Live data from Hacker News

Telegram founder: US intelligence tried to bribe us to weaken encryption

news.fastcompany.com

111–120 of 220 posts

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#111
post #61

Earlier quoted context omitted.

Good for business but what business? As far i know he is running telegram using his own money, and he has no businesses plan and he doesn't want one. Only the telegram server is closed source (for now), telegram client and protocol are open source.

How about a business of selling troves of data to Russian government, for example? The only thing that makes such "business" seem unlikely is trust in Durov. It can be unfounded given his claims like [1] > No, because I never took money from the government. I left Russia and lost a $3bn business there because I defended users' privacy from it. while he is often spotted in Saint-Petersburg, Russia. Moreover, Telegram'…

Could you provide a little context to your comment?

I'm not well read on this (eg, what company he lost, how he claims he lost it, etc) -- you seem to be responding in the context of a story, but not a story I know about.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#112
post #97

Can someone correct me if I am wrong, but it seems relatively easy to make an encrypted peer-to-peer messaging system. I mean, simply use a public/private encryption algorithm that has proven to be highly secure: - Share your public key openly - Anyone can send a message to you using your public key to encrypt the message - You decrypt with your private key on device Do all the encryption/decryption on device and vio…

One thing missing is that most users cannot be trusted not to lose their key and still want a way to recover it. LastPass, for example, provides ways to do that, for example by using devices they have used recently but, I don't think it is particularly secure. Spreading the key to multiple devices so that you have a copy of it on another device helps obviously, as does allowing an unencrypted backup of the key, for e…

Yes, if you lose your private key, it is gone forever. Otherwise there is no security. (Backup options would depend on the use case.)

Yes, payment is a separate issue. It would be assumed that there is value in having this system available to the users that would be outside their messaging needs.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#113
post #92

Can someone correct me if I am wrong, but it seems relatively easy to make an encrypted peer-to-peer messaging system. I mean, simply use a public/private encryption algorithm that has proven to be highly secure: - Share your public key openly - Anyone can send a message to you using your public key to encrypt the message - You decrypt with your private key on device Do all the encryption/decryption on device and vio…

For example you're missing forward secrecy: Do old messages stay secure or not if a key is leaked?

The public/private keys could be changed periodically. Old private keys could be deleted. Once lost, access to the messages they decrypt would be permanently lost (no searching of message history).

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#114

Hmmmm.... A Russian peddling undocumented crypto warez implies US crypto is untrustworthy despite the obvious open source code. Don't suppose this would be one of Putin's patriotic citizen artists spreading fake news do you? Edit: thanks to all the replies. I am smarter now.

You can't be more wrong and uninformed. Russia-bashing seems to be a common and accepted theme now. He actually left Russia and his old company because the Russian government tried to censor it (VK) and he refused to do so. So basically he and Putin are in some kind of fight / disagreement. https://en.wikipedia.org/wiki/Pavel_Durov#Dismissal_from_VK

He didn't leave Russia as in "exile", he did leave Russia as in "it's nice to leave somewhere else". Here [1] is a news report about him throwing out someone's phone for trying to make a photo of him in one of Saint-Petersburg's malls. Here [2] is an article from 2014 stating that he's visiting Telegram's office daily. By the way, Telegram's developers sit in the same building as VK's (also in [2]).

Durov seems very keen on supporting the myth of his "dissent" (to the point of outright lying) and very shy about the actual location of Telegram's developers and servers. Guess why

[1] https://lenta.ru/news/2017/03/20/durov/ (in Russian)

[2] https://tjournal.ru/p/durov-back-in-ussr (in Russian)

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#115

I am not sure about the claim here but the FBI has always been all over cryptography companies and products and this was well before Snowden, Phil Zimmermann (PGP) knows about this. In 2003-2006, we built a service that was a financial system to exchange financial data through various means including AS/2 EDI over HTTP with big companies and the government suppliers such as AAFES (Army and Air Force Exchange). Initia…

Did the FBI give any reason/leverage as to why you should comply with their ask?

