Earlier quoted context omitted.
Funded by the government != The government has their hands all over it
Even TOR was originally a government funded project
Telegram founder: US intelligence tried to bribe us to weaken encryption
81–90 of 220 posts
Re: Telegram founder: US intelligence tried to bribe us to weaken encryption
#82Option 2: Could be true because seriously, who trusts the FBI/NSA not to violate our privacy anymore?
Really not sure what to believe about this one.
Re: Telegram founder: US intelligence tried to bribe us to weaken encryption
#83>"It would be naive to think you can run an independent/secure cryptoapp based in the US." This seems to be a shot at WhatsApp and Signal, implying that they have loopholes that allow the FBI to snoop in. I'm not sure how true that is. This might be an attempt to deflect from the fact that Telegram uses a home-baked encryption protocol which might be insecure, while WhatsApp uses the OWS protocol.
If I'm not mistaken Telegram has already been proven insecure once in the past. WhatsApp is a zuck property now, you can consider it insecure.
Re: Telegram founder: US intelligence tried to bribe us to weaken encryption
#84Earlier quoted context omitted.
If I'm not mistaken Telegram has already been proven insecure once in the past. WhatsApp is a zuck property now, you can consider it insecure.
Why? Do you have any proof WhatsApp is insecure?
Re: Telegram founder: US intelligence tried to bribe us to weaken encryption
#85I mean, simply use a public/private encryption algorithm that has proven to be highly secure:
- Share your public key openly
- Anyone can send a message to you using your public key to encrypt the message
- You decrypt with your private key on device
Do all the encryption/decryption on device and viola, secure messaging. (This is basically how https works.)
Of course this only allows a single device the ability to decrypt the message.
However, if you want to allow multiple devices to share a private key, they can simple send each other their own private keys using the same encrypted protocol.
In addition, for super paranoid use, a master password could be used to salt the private key so that would be required with the private key to enable decryption. (Which is similar to how password keepers basically work.)
What am I missing?
Re: Telegram founder: US intelligence tried to bribe us to weaken encryption
#86Earlier quoted context omitted.
Is it bad to be afraid when there is reason to be?
Of course not, but there should be more to it than merely seeing the word 'Russian'. I see this all the time now in left-leaning US papers (NYTimes, WaPo) that immediately imply association with something bad happening (he spoke with a Russian!). Much like the other popular generalization of 'Muslim' without qualification of type of Muslim where significant subsets have never been involved with terrorism (sufism vs w…
With this comment, the idea is that crypto software built in Russia could easily be compromised by the rather un-free Russian government, which seems pretty reasonable. Of course, the fact that this fellow no longer lives in Russia scuttles it, but that's just not being fully informed, not "xenophobia."
Re: Telegram founder: US intelligence tried to bribe us to weaken encryption
#87The problem I have as an end user is that I want the infrastructure protecting me to be invisible. Let's return to this after the following paragraphs. I will make some pretty far-reaching conclusions. I think we can all agree that if some totally below-the-radar crypto anarchist who happens to have a few million dollars from bitcoins figured out that they actually have enough access via the dark web to bribe a few R…
> I think we can all agree that if some totally below-the-radar crypto anarchist who happens to have a few million dollars from bitcoins figured out that they actually have enough access via the dark web to bribe a few Russian generals and long story short detonate a nuclear bomb a few miles outside New York City, just for shits and giggles, then they should be stopped at some point along the way. I agree with this,…
Technology is accelerating to the point where the destructive power that was formerly available only to state actors with proper command & control systems is now available to small states, groups, and even individuals -- chemical, bioweapons, delivery by drone, etc. It is now possible to mail-order custom gene sequences for garage bioengineering (yes, they do try to filter the requests against homebrew bioweapons, but the operative word is 'try'). Even computing power -- I'd be surprised if a random dozen people on this forum, properly motivated and funded, could not take down the US power grid within a year.
This scale of mass destruction in the hands of individuals is a far greater scale and scope of problem than the ability of any nutjob to go to WalMart and buy a hunting rifle to point at you, me, or a Congressman.
It is the kind of real problem that keeps serious security pros up at night. And there are many of these scenarios becoming more real all the time, even if logicallee's nuke example seems too fictitious for you.
The real question he's posing is whether its feasible to build an automated system that's sufficiently private and intelligent so that it could scan the comms without violating privacy while only alerting on genuine threats.
I think it's an interesting idea, but even if implementable, would fall to the problem. What is to prevent the people who build, maintain, operate the watch-system from abusing it? Nothing but the same level of ethical training that we have now, so this is simply adding one level of indirection.
Re: Telegram founder: US intelligence tried to bribe us to weaken encryption
#88Earlier quoted context omitted.
Even TOR was originally a government funded project
It still gets a large portion of its funding from the USG
Re: Telegram founder: US intelligence tried to bribe us to weaken encryption
#89Re: Telegram founder: US intelligence tried to bribe us to weaken encryption
#90>"It would be naive to think you can run an independent/secure cryptoapp based in the US." This seems to be a shot at WhatsApp and Signal, implying that they have loopholes that allow the FBI to snoop in. I'm not sure how true that is. This might be an attempt to deflect from the fact that Telegram uses a home-baked encryption protocol which might be insecure, while WhatsApp uses the OWS protocol.
Pavel Durov wants everyone to think security is about trust in people. Most companies in that business do the same, because it's easier than building something that doesn't require trust in people. The way Pavel Durov and others like him present "trust" is (ironically) shady corporate structures[1], shell companies, or use of the word "Switzerland." They want people to think like that because they've built businesses…
If Telegram isn't that secure, then why are extremists like IS using it over Signal or WhatsApp? I know Telegram has better features for big groups and much better multi-platform support, so is that the reason? I'm legitimately asking without any snark.