Live data from Hacker News

Telegram, a.k.a. “Stand back, we have Math PhDs”

unhandledexpression.com

41–50 of 56 posts

Re: Telegram, a.k.a. “Stand back, we have Math PhDs”

#41
post #37

Smugness aside, I am actually concerned about this implementation and Telegram's response: > The rest looks like matters of taste as opposed to objective reasoning. Can you name an actual attack? The response to that is, "I shouldn't have to!" Anything that replaces a proven secure component with something that we haven't (yet) found an attack on is grounds for suspicion at the very least. SHA-1 isn't a MAC. It's not…

Agreed. To quote Colin Percival's excellent article which addresses both topics:

"Assessing the security of software via the question "can we find any security flaws in it?" is like assessing the structure of a bridge by asking the question "has it collapsed yet?" -- it is the most important question, to be certain, but it also profoundly misses the point. Engineers design bridges with built-in safety margins in order to guard against unforeseen circumstances (unexpectedly high winds, corrosion causing joints to weaken, a traffic accident severing support cables, et cetera); secure software should likewise be designed to tolerate failures within individual components. Using a MAC to make sure that an attacker cannot exploit a bug (or a side channel) in encryption code is an example of this approach: If everything works as designed, this adds nothing to the security of the system; but in the real world where components fail, it can mean the difference between being compromised or not. The concept of "security in depth" is not new to network administrators; but it's time for software engineers to start applying the same engineering principles within individual applications as well."

http://www.daemonology.net/blog/2009-06-24-encrypt-then-mac....

Re: Telegram, a.k.a. “Stand back, we have Math PhDs”

#42

Earlier quoted context omitted.

Because Telegram is acting careless, and ignoring actual criticism, while touting claims that do not appear to be true? It's close to lying and scamming users. If Telegram was a messaging proposal, I'm sure the attitude would be a more straightforward one (with the same end result of "you're not ready to handle this yet"). Instead, it's billed as a definitely secure system. Seriously, read the previous thread: https:…

So which efforts are leading the pack at this stage that I could recommend to my entire family who practically daily urge me to join them on Viber? Years ago I would have said Skype. Now I just don't know. I'm saddened because I thought Telegram looked pretty sweet and a serious new contender. Practically calling them liars after that much hard work is unfair.

If none of the available options are acceptably secure, it doesn't do anyone any favors to point to the one that's least broken and tell them to use that. That just leads to people putting sensitive information into a tool that can't protect it. It's better for everyone to just say that there is no secure choice currently and leave it at that.

Re: Telegram, a.k.a. “Stand back, we have Math PhDs”

#43
post #32

Earlier quoted context omitted.

I hear you. Agreed. Surely every decent crypto system started off home-grown?

There's a line with this sort of stuff, and the crossing of it is what I have an issue with. If they presented it as an attempt and asked for critique, then this would have been a fine thing to publish. They would have got chewed out by a professional, fixed it or removed it, and everyone would go away learning something new. The issues comes when they don't accept critique, and make claims that don't stack up in act…

Exactly. Being wrong is fine. Being stubbornly wrong is not.

Re: Telegram, a.k.a. “Stand back, we have Math PhDs”

#44

Why so smug? I've seen this attitude in all types of IT heads (sys admins easily being the worst of the bunch) over the years. What is it about techies that they come over so smug when pointing out deficiencies in others? I still have the shame and anger provoking memory of two techies sniggering not-so-openly at me because I didn't know about name service switch in UNIX because guess what, I don't know everything. W…

I initially had the same reaction as you, but reading the discussion between the author and Telegram in the comments (both on the linked article and the original HN thread) it seems to be this is largely deserved given the way Telegram has been responding. They've essentially refused to justify any any of their (curious) choices and relying on authority arguments instead:

> We grew tired of “experts” too lazy to read the full documentation.

Re: Telegram, a.k.a. “Stand back, we have Math PhDs”

#45

Earlier quoted context omitted.

I understand the importance of security. I do hope Telegram can get it right. I acknowledge it is probably not as secure as they claim right now. I still maintain the article author's attitude just rubs me up the wrong way because of the mood I'm in - the smugness (and I hope I'm not imagining it) is definitely a side issue but one I felt I had to get off my chest. I don't want to make a big issue of it and detract t…

Given their attitude, it's unlikely they'll get it right. They'll keep telling people "that's not a real attack" and making up excuses. Then someone will publish a real attack, and they'll patch over it. Repeat. The "smugness" is pointing out problems in their implementation, despite them going on about having "ACM champions" that took two years to design it, so it obviously must be perfect. If someone pitched a data…

I am with you. ACM Champions mean a shit to me, and I have enough publications in crypto and secure communication to claim that I am a ACM Champion, and BTW I have a PHD actually related to security and crypto. But, NONE of my credentials is a valid argument about how secure my protocols are.

This kind of attitude (trust us, we have enough credentials to show) seems to be a universal problem with people in academics. Come on, don't do this. We all get the sense that you have to bluff to get your paper published, but this is not going to work for a product to be accepted.

Re: Telegram, a.k.a. “Stand back, we have Math PhDs”

#46
post #5

Typical NIH syndrome. They hired some smart people who are not cryptographic experts and now their cryptography is broken. Which is pretty much the story for anyone who has ever created a custom cryptographic system (and the story of SSL for the first few years).

Read the comments under TFA. Nothing was broken. The author was quick to write the article without understanding protocol first.

The comments from TFA doesn't say a shit but full of "you are wrong, because you don't understand it" without debating the technical details.

Re: Telegram, a.k.a. “Stand back, we have Math PhDs”

#48
post #4

Earlier quoted context omitted.

Just use RedPhone. Moxie knows what he's doing and it's auditable + good technology. Whatsapp is a joke, but lower friction matters much more for their market.

Wickr seems like a good goto, though I haven't had the need for it yet, so I haven't done all the research I could.

Wickr is closed source.

TextSecure is where it's at. Hopefully the iOS release comes out soon.

Re: Telegram, a.k.a. “Stand back, we have Math PhDs”

#49
post #4
post #2

Well that escalated quickly. Still, nowhere near as bad as Whatsapp I'm assuming?

Just use RedPhone. Moxie knows what he's doing and it's auditable + good technology. Whatsapp is a joke, but lower friction matters much more for their market.

I'm a happy user of whatsapp.

Then again, I'm a happy user under the assumption that everybody everywhere could read my messages if they actually made an effort.

I just don't send anything over whatsapp that I really care about - if the world discovers that I regularly tell my girlfriends I love them, that really doesn't bother me.

Re: Telegram, a.k.a. “Stand back, we have Math PhDs”

#50

Why so smug? I've seen this attitude in all types of IT heads (sys admins easily being the worst of the bunch) over the years. What is it about techies that they come over so smug when pointing out deficiencies in others? I still have the shame and anger provoking memory of two techies sniggering not-so-openly at me because I didn't know about name service switch in UNIX because guess what, I don't know everything. W…

I wrote that article, and I think you are right. That was not the right tone for a review of a new product, even if Telegram's attitude (in particular here https://news.ycombinator.com/item?id=6913456 ) has been of denial and arrogance.

I usually have no temper problem, but everytime someones proposes a new secure system and ignores the holes people point out, because that means I will need to spend months explaining to pepople that they should not use it, even if it is "hype".

So, yes, again, you are right, my apologies.

Post reply on HN