Live data from Hacker News

$200,000 to the first person to break Telegram

telegram.org

101–110 of 176 posts

Re: $200,000 to the first person to break Telegram

#101
Judging by the phone numbers, I would say that this is likely to be some form of elliptic curve cryptography with domain parameters different from the NIST and GOST standards.

I don't personally have the depth of experience with elliptic curves to go about cracking this crypto, but others have cracked elliptic curve algorithms. Perhaps one of those people will find this tidbit useful in narrowing the field.

Also, I would expect that at least some of the plain text is Unicode, probably the plane from 0400-04FF.

Re: $200,000 to the first person to break Telegram

#102

Earlier quoted context omitted.

Unfortunately, this doesn't mean that it's secure. If someone breaks it, it means it's broken, but if nobody breaks it, it doesn't mean someone else can't break it (or hasn't already).

Agreed, but the tone of the previous discussion was definitely more along the lines of "This could never work, you guys don't know what you're doing." If it proves resilient over 2.5 months of highly motivated attacks (motivated by both the money / "I-Told-You-So" factor), I think that's a fairly strong statement in their favor.

Nobody's claiming it won't work; they're claiming it will work in a way that is dangerous to its users.

Re: $200,000 to the first person to break Telegram

#103
post #89
post #87

Earlier