Live data from Hacker News

Telegram founder: US intelligence tried to bribe us to weaken encryption

news.fastcompany.com

161–170 of 220 posts

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#161
post #78

they "trust me", dumb fucks

Are we really still doing this? Can't we just collectively agree to think whatever we want about Facebook and not make the same unsubstantive, pointless comments over and over again every time Facebook or one of its subsidiaries is mentioned? Is no discussion safe from this never ending circlejerk?

I don't care if you hate Facebook, or Mark Zuckerberg, for whatever reason, but can we please just stop infecting every thread with comments like this? It's not productive! No one was convinced who didn't already side with you, and everyone else remains just as unconvinced as they were before. At least try.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#162

Earlier quoted context omitted.

> What happens if someone is briefly compromised? Could you give an example please? How do current protocols deal with that?

https://en.wikipedia.org/wiki/Forward_secrecy

I know about forward secrecy but my question is how you could protect future seasons, not past seasons.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#163
post #59
post #36

Earlier quoted context omitted.

Is it bad to be afraid when there is reason to be?

> Is it bad to be afraid when there is reason to be? We also have a reason to connect "American company" with "NSA Spy"... and it's probably not really true for all US companies is it? :) It's kind of ironic that Telegram is being attacked for being Russian by people coming from US of all places.

Falling down a staircase does not always hurt you seriously, I'm still afraid of getting hurt when falling down a staircase. That's why I avoid as best as I can to fall down staircases.

I also avoid as best as I can giving any data to usa companies or buying privacy-sensitive products from them.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#164
post #105

I am not sure about the claim here but the FBI has always been all over cryptography companies and products and this was well before Snowden, Phil Zimmermann (PGP) knows about this. In 2003-2006, we built a service that was a financial system to exchange financial data through various means including AS/2 EDI over HTTP with big companies and the government suppliers such as AAFES (Army and Air Force Exchange). Initia…

Interesting. That strongly implies that RSA has a flaw, which is news to me.

It could be the opposite. Perhaps the FBI wanted to ensure this firm, which was moving government data, had a properly implemented security system.

I'd hazard a guess that 'custom encryption' would be a big red flag if the FBI was doing a security audit of who has access to government data.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#165

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Forward_secrecy

I know about forward secrecy but my question is how you could protect future seasons, not past seasons.

Negotiate new keys with Diffie-Hellman periodically, I think.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#167
post #83

Earlier quoted context omitted.

Why? Do you have any proof WhatsApp is insecure?

Yes https://news.ycombinator.com/item?id=13389935

That article is false. A large number of people in the security community have spoken out against that article, which had the effect of convincing people in dangerous situations to switch to less secure communication methods.

"Security researchers call for Guardian to retract false WhatsApp backdoor story" [1]

The Guardian claims they have offered to let Zeynep Tufekci write a rebuttal; according to Tufekci, they have repeatedly delayed and are not taking the offer they made seriously.

If you have spread this misinformation in other places, you might want to follow up with the people you misled.

[1] https://techcrunch.com/2017/01/20/security-researchers-call-...

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#168
post #77

Earlier quoted context omitted.

when telegram has been proven insecure? in every topic about telegram people keep saying telegram is not secure. i failed to find info about how insecure their secure chats. maybe you can help me?

Their homebrew crypto seems very shaky: https://cs.au.dk/~jakjak/master-thesis.pdf https://eprint.iacr.org/2015/1177.pdf tl;dr: they tried to use SHA-1 as a MAC. This is something of a crypto 101 mistake. Had they even used HMAC they'd be in much better shape. Worse, even after this was pointed out to them and people started writing papers about potential attacks, they have stood by their shaky design, refusing to up…

> But even worse than that, end-to-end encryption is off-by-default, and users must opt into it. Why?

Because it is unusable. It has no synchronization between devices, only 1 device to 1 device. And if you accidentally closed the chat, you have to verify it again. You can't store trusted key fingerprint.

It is not suitable for mobile devices. Secure chats are like OTR, but with bad crypto. Signal and WhatsApp are the same protocol as OMEMO, originally designed for Signal.

> so that the simple fact of using Telegram does not mark users as targets for heightened surveillance in certain countries

And yet Telegram is associated with terrorism more that, e.g., WhatsApp.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#169
post #5

>"It would be naive to think you can run an independent/secure cryptoapp based in the US." This seems to be a shot at WhatsApp and Signal, implying that they have loopholes that allow the FBI to snoop in. I'm not sure how true that is. This might be an attempt to deflect from the fact that Telegram uses a home-baked encryption protocol which might be insecure, while WhatsApp uses the OWS protocol.

Even if the protocol is mathematically sound, there is no way to verify that it's implemented faithfully by closed source software such as WhatsApp.

Telegram protocol is open and has an open source reference client. While not as good as having both the server and the client open source, at least it allows independent verification that the protocol is being implemented faithfully.

Re: Telegram founder: US intelligence tried to bribe us to weaken encryption

#170
post #167

Earlier quoted context omitted.

Yes https://news.ycombinator.com/item?id=13389935

That article is false. A large number of people in the security community have spoken out against that article, which had the effect of convincing people in dangerous situations to switch to less secure communication methods. "Security researchers call for Guardian to retract false WhatsApp backdoor story" [1] The Guardian claims they have offered to let Zeynep Tufekci write a rebuttal; according to Tufekci, they hav…

There is absolutely nothing wrong with the article, claiming that it is FUD will not change the fact that WhatsApp can re-send messages encrypted with different keys at will (which makes it ABSOLUTELY USELESS for people who actually care about their privacy). The argument against the article seems to be around "we can trust whatsapp not to abuse their ability", which blows my mind. You should not have to trust anyone with cryptography.

> WhatsApp does not give governments a “backdoor” into its systems and would fight any government request to create a backdoor

The problem is that I have to take their word for that, while they have the ability to activate the backdoor at will.

I linked to HN for a reason, so that people could see what other people think concerning the article. Here is the HN version of that opinion https://news.ycombinator.com/item?id=13394900

The misleading is that people are told that proprietary and centralised messaging services such as whatsapp can guarantee security - the truth is that they probably can't.

Post reply on HN