Earlier quoted context omitted.
Has there been any weakness found in Telegram's encryption?
Its default settings are nothing to be desired from a messenger app. And for the paltry $200k they are offering for breaking it I'd bet you could find a magnitude more with little effort on the grey markets. But no, absolutely no proof the underlying crypto has been broken. It doesn't need to be when government requests for data stored on their servers does more than enough.
Jeff Bezos's phone 'hacked by Saudi crown prince'
241–250 of 327 posts
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#242Earlier quoted context omitted.
I shudder to think what would have happened if Obama had ultimately refused to give up his personal phone, and every half-talented hacking group on the planet had pwned it six ways from Sunday—what a national security disaster that would have been! Oh wait
The Clinton server wasn't really interesting because she broke the rules...it was because the Chinese/whomever could grab stuff and the owners had plausible deniability.
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#243Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#244Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#245Earlier quoted context omitted.
Its default settings are nothing to be desired from a messenger app. And for the paltry $200k they are offering for breaking it I'd bet you could find a magnitude more with little effort on the grey markets. But no, absolutely no proof the underlying crypto has been broken. It doesn't need to be when government requests for data stored on their servers does more than enough.
Don't even need that, intercepting SMS is enough.
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#246Earlier quoted context omitted.
While David Pecker was involved in the brokering of the hush money deal with Stormy Daniels, which Michael Cohen eventually made (and prosecuted for), the "catch and kill" payment was made to Karen McDougal, which was another Trump affair.
It is insane to me that Trump is a pariah for the religion crowd
I'm not sure I understand your comment
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#247Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#248Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#249Earlier quoted context omitted.
Well, > To protect the data that is not covered by end-to-end encryption, Telegram uses a distributed infrastructure. Cloud chat data is stored in multiple data centers around the globe that are controlled by different legal entities spread across different jurisdictions. The relevant decryption keys are split into parts and are never kept in the same place as the data they protect. As a result, several court orders…
Telegram also supports proper E2E in the form of secret chats, though the UX is definitely not as good (for example, last I checked it did not support group chat or multi device.)
OLD COMMENT:
E2e using a client that is not opensource (on a system that is not trusted) is not helping much.
E2e where the server is not open source should be okay, because the server-end can only snoop on some meta data (how much, when, what IP, chunk sizes, etc.) but not the content.
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#250Earlier quoted context omitted.
Telegram also supports proper E2E in the form of secret chats, though the UX is definitely not as good (for example, last I checked it did not support group chat or multi device.)
EDIT: Was under the impression Telegram served closed source clients. Turns out it does not. I stand corrected. OLD COMMENT: E2e using a client that is not opensource (on a system that is not trusted) is not helping much. E2e where the server is not open source should be okay, because the server-end can only snoop on some meta data (how much, when, what IP, chunk sizes, etc.) but not the content.