Live data from Hacker News

Telegram messaging app proves crucial to Belarus protests

latimes.com

411–420 of 557 posts

Re: Telegram messaging app proves crucial to Belarus protests

#411
post #219

Earlier quoted context omitted.

By default it's no more encrypted than HN (as in, traffic to their servers uses TLS, messages on the server are not encrypted at all). There's Secret Chats feature which they claim to be end-to-end encrypted, meaning that it's no more secure than Facebook's Messenger (also end-to-end encrypted in Secret Conversations). Even less so considering that they roll their own encryption (MTProto), while Facebook's Messenger…

This is all information in bad faith. The protocol and all Telegram is open source. Are you a cryptographer? And who "rolled" the Signal protocol, Moxie Marlinspike? Did he not design that himself?

The protocol and all Telegram is open source.

The open source Telegram client tells us

1. That E2EE is not enabled by default

2. That E2EE is not available at all for group chats

3. That E2EE is not available at all for desktop clients.

So just. No.

"Are you a cryptographer?"

Here's the world's most famous cryptographer, Bruce Schneier saying don't use Telegram: https://www.schneier.com/blog/archives/2016/06/comparing_mes...

Here's the world's second most famous cryptographer, Matthew Green saying don't use Telegram https://twitter.com/matthew_d_green/status/72642891296898252...

Now show me the cryptographer who recommends Telegram. You can't. Because there isn't _any_.

"And who "rolled" the Signal protocol, Moxie Marlinspike? Did he not design that himself?"

No, it was co-authored with Trevor Perrin[1] who is a cryptographer.

[1] https://twitter.com/trevp__

Telegram's encryption OTOH was designed by Nikolai Durov who is not a cryptographer, but a geometrician. That's like asking a gynecologist to perform brain surgery, lol.

Re: Telegram messaging app proves crucial to Belarus protests

#412

Earlier quoted context omitted.

And how is Signal's protocol is not "roll their own" ? Sorry I don't know.

Signal Protocol won the Levchin Prize at Real World Crypto, which was awarded by a panel of several of the most renowned academic cryptographers in the field (including Dan Boneh and Kenny Paterson). Other winners include Bellare, Krawczyk, and Joan Daemon. The protocol has been extensively analyzed and is the current gold standard for messaging encryption. Telegram's protocol... is not that.

This. It's not the Durov brothers who are moving the field of secure messaging onwards, or talking at conferences. They're complete amateurs surrounded by fanboys who don't understand the very basics of the field, and who think copy-pasting from https://tsf.telegram.org/manuals/e2ee-simple makes them useful as opposed to spreading propaganda.

Re: Telegram messaging app proves crucial to Belarus protests

#413
post #405
post #331

Earlier quoted context omitted.

Imagine how hard it must be to run a presidential campaign in the US when your incumbent opponent in an election controls the systems that get to read any message in GMail.

Explain how this works. A blue party voter writes to another blue party voter: Hey, let's vote blue this year. NSA that intercepts the message and __________.

The thing being suggested here is that the campaign of the incumbent is reading all the communications of the campaign of the challenger. I don't think anything of the sort actually happens or is really that easy to (completely secretly!) make happen, but that's the proposed scenario.

Re: Telegram messaging app proves crucial to Belarus protests

#414

Earlier quoted context omitted.

Signal Protocol won the Levchin Prize at Real World Crypto, which was awarded by a panel of several of the most renowned academic cryptographers in the field (including Dan Boneh and Kenny Paterson). Other winners include Bellare, Krawczyk, and Joan Daemon. The protocol has been extensively analyzed and is the current gold standard for messaging encryption. Telegram's protocol... is not that.

But the standard we should apply to secure chat protocols isn't how many awards it won, but whether it's watertight. Obviously winning a prestigious prize means it's watertight, but the converse doesn't follow. A protocol can be safe for practical use without winning any prizes.

It can, but given Telegram's history and professional cryptographers like Schneier[1] and Green[2] saying DO NOT USE IT, it's obvious it's _anything_ but watertight.

[1] https://www.schneier.com/blog/archives/2016/06/comparing_mes...

[2] https://twitter.com/matthew_d_green/status/72642891296898252...

Re: Telegram messaging app proves crucial to Belarus protests

#415

Earlier quoted context omitted.

