Live data from Hacker News

‘I will show you how safe Telegram is’

twitter.com

141–150 of 206 posts

Re: ‘I will show you how safe Telegram is’

#141

I monitor Russian war channels and some people there insist on using Telegram only for Russian military people. If you use Whatsapp, Ukrainian officers will get all chats from NATO. Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. My takeaway is that for truly private chat one should write his own software using simple crypto without all those fancy clients. Ideally ju…

"Signal might be safe, but I think it's a honeypot."

Based on what?

Signal documents its own encryption process, and you can check the app source code to verify it. https://signal.org/docs/specifications/doubleratchet/

Signal is the best choice I know of when I'm looking for the union of 1. True e2e encryption, and 2. Ease of use by non-technical people.

Re: ‘I will show you how safe Telegram is’

#142

All fine and dandy but so far I have lost entire conversations on signal, whatsapp and matrix while this never happened to me on telegram, which is the number one thing that matters to me.

Retrieving the victim's entire chat history is also the number one thing that matters to hackers.

Re: ‘I will show you how safe Telegram is’

#143
post #53
post #44

Earlier quoted context omitted.

Everyone in that group also has to manage to keep that 1 GB secret.

also how do you ensure the messages haven't been corrupted in transit

1. For each letter of the plaintext, concatenate "dontcorruptmebro"

2. Grab 17 letters from the pad (I'm assuming pad means the randomly chosen letters that make up the 1 gigabyte of shared secret among the participants)

3. Convert the first letter of the pad to a number (let's say 1-26)

4. Right-shift the message by that amount and let the letters wrap around: e.g., if the plaintext letter is g and we're shifting by 1 the plaintext becomes "ogdontcorruptmebr"

5. Encrypt with pad (not a cryptographer, but I'm assuming this means adding a character of the shared secret with a character of the plaintext, and wrapping around if it goes past the end)

6. Send

7. Decrypt with pad

8. Left-shift and wrap by $first_pad_letter_value (i.e., the same value we used to right-shift and wrap above)

9. Remove the "dontcorruptmebro" part to concatenate the plaintext letters to reveal the original message

10. Rinse and repeat, and do whatever secure messengers do if/when you receive a part of the "dontcorruptmebro" that isn't "dontcorruptmebro"

I only thought about this for a few minutes, and I'm not a cryptographer. So I'm honestly asking-- did I solve the corruption-in-transit problem without screwing up anything?

Edit: just to be clear-- I'm not trying to be efficient, or to authenticate, or do anything whatsoever other than a dead simple thing that can be implemented easily.

Edit 2: clarification

Re: ‘I will show you how safe Telegram is’

#145

Earlier quoted context omitted.

"Please don't complain about tangential annoyances—e.g. article or website formats, name collisions, or back-button breakage. They're too common to be interesting." - https://news.ycombinator.com/newsguidelines.html

It appears that frustration with twitter threads is too common to be interesting. Not unexpected.

That's correct. The reason we don't want such comments isn't that they're unjustified, it's that they're repetitive.

Re: ‘I will show you how safe Telegram is’

#146

Earlier quoted context omitted.

Moxie Marlinspike is a lot of things but I'm pretty confident the queen bee of a honeypot is not one of them.

Signal is funded by the US State Department[1]. I'm sure you can trust it to send messages to your drug dealer, your mistress, or the competitor you are selling you company's secrets to. I wouldn't trust it if I wanted to keep secrets from american 3 letter agencies, though. [1] https://www.mintpressnews.com/the-open-technology-fund-makes...

DARPA was going to contribute money to the OpenBSD project (which also maintains OpenSSH) before Theo said some things critical of the Iraq war and they retracted it. I wonder how many people would have accused them of being CIA plants if they took the grant money. Regardless, there are many competing interests and bureaucracies in the US government and it's not a safe assumption that they are in cahoots with each other on encryption they can break on demand. It's usually a more complicated picture than just "the government". Some of this funding is likely with the well meaning intention and goal of strengthening the security and privacy of communication between Americans.

Re: ‘I will show you how safe Telegram is’

#147
post #38

Better to link to the actual story (Guardian in partnership with a few others): https://www.theguardian.com/world/2023/feb/15/revealed-disin... Covered already on HN: https://news.ycombinator.com/item?id=34800157 https://news.ycombinator.com/item?id=34803779 Etc

Speaking of the actual story, how come they put all of this effort into unmasking this guy, discussing the consequences of his actions to the integrity of democracies... but then he says "I hack into Telegram accounts by using an SS7 vulnerability", and they just copy and paste that verbatim into the story, not even bothering to explain it in the slightest? Obviously it's because they themselves don't know what it me…

The SS7 might just be a cover for a basic spear phishing attack. Otherwise I'm not sure why to demo it you wouldn't hack the actual politician's phone, instead of just doing his assistant.

Re: ‘I will show you how safe Telegram is’

#148
For me personally, the main argument against Telegram is that its development and operations team is physically located in Russia. This means that they can very easily be bribed and/or intimidated into any type of collaboration with their state.

Re: ‘I will show you how safe Telegram is’

#149
post #77

I monitor Russian war channels and some people there insist on using Telegram only for Russian military people. If you use Whatsapp, Ukrainian officers will get all chats from NATO. Telegram accounts of opposition were hacked by belarus police as well. It's known and documented. My takeaway is that for truly private chat one should write his own software using simple crypto without all those fancy clients. Ideally ju…

> My takeaway is that for truly private chat one should write his own software using simple crypto without all those fancy clients. That‘s actually pretty secure in practice, because you won‘t be communicating with anybody. > Ideally just use one time keys and xor everything. How do you generate the keys? How do you share them? And you only care about encryption, authentication does not matter to you at all? The chan…

> That‘s actually pretty secure in practice, because you won‘t be communicating with anybody.

Nice. In all seriousness though, there has to be a way to make a hand-rolled but secure channel. E.g. use standard crypto libraries, hand-exchange keys or key phrases, etc?

Re: ‘I will show you how safe Telegram is’

#150

Earlier quoted context omitted.

Both could be, just from different queen bees

Moxie Marlinspike is a lot of things but I'm pretty confident the queen bee of a honeypot is not one of them.

Moxie Marlinspike - and Whisper Systems - have assumed a variety of concerning positions over the years. Concerning, because their flaws are obvious, yet Moxie - a very smart guy - pretends not to notice them.

For example, Moxie defended discontinuing encrypted SMS on the grounds that it leaked metadata to telcos - yet failed to emphasize that this was merely the same metadata leaked to Whisper Systems, or justify why we should trust Whisper Systems more. "Just trust us" policies are worrying.

Moxie's defense of failing to provide any alternative to downloading Signal/TextSecure from Google Play also contained a number of very eye raising frank admissions, including that Whisper Systems was motivated by the ability to silently push updates and monitor its users (there's that "just trust us" again). Followed by the very weird assertion that "Avoiding Play alone is not a privacy win", which is a bit like saying there's no point wearing a seatbelt because you might get injured in other ways.

Whisper Systems is notoriously hostile to any use of Signal that doesn't involve their official client, going through servers they administrate (servers which run code they release infrequently if at all). Signal has made no attempt to bootstrap a federated system, even though this would save them money. They are extremely keen to maintain ironclad control over both the app and the server, and are willing to take unusual security postures in service of this.

I've read enough stuff from Moxie that makes me say "what, that doesn't make sense" to make me very suspicious.

Post reply on HN