Live data from Hacker News

$200,000 to the first person to break Telegram

telegram.org

71–80 of 176 posts

Re: $200,000 to the first person to break Telegram

#71
post #53

Earlier quoted context omitted.

No, the goal of these security products is to defend against the government, not a random guy. In that context, it's extremely important that their server undergo the same level of cryptanalysis.

We already know the system is hopelessly vulnerable to server side MITM attacks, it makes no effort to defend against that attack model. It's mentioned in the comments that they might do manual key verification in the future, but that doesn't happen now. Compromise is silent.

Is that really the case? Would you mind linking to that? Because if that's true, then this contest is dangerously misleading.

Re: $200,000 to the first person to break Telegram

#73
post #2

So yeah guys, Pavel Durov saw your comments regarding security of Telegram messenger. Go for it.

All the haters here can go pound sand. It's a cool project, and I like the mindset behind it: https://telegram.org/faq#q-how-are-you-going-to-make-money-o...

Re: $200,000 to the first person to break Telegram

#75
post #17

Earlier quoted context omitted.

It actually makes things worse really "no hackers can break this!" sounds good on paper, but it could just mean your adversary has more to gain by the system not being publicly broken.

I don't see how it makes things worse. Surely it shows more if you gave hackers a big incentive to crack your encryption and they still didn't, compared to them not cracking it when there was no incentive. It is evidence that the reason they did not crack it was the difficulty of the problem, not just indifference.

A 73 day deadline on no notice to crack the system in a very specific way with no pay for people who succeed after the first is not a very big incentive. How many highly compensated security experts do you expect to stop doing their jobs for the opportunity to work for free?

Re: $200,000 to the first person to break Telegram

#76
post #53

Earlier quoted context omitted.

No, the goal of these security products is to defend against the government, not a random guy. In that context, it's extremely important that their server undergo the same level of cryptanalysis.

We already know the system is hopelessly vulnerable to server side MITM attacks, it makes no effort to defend against that attack model. It's mentioned in the comments that they might do manual key verification in the future, but that doesn't happen now. Compromise is silent.

Let me respectfully disagree with you here. Secret Chats in Telegram provide users with a way to detect a server-side MITM attack. http://core.telegram.org/techfaq#q-how-are-telegram-users-pr...

Re: $200,000 to the first person to break Telegram

#77
post #65

Earlier quoted context omitted.

I'm afraid breaking into Telegram's central server (by the way, there is no such thing) will hardly enable you to decipher end-to-end encrypted secret chats. But certainly worth trying anyway.

It will allow you to conduct a man-in-the-middle attack on all encrypted traffic though, which would certainly be enough to read messages in plaintext.

http://core.telegram.org/techfaq#q-how-are-telegram-users-pr...
Post reply on HN