And how is Signal's protocol is not "roll their own" ? Sorry I don't know.

First of all, most of this goes back five years and things have likely changed, but basically MTProto used several non-standard and out of date security mechanisms (no AE and using SHA1 were fairly notable at the time) whereas Signal was purposing fairly standard and widely used mechanisms (OTR). It's possible that many of those failures have been addressed over the years, but I haven't followed it closely. It's wort…

The very fact out-of-date security mechanisms passed into first version should tell the developers don't follow their field, or that they're complete amateurs. Both are flags so red Stalin would have a problem with it.

Re: Telegram messaging app proves crucial to Belarus protests

#416
post #393

Earlier quoted context omitted.

I don't understand how they will get the chats except from individual phones. The convo is encrypted between telegram app and their servers and the servers aren't available to Bealrus' government officials, so how are they going to get the messages? Obviously they can if they're monitoring public group chats because all they have to do is join, but person to person or private groups, how are they going to get to thos…

" I don't understand how they will get the chats except from individual phones. " ~~By default~~ Telegram's group chats used to organize protests aren't E2EE. If Belarusian government hacks Telegram server, they can read every dissident group's chat history trivially.

E2EE is not available at all for group chats.

Re: Telegram messaging app proves crucial to Belarus protests

#417

Earlier quoted context omitted.

The Signal Protocol[0] is based on OTR, a technology which had already seen a number of implementations and informed scrutiny by the time Signal came along. [0] https://en.wikipedia.org/wiki/Signal_Protocol

Also an important aspect is that it is open sourced, meaning others can audit it. I'm a little untrusting of people that say "trust me" but also "no, you can't look at it." (unless there is a good reason to hide it, which in this case I do not believe there is)

The thing is, there's nothing to audit.

The world's best audit of Telegram would make the following obvious findings:

1. It's not E2EE by default therefore it's not private and secure by default.

2. It's not E2EE at all for groups therefore it's not safe for use of dissident groups

3. It's not E2EE at all for desktop clients therefore it's not practical in daily messaging.

Any audit of the E2EE part is meaningless when E2EE is so impractical it's not used by users at all.

Re: Telegram messaging app proves crucial to Belarus protests

#418

Earlier quoted context omitted.

The Signal Protocol[0] is based on OTR, a technology which had already seen a number of implementations and informed scrutiny by the time Signal came along. [0] https://en.wikipedia.org/wiki/Signal_Protocol

It's based on the concepts of OTR but it has gone in different directions to actually implement those ideas.

(DH-ratchet is still there. 1536-bit FF-DH was replaced with X3DH etc, but the basic idea is still there. Adding hash ratchet for non-round-trip messaging was a good idea, as was pre-keys stored on server. IMO it's fair to say it's been expanded around OTR)

Re: Telegram messaging app proves crucial to Belarus protests

#419

Earlier quoted context omitted.

Signal does encrypt your messages locally. Also Android supports file encryption you don't need to use full disk encryption anymore. Also I think the policy has changed in Android 10. > All compatible Android devices newly launching with Android Q are required to encrypt user data, with no exceptions.

Signal traditionally had an easy to get encryption key for the local encryption. Now there is a PIN but I don't think it is any protection against having access to the disk. The signal people would prefer that that you deal with the end point security yourself, because they really can't do much there.

Indeed, the PIN is just for SVR. Exported message logs on Android use separate, client-generated, 30-digit, PINs.

Unless the OS+HW provide API for some sort of TPM, it's not possible to provide strong protection for app databases without asking for strong password every time the app is opened. Android has had some sort of sandboxing for a while but it's not comparable to secure enclaves etc. AFAIK.

Re: Telegram messaging app proves crucial to Belarus protests

#420
post #414

Earlier quoted context omitted.

But the standard we should apply to secure chat protocols isn't how many awards it won, but whether it's watertight. Obviously winning a prestigious prize means it's watertight, but the converse doesn't follow. A protocol can be safe for practical use without winning any prizes.

It can, but given Telegram's history and professional cryptographers like Schneier[1] and Green[2] saying DO NOT USE IT, it's obvious it's _anything_ but watertight. [1] https://www.schneier.com/blog/archives/2016/06/comparing_mes... [2] https://twitter.com/matthew_d_green/status/72642891296898252...

Both four years old. Did they not improve since?
Post reply on HN