Earlier quoted context omitted.
Pavel Durov also said > The encryption of Signal (=WhatsApp, FB) was funded by the US Government. I predict a backdoor will be found there within 5 years from now. He seems to enjoy throwing out loosly supported accusations. He might be right in some of them, but stopped clocks and so forth. He's also been accused himself of deliberately sabotaging the security of his own encrypted messenger app (Telegram). There's n…
Trevor Perrin and Moxie Marlinspike won the Levchin Prize at Real World Crypto for Signal's cryptography; the Levchin Prize referees are a who's who of academic cryptography, including Dan Boneh, Kenny Paterson, and Nigel Smart; other Levchin winners have included Hugo Krawczyk, Mihir Bellare, and Joan Daemon. Any suggestion that Telegram's cryptography is somehow comparable owing to "half of them Ph.D's in math", or…
Jeff Bezos's phone 'hacked by Saudi crown prince'
161–170 of 327 posts
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#162Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109
Pavel Durov also said > The encryption of Signal (=WhatsApp, FB) was funded by the US Government. I predict a backdoor will be found there within 5 years from now. He seems to enjoy throwing out loosly supported accusations. He might be right in some of them, but stopped clocks and so forth. He's also been accused himself of deliberately sabotaging the security of his own encrypted messenger app (Telegram). There's n…
From my understanding, TOR was created with the intent of hiding US intelligence communications[0]. From my naive understanding, this only works if 1) no one else can back door it (which is critical since it is presumed you're using it to hide from highly technical state actors) 2) there are a sufficient number of users that are not intelligence actors (so you can hide among them. Otherwise you get "Oh, that person connected to a TOR node, let's go pick them up and grab their computer").
Maybe I'm naive, but it seems like the crypto people and the US government have aligned interests here.
> The stated goal of the fund is to promote democracy in developing countries
With an additional alignment of interests, I think many believe that being able to "talk shit" on your leaders is a key part to democracy. And if you're able to do this without fear of your government coming after you (aka: backdoors), then you will freely acknowledge your dissent, find support, and democracy is the likely outcome. I'm not sure if that's true, but I've definitely heard intelligence people suggest that.
So even if it was controlled by the CIA, would this be an issue? It seems like it is actively in their best interest to use real encryption and no backdoors. You don't want all your potential rebels to get caught. You want them to be able to organize out of the eyes of the government that the CIA is trying to overthrow. Having a backdoor just puts a timebomb on it, and one that isn't going to last very long.
Or I guess there's another answer to this. The CIA is pretty fucking dumb. Which is a reasonable answer that I'll accept too, but I think the people working on this stuff would be well aware (since they're probably experts in hacking similarly encrypted systems)
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#163I wonder how often less high profile folks get hit with stuff like this? On one hand, zero days are rare and expensive. OTOH someone who isn't the CEO of a major company might not notice the malware, or if they do, not know they should forward it to an organization like Citizen Lab.
> zero days are rare really?
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#164Earlier quoted context omitted.
Honest question. Given that RCE's are extremely rare, can't FB and AAPL announce 100M USD bounty to get them first and patch them, avoiding bad PR and brand impact? Damn, make it 200M?! Or bad actors can easily pay 5x more to exploit said 0 day on a few targets, so hackers will sell to them instead?
The actual prices are in the $100k-$200k range. $1m if you are extremely generous.
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#165Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109
> To protect the data that is not covered by end-to-end encryption, Telegram uses a distributed infrastructure. Cloud chat data is stored in multiple data centers around the globe that are controlled by different legal entities spread across different jurisdictions. The relevant decryption keys are split into parts and are never kept in the same place as the data they protect. As a result, several court orders from different jurisdictions are required to force us to give up any data.
https://telegram.org/faq#q-do-you-process-data-requests
If we register Telegram, Telegram has our master key. I am not sure they are really that secure. Yes, it makes politically hard to disclose any data, but it does not mean impossible.
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#166Earlier quoted context omitted.
That was what Bezos's camp has been saying from almost the very beginning. The news here isn't the suspected involvement of the Saudis, the news is that MBS is directly implicated.
MBS definitely seems pretty brazen. I could totally buy him doing this - effectively social engineering Bezos - over negative stories about Saudi Arabia in the Washington Post. Who better to persuade Bezos to look at a video? I'm a little surprised Bezos fell for it. Video-triggered vulnerabilities are pretty rare and not something you'd normally be vigilant about, as are world leaders acting as APTs, but he still sh…
Hacking a phone is small potatoes.
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#167Earlier quoted context omitted.
MBS definitely seems pretty brazen. I could totally buy him doing this - effectively social engineering Bezos - over negative stories about Saudi Arabia in the Washington Post. Who better to persuade Bezos to look at a video? I'm a little surprised Bezos fell for it. Video-triggered vulnerabilities are pretty rare and not something you'd normally be vigilant about, as are world leaders acting as APTs, but he still sh…
Pretty brazen? Don't forget that the WP reported that US intelligence intercepted comms from Saudi officials discussing a plan ordered by MBS to lure Jamal Khashoggi from his home in Virginia and then subsequently had him cut into pieces in an embassy. Hacking a phone is small potatoes.
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#168Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109
Well, > To protect the data that is not covered by end-to-end encryption, Telegram uses a distributed infrastructure. Cloud chat data is stored in multiple data centers around the globe that are controlled by different legal entities spread across different jurisdictions. The relevant decryption keys are split into parts and are never kept in the same place as the data they protect. As a result, several court orders…
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#169Earlier quoted context omitted.
Pavel Durov also said > The encryption of Signal (=WhatsApp, FB) was funded by the US Government. I predict a backdoor will be found there within 5 years from now. He seems to enjoy throwing out loosly supported accusations. He might be right in some of them, but stopped clocks and so forth. He's also been accused himself of deliberately sabotaging the security of his own encrypted messenger app (Telegram). There's n…
> like TOR From my understanding, TOR was created with the intent of hiding US intelligence communications[0]. From my naive understanding, this only works if 1) no one else can back door it (which is critical since it is presumed you're using it to hide from highly technical state actors) 2) there are a sufficient number of users that are not intelligence actors (so you can hide among them. Otherwise you get "Oh, th…
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#170Earlier quoted context omitted.
Trevor Perrin and Moxie Marlinspike won the Levchin Prize at Real World Crypto for Signal's cryptography; the Levchin Prize referees are a who's who of academic cryptography, including Dan Boneh, Kenny Paterson, and Nigel Smart; other Levchin winners have included Hugo Krawczyk, Mihir Bellare, and Joan Daemon. Any suggestion that Telegram's cryptography is somehow comparable owing to "half of them Ph.D's in math", or…
Has there been any weakness found in Telegram's encryption?
And for the paltry $200k they are offering for breaking it I'd bet you could find a magnitude more with little effort on the grey markets.
But no, absolutely no proof the underlying crypto has been broken. It doesn't need to be when government requests for data stored on their servers does more than enough.