Live data from Hacker News

$200,000 to the first person to break Telegram

telegram.org

81–90 of 176 posts

Re: $200,000 to the first person to break Telegram

#81
post #5

Travel to russia, get big wrench and hit Durov with it until he gives up his password. Win 200k. In all seriousness, im interested to see if anyone can crack this.

A Russian friend of mine mentioned playing in an MMO with another guy called 'Krusk' for a year or so before realising that the other guy was also Russian, and 'Krusk' was the anglicised version of the Russian word for "the sound bones make when you crush them"...

Re: $200,000 to the first person to break Telegram

#82

Earlier quoted context omitted.

Agreed, but the tone of the previous discussion was definitely more along the lines of "This could never work, you guys don't know what you're doing." If it proves resilient over 2.5 months of highly motivated attacks (motivated by both the money / "I-Told-You-So" factor), I think that's a fairly strong statement in their favor.

Not quite 2.5 months.

How time flies.. I read it as Mar 31, 2014 originally and didn't realize it was already Dec 18.. Edited to reflect that it's not really 4 months.

Re: $200,000 to the first person to break Telegram

#83

Earlier quoted context omitted.

Agreed, but the tone of the previous discussion was definitely more along the lines of "This could never work, you guys don't know what you're doing." If it proves resilient over 2.5 months of highly motivated attacks (motivated by both the money / "I-Told-You-So" factor), I think that's a fairly strong statement in their favor.

i have a day job and i'm not going to drop everything for the chance i won't make any money at all... told-you-so factor or not.

I could imagine a lot of university math students (young, hungry, nothing to lose) would be highly motivated by this.

Re: $200,000 to the first person to break Telegram

#84

This is such a sham. Here, I'll offer $2000 to break my plaintext crypto. Every morning, in the shower, I'll say a secret word. Email me the secret word and I'll send you $2000 in BTC.

I'll need to narrow it down further, but I'm pretty sure it's one of "Oh", "god", "groan", "I'm", "running", "late", "for", "work", "again". Hrm, does groan count as a word? How many guesses am I allowed?

Re: $200,000 to the first person to break Telegram

#85
post #53

Earlier quoted context omitted.

We already know the system is hopelessly vulnerable to server side MITM attacks, it makes no effort to defend against that attack model. It's mentioned in the comments that they might do manual key verification in the future, but that doesn't happen now. Compromise is silent.

Let me respectfully disagree with you here. Secret Chats in Telegram provide users with a way to detect a server-side MITM attack. http://core.telegram.org/techfaq#q-how-are-telegram-users-pr...

That only protects against a MITM between peers who have communicated with a "secret chat" previously, not two fresh peers. As "secret charts" are disabled by default it's not really a defence against infiltration; users will presumably only enabled the "secret chat" mode when they have something sensitive to talk about.

When they do enabled it for the first time, we can instantly MITM them using the attack against the "image verification" I mentioned lower down (https://news.ycombinator.com/item?id=6932053), and we can assume that the conversation is worth our while listening in on. The user will hopefully expose themselves in the belief that they are safe, and the game is over.

Re: $200,000 to the first person to break Telegram

#86
post #29

Cryptography Snake Oil Warning Sign #9: Cracking contests. https://www.schneier.com/crypto-gram-9902.html (1999)

Our Twofish cryptanalysis contest offers a $10K prize for the best negative comments on Twofish that aren't written by the authors. There are no arbitrary definitions of what a winning analysis is. There is no ciphertext to break or keys to recover. We are simply rewarding the most successful cryptanalysis research result, whatever it may be and however successful it is (or is not). Again, the contest is fair because…

[deleted]

Re: $200,000 to the first person to break Telegram

#87
post #65

Earlier quoted context omitted.

It will allow you to conduct a man-in-the-middle attack on all encrypted traffic though, which would certainly be enough to read messages in plaintext.

http://core.telegram.org/techfaq#q-how-are-telegram-users-pr...

This is irrelevant - the "secret chat" mode is not the default (according to someone else in this thread) and you're just shoving the key verification process off on to the user with these silly graphic patterns (which, if OTR is any indication, the user won't verify anyway).

This is still vulnerable to server-side _key_ MITM. It's the hushmail/iMessage/etc silent escrow key attack.

Re: $200,000 to the first person to break Telegram

#89
post #87

Earlier quoted context omitted.

http://core.telegram.org/techfaq#q-how-are-telegram-users-pr...

This is irrelevant - the "secret chat" mode is not the default (according to someone else in this thread) and you're just shoving the key verification process off on to the user with these silly graphic patterns (which, if OTR is any indication, the user won't verify anyway). This is still vulnerable to server-side _key_ MITM. It's the hushmail/iMessage/etc silent escrow key attack.

The interesting thing with the graphic patterns is that they're lossy. If you assume that a person will just describe the pattern or show a picture of them to one another, it becomes fairly easy to forge them.

http://telegram.org/img/key_image.jpg

Blue in the top and bottom, white line through the middle. So little information that anybody could simply brute force the keys until they found one that matched the description well enough.

I'd happily write a little attack for that, but it's clearly not "breaking" the system enough for the bounty.

Post reply on HN