under law. It names none. It points instead to what the app is “capable of” enabling.

It reaches into criminal law as well. Alongside Section 43 of the IT Act, a civil compensation provision, it invokes conspiracy and abetment under the Bharatiya Nyaya Sanhita of 2023, against a platform that hosts code.

Keep reading

AMD silently removes memory encryption from consumer Ryzen CPUs

According to a report by Ars Technica, AMD has quietly stripped a critical security feature from its lower-end CPUs, leaving unaware users potentially vulnerable to physical attacks. Following a months-long investigation tracked on GitHub, Ben Kilpatrick confirmed that the Transparent Secure Memory Encryption (TSME) feature — which protects CPUs against physical exploits that siphon data from connected memory chips — was suddenly no longer available on AMD CPUs outside the company’s Pro lineup.

As the exhaustive inquiry, which involved conversations with AMD engineers, board vendors, and other CPU users, was coming to a head, an AMD engineer abruptly cut discussions short, stating, “My apologies, but I don’t have any more information to share on this topic.” As of this report, AMD has neither officially acknowledged nor explained the disappearance of the security feature.

TSME is a protection feature that encrypts the data stored in memory, making it unusable to physical attackers. AMD initially added this feature to its high-end CPUs, then later extended it to lower-end CPUs. Eventually, the feature became a given, leaving lower-end chip users assured in its availability as part of the chip package. However, without prior notice, AMD appears to have scrapped the security feature in these processors.

According to the Ars report, the company’s only official reaction to the matter — not counting the GitHub discussions — is an email response stating that TSME “is a security feature only applied to PRO CPUs as part of AMD PRO Technologies,” notably the first time the company has publicly stated such a restriction, despite the feature having worked on consumer chips for years. However, it remains unclear whether the disappearance is an intentional policy decision by AMD to reserve TSME for Pro chips or an unintentional regression that was introduced in AGESA 1.2.7.0, a newer firmware release.

Another concerning aspect of the removal is that the feature’s disappearance is completely undetectable on Windows machines and requires significant technical work to identify on Linux. That means the security feature was removed, leaving users unaware that anything had changed.

Kilpatrick, a self-described “privacy-conscious Linux hobbyist” who first reported the change, was installing a new operating system on his machine running a Ryzen 7 9700X from the Zen 5 architecture. To confirm that all his security protections were enabled, he ran Host Security ID (HSI), an auditing feature that evaluates a system’s firmware and hardware security configurations. To his surprise, HSI reported that TSME was no longer supported — even though he had enabled it in his BIOS settings all along. The contradiction sent him searching for answers.

Keep reading

France’s Own Hack Is the Best Argument Against Its War on Encryption

Brussels and a run of European governments, France loud among them, have spent the past few years treating strong encryption as a problem to be solved.

The argument behind proposals like Chat Control is that the state needs a way to scan private messages to keep people safe and that it can be trusted to hold that kind of access without abusing it or losing control of it.

But France just handed that argument an awkward rebuttal. Tchap, the messenger the French government built for its own civil servants, got breached.

France’s National Cybersecurity Agency, ANSSI, detected the compromise on June 7, and DINUM, the digital affairs directorate that runs the platform, blocked the account involved and published an incident notice.

The intrusion broke neither the encryption nor the servers. Someone hijacked a legitimate user account, which is all an attacker needs when any one credential is a key to the same building.

That detail is the part the backdoor crowd keeps refusing to absorb. The encryption on Tchap did its job. DINUM says private conversations stay end-to-end encrypted even when an account is impersonated and that the attacker could reach only the unencrypted public chat rooms any authenticated user is able to find.

Security researchers were quick to note what that reassurance skips over. An attacker wearing a real user’s identity can see whatever that account sees in the moment, private rooms included.

A government backdoor is exactly that, an access path bolted on beside working encryption and France just demonstrated it cannot keep one of those paths shut for a single weekend.

DINUM has notified CNIL, the French data protection regulator, because personal information may have surfaced in whatever the attacker viewed. The directorate described its handling of the intrusion in a press release.

“At this stage, the account originating the malicious requests has been identified. It was immediately blocked to remove the attacker’s persistent access and allow for a thorough analysis of the data they were able to access. The investigation continues, including the study of event logs, to identify the conversations that the attacker was able to access and the nature of the exfiltrated data,” DINUM said.

The directorate also pushed responsibility back toward its own users, reminding them where the safe lines were supposed to be.

“A message has been sent to all Tchap users reminding them that a public chat room can be found and joined by any user and that its content is not encrypted. In accordance with Tchap’s terms of service, no personal, sensitive, or confidential information should be exchanged in public chat rooms: such exchanges should be reserved for private chat rooms.”

Keep reading

UK Encryption Backdoor Could Hit US Data, Jordan Warns

Britain has refused to let a US technology company brief Congress about a secret order to weaken encryption and the chairman of the House Judiciary Committee is treating that refusal as a problem in its own right.