If you are writing about it here, I'm assuming it wasn't an NSL (national security letter) and so would you be open to publishing a copy of it publicly? Would be great to get sunlight on that.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#116
post #105

I am not sure about the claim here but the FBI has always been all over cryptography companies and products and this was well before Snowden, Phil Zimmermann (PGP) knows about this. In 2003-2006, we built a service that was a financial system to exchange financial data through various means including AS/2 EDI over HTTP with big companies and the government suppliers such as AAFES (Army and Air Force Exchange). Initia…

Interesting. That strongly implies that RSA has a flaw, which is news to me.

Or that the FBI was confident enough in their ability to steal private keys, or that they believed the keys were low-enough strength that they could crack the keys and decrypt the intercepted data at some point in the future.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#117

The government has progressed from banning encryption to trying to subvert it :/

That's actually a central tenant of the NSA's mission. But that mission predates the internet and public key crypto. Now it's like the gas company is running around drilling holes in gas pipes.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#118

Earlier quoted context omitted.

How about a business of selling troves of data to Russian government, for example? The only thing that makes such "business" seem unlikely is trust in Durov. It can be unfounded given his claims like [1] > No, because I never took money from the government. I left Russia and lost a $3bn business there because I defended users' privacy from it. while he is often spotted in Saint-Petersburg, Russia. Moreover, Telegram'…

Could you provide a little context to your comment? I'm not well read on this (eg, what company he lost, how he claims he lost it, etc) -- you seem to be responding in the context of a story, but not a story I know about.

You can find a dry summary here [1]. Basically there is a nice story that Durov constructed over the years, the story of a tough libertarian who stood against the Russian government and was forced out of his business (Vkontakte), having to sell it for a fraction of its true price. He stands by his fellow users, willing to risk his business over their privacy, and now he runs Telegram out of his own pocket because… reasons. He is also in (implied) exile from Russia, he bought a citizenship of some island nation and is now a digital nomad.

I believe that's the gist of his "official" image. However, there are cracks in that story to which I alluded in the comment.

https://en.wikipedia.org/wiki/VK_(social_networking)#2013.E2...

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#119

Earlier quoted context omitted.

Pavel Durov wants everyone to think security is about trust in people. Most companies in that business do the same, because it's easier than building something that doesn't require trust in people. The way Pavel Durov and others like him present "trust" is (ironically) shady corporate structures[1], shell companies, or use of the word "Switzerland." They want people to think like that because they've built businesses…

I read the WP article you cited, titled, "The secret American origins of Telegram, the encrypted messaging app favored by the Islamic State". If Telegram isn't that secure, then why are extremists like IS using it over Signal or WhatsApp? I know Telegram has better features for big groups and much better multi-platform support, so is that the reason? I'm legitimately asking without any snark.

You highly overestimate the people who are in position of power.

I am talking about politicians, head of terrorist groups, etc.

While saying that top politicians are complete idiots is probably wrong - then again maybe not, I am not sure anymore - the fact that H. Clinton, run the most expensive campaign in history, with backing from all major tech corps AND her staff didn't bother to use encryption at any scale, let alone running a mail server (God knows what kind of software the server was running if it was OpenBSD or Windows Server 08), to me says a lot about how flawed the understanding of these people and their consultant's is about today's world.

Watching "House of Cards" everybody seems incredibly smart, driven, etc. but the politicians I see in real life on average and on the not-very-smart side and the few I've met in person are clueless beyond salvation.

Ps. Sorry for possible mistakes, I'm reading from mobile.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#120
post #16
post #7

Sounds like a reasonable exit if noone wants to buy your popular e2e encrypted chat app. Take the bribe, shutdown and move on to the next iteration.

1) Open source codebase pre-backdoor 2) Take bribe 3) Insert backdoor 4) Close company

truecrypt?
Post reply on HN