Telegram Will Not Allow Scanning of Private Chats — Pavel Durov Strongly Criticizes EU Over Chat Control Initiative
Pavel Durov, founder of the messaging platform Telegram, has delivered a sharp rebuke to the European Union over renewed efforts to advance the Chat Control initiative. The proposal, which has resurfaced in EU legislative discussions, could authorize or require online services to scan private messages, emails, and photographs in order to detect prohibited content.
Durov reacted forcefully to the development, stating that methods previously associated with banana republics are now being employed within the EU to push through surveillance legislation. He made it unequivocally clear that Telegram will not scan users’ personal messages, irrespective of any regulatory maneuvers attempted by European authorities.
The founder reiterated the platform’s longstanding position: private correspondence must not be converted into material for mass automated monitoring. This stance directly challenges the direction of the proposed Chat Control regulation currently under debate.
Background on the Legislative Initiative
The European Parliament has returned the bill linked to the Chat Control initiative for further consideration. Earlier drafts explored the possibility of allowing online platforms to voluntarily scan user-generated content, including text messages and media files, with the stated goal of identifying illegal material.
Opponents of the measure contend that the legislation would establish a de facto system of mass surveillance of private communications, despite being presented under the banner of public safety. Proponents, however, maintain that such scanning capabilities are essential for combating illegal content and safeguarding users online.
In this ongoing debate, Telegram has aligned itself firmly with privacy advocates. Durov’s statements signal that the service intends to resist any attempts to transform encrypted personal chats into accessible data streams for regulatory oversight, even as the EU continues to tighten requirements for technology platforms.
Related articles
Gesture Dynamics CAPTCHA Emerges as Privacy-Focused Drop-in Alternative to reCAPTCHA
A new open-source CAPTCHA system called Aptogon replaces traditional image-based challenges with analysis of hand gesture dynamics to verify human users. Instead of clicking on traffic lights or buses, visitors draw a free-form gesture for about ten seconds while the system measures velocity variance, pause entropy, rhythm irregularity, and micro-corrections that distinguish human motor patterns from bots. The solution addresses recent reCAPTCHA restrictions, including Google's reduction of free monthly verifications from one million to ten thousand and tightened GDPR data responsibility rules starting in April 2026. An iframe architecture loaded from the vendor origin eliminates cross-origin issues and CORS blocks while supporting public and secret key pairs for domain validation. Machine learning relies on a local gradient boosting model for confident decisions and an LLM only for borderline cases, with fail-closed behavior returning 503 errors when the classifier is unavailable. Coordinates never leave the browser; only derived statistics are sent, satisfying GDPR requirements without cookie banners or biometric templates. The project is released under AGPL-3.0 with a free tier of one thousand checks per month and integration examples for HTML, React, Node, Python, and PHP.
Cat Tunnels Service Deploys Kotator-Rotator to Counter Mass Blocking of Relay Nodes in Russia
The operators of the decentralized Cat Tunnels service faced a sudden wave of blocks that disabled all several dozen of their tracker nodes inside Russia. Without these anchor relays, new user connections slowed dramatically and existing sessions degraded. The team responded by building Kotator-Rotator, an automated system that continuously evaluates node reachability from the client side and replaces failing relays with fresh instances. The decision engine relies on Grohotator, an aggregated availability metric derived from client technical logs that also triggers an audible alarm when thresholds are crossed. Analysis of the logs revealed that blocking activity follows a clear weekday pattern, pausing on Friday evenings and resuming Monday mornings. The experience demonstrated that server-side health checks alone are insufficient when censors interfere with paths between clients and relays.
Google Chrome Tests Visible Global Privacy Control Toggle in Canary
Google is testing a new visible toggle for Global Privacy Control in Chrome Canary that lets users send a standardized request asking websites not to sell or share their personal data and not to use it for targeted advertising. When enabled, the browser adds the Sec-GPC: 1 header to web requests and exposes the setting via navigator.globalPrivacyControl. In regions with supporting laws such as California's CCPA, the signal can serve as a formal opt-out from data sales. The feature currently appears primarily on Android, with experimental flags available on Windows, macOS, Linux, and ChromeOS, though the desktop interface remains incomplete. Two separate flags are required—one to show the toggle and another to actually transmit the signal—because enabling only the UI does not send Sec-GPC: 1. The mechanism is not a guaranteed enforcement tool; websites decide how to respond, and effectiveness depends on legal frameworks and site compliance. The feature is absent from the stable Chrome release and may still change before wider rollout.
OpenAI ChatGPT Computer History Feature on macOS Could Expose Detailed User Activity Logs to Infostealers
OpenAI has introduced the Computer History feature in its macOS ChatGPT app, which records application switches, clicks, keystrokes, and accessibility context to generate AI summaries and memories. The feature is disabled by default and requires explicit activation of Memories, with availability limited to Pro, Business, and Enterprise users outside the EEA, Switzerland, and the UK. While raw event files are deleted after 48 hours and not used for model training, the resulting Markdown memory files remain unencrypted on the local Mac. These files can be read by any process running under the same user account, creating a ready-made activity log for infostealers and other malware. OpenAI also warns about prompt injection risks where hidden instructions from websites or apps could influence ChatGPT or Codex behavior. Users retain controls to select participating apps, pause collection, or delete history, but the lack of encryption on stored memories raises significant privacy concerns.