Jim Jordan, the Ohio Republican who leads the committee, wrote to Home Secretary Shabana Mahmood on Friday warning that Britain may be using encryption powers to reach the private data of US citizens.

The underlying dispute is not new. For more than a year, the UK’s use of secret “technical capability notices” under the Investigatory Powers Act 2016 has strained relations with Washington, ever since reports that Britain ordered Apple to open up encrypted iCloud data. What is new is the wall Jordan says he keeps hitting when he tries to learn more.

He met Sir Christian Turner, the British ambassador to the United States, in March, after a US company asked to brief members of Congress about one of these notices, something that would require Mahmood’s sign-off.

The ambassador suggested it could happen. Mahmood then refused.

“This denial is inconsistent with our understanding from Ambassador Turner and raises serious concerns about shared cooperation on these sensitive matters, particularly as Congress exercises its important oversight responsibilities,” Jordan wrote, the Telegraph reported, adding that it cast doubt on the “trust and effective partnership between our two countries.”

He asked Mahmood to “review this matter and grant the US company’s request to speak with Congress about an alleged technical capability notice,” which he said would “honour the representation made by the ambassador during our meeting and uphold the spirit of transparency and cooperation that is the foundation of our shared security relationship.”

The secrecy Jordan ran into is built into how these orders work and it is worth keeping in view.

The UK may be building “backdoors into their encrypted services,” he wrote.

A backdoor is a deliberately built flaw, a master key, or a hidden bypass that lets an intelligence agency read encrypted data without the user ever knowing. It defeats end-to-end encryption, the design that normally keeps a message readable only to the person who sent it and the person who received it.

A company served with a notice cannot tell its customers, the press, or apparently even a foreign legislature, without the express permission of the Home Secretary.

Keep reading

Canada Moves to Destroy Encryption – Demands Backdoor Access to ALL Available Data

Canada is walking into extremely dangerous territory and most people do not understand the implications because governments always package surveillance laws as “public safety.” That is how this begins every single time historically. They sell fear first, then quietly expand state power behind the scenes while claiming only criminals should worry.

Now even Apple, Google, Meta, Signal, privacy experts, cybersecurity professionals, and members of the U.S. Congress are warning that Canada’s Bill C-22 could force technology companies to weaken encryption and build government access mechanisms directly into their systems.

People need to understand what encryption actually is. Encryption is not some toy used only by criminals. Encryption protects bank accounts, corporate systems, private medical data, government communications, journalists, dissidents, businesses, lawyers, and ordinary citizens. Every time you use secure banking, send a private message, or protect sensitive data online, encryption is standing between you and cybercriminals.

The government always frames these laws as targeting terrorists, child exploitation, organized crime, or national security threats. But the mechanism itself never stays limited. Once governments establish the legal right to force “lawful access” into encrypted systems, the infrastructure for surveillance already exists. The temptation to expand those powers becomes overwhelming.

Apple warned directly that Bill C-22 could allow Canada to “force companies to break encryption by inserting backdoors into their products.” Meta warned the bill could require companies to “break, weaken, or circumvent encryption” and potentially install government spyware capabilities directly into systems. Signal reportedly stated it would rather leave Canada entirely than compromise its encryption promises.

Keep reading

AI Safety Institute Debuts with Big-Name Backers and a Censorship Agenda

Common Sense Media’s Youth AI Safety Institute arrived at the Danish Parliament this week and the guest list is stacked with people who think you can’t be trusted to speak freely online.

Hillary ClintonUrsula von der Leyen, former Biden Surgeon General Vivek Murthy, Ofcom chief Melanie Dawes, and the head of an organization that wants to break end-to-end encryption are all gathering at Christiansborg Palace in Copenhagen to announce what they’d like to do next about AI and children.

The “next” part is where it gets concerning. The Youth AI Safety Institute, launched by Common Sense Media on May 5, says it will “complement efforts by regulators and policymakers to translate frameworks such as the EU AI Act, the Digital Services Act, and the UK Online Safety Act into practical protections for child-safe AI.”

Those three censorship laws represent the most aggressive government-directed speech suppression regimes currently operating in the Western world. The Institute isn’t questioning them. In fact, it wants to help implement them and push them further.

The summit, titled “Keeping Our Children and Families Safe in the AI Era,” is co-hosted by Common Sense Media, Save the Children Denmark, and Margrethe Vestager, who spent years as the European Commission’s executive vice president building the regulatory architecture that now lets EU officials order platforms to delete content.

More than 200 policymakers, tech executives, and civil society figures are expected. King Frederik X of Denmark is giving the opening address. The Duchess of Edinburgh will attend. Danish Prime Minister Mette Frederiksen is on the bill.

And so is Pinterest CEO Bill Ready, whose company helped pay for the Institute’s creation.

Keep reading

France Moves to Break Encrypted Messaging

France’s intelligence delegation in parliament has formally backed breaking the encryption that protects WhatsApp, Signal, and Telegram conversations, recommending that magistrates and intelligence agents be granted what lawmakers describe as targeted access to messages that platforms currently cannot read even themselves.

The delegation, an eight-member body composed of four deputies and four senators, published its conclusions on Monday after months of work on a question that keeps returning to the French Parliament. “The inability to access the content of encrypted communications constitutes a major obstacle for the work of the justice system and intelligence services,” the delegation wrote, framing end-to-end encryption as a problem to be solved rather than a protection to be preserved.

The technology end-to-end encryption uses is precisely the thing the delegation wants weakened. Decryption keys live on user devices, not on company servers, which means the platforms holding your messages genuinely cannot read them. That’s the design and the point. Strip that property away and the protection collapses because a system that lets investigators read messages on demand is also a system that can be abused, leaked, subpoenaed, or hacked.

French police and intelligence services have spent years complaining about this tech. They can still intercept old-fashioned phone calls and SMS messages with a judge’s warrant but encrypted platforms route around that capability entirely.

Keep reading

Apple Fixes Bug That Allowed FBI To Read Deleted Signal Messages

Tech giant Apple has fixed a security flaw that had allowed the FBI to access a Signal user’s deleted messages through their phone’s push notification database, despite the app being deleted and messages being set to disappear.

In a security advisory released on Wednesday, Apple said it had fixed a bug that allowed “notifications marked for deletion” to be “unexpectedly retained on the device.”

In an X post on Wednesday, Signal said the update fixed the issue that made a user’s messages retrievable by law enforcement.

“Apple’s advisory confirmed that the bugs that allowed this to happen have been fixed in the latest iOS release,” Signal said.

Signal uses end-to-end encryption to secure messages between its users. The bug is a reminder that messaging encryption may not be enough to keep data protected when using certain devices or operating systems.

Keep reading

Meta is Ending Instagram Direct Message End-to-End Encryption

Meta is quietly dismantling one of its few genuine privacy commitments. Starting May 8, end-to-end encryption for Instagram direct messages disappears, taking with it the one technical guarantee that kept those conversations private from Meta itself.

“If you have chats that are impacted by this change, you will see instructions on how you can download any media or messages you may want to keep,” the company said in a help document, framing the loss of message privacy as a data export problem. Collect your things, the walls are coming down.

The feature being removed was never universal anyway. End-to-end encryption for Instagram DMs had been available only in certain regions, not enabled by default, since Meta began testing it in 2021 as part of what CEO Mark Zuckerberg called his “privacy-focused vision for social networking.”

That vision apparently has an expiration date. Meta also made encrypted DMs available to all adult users in Ukraine and Russia in February 2022, weeks after the Russian invasion began. That access, too, is ending.

The timing is revealing. TikTok told the BBC last week that it has no plans to bring end-to-end encryption to its DMs, arguing that privacy makes users less safe. Meta is now arriving at the same destination from a different direction.

The stakes are straightforward. End-to-end encryption means only the people in a conversation can read it, a technical lock that excludes the platform, third parties, and anyone who might later obtain a warrant.

When that lock disappears, Meta and its employees can read Instagram DMs, law enforcement can subpoena them, and advertisers may eventually benefit from what gets learned.

Instagram users who relied on encrypted DMs have until May 8 to decide what to archive. After that, their private conversations are Meta’s to read.

Keep reading

TikTok Says Privacy Makes Users Less Safe

Over the past five years, the largest social platforms settled on a clear position about private messaging. Lock it down. Facebook turned on end-to-end encryption. Instagram and Messenger did the same. X joined the club. Yes, metadata is still an issue and the protocols used matter; but, generally speaking, the move was toward more privacy of actual messages.

TikTok looked at that trend and made a different choice. Then it scheduled a briefing in London with the BBC to explain the reasoning.

The explanation was safety.

In the UK, TikTok belongs to ByteDance, a Chinese technology company that operates under Beijing’s jurisdiction. China maintains strict limits on end-to-end encryption inside its borders. TikTok, after its own review of the issue, reached the same policy outcome for its messaging system.

Alan Woodward, a cybersecurity professor at Surrey University, raised that point directly. The company’s “Chinese influence might be behind the decision,” he said, adding that end-to-end encryption is “largely banned in China.”

TikTok declined to engage with that suggestion, of course. The remark hung in the air. However, it’s worth adding that the US operation of TikTok has made no indication that it is moving towards private messaging standards either.

End-to-end encryption is simple in theory. Only the people in a conversation can read the messages. The platform running the service cannot access the content. Governments cannot request it. Engineers inside the company cannot view it.

TikTok’s system operates in a different way. Messages on the platform remain readable to the company. Employees can access them under defined circumstances. Law enforcement agencies can request them through legal channels.

TikTok argues that readable messages allow the company to identify harmful activity.

The debate turns on a basic technical fact. “We can read your messages to catch predators,” and “we can read your messages” describe the same system.

Keep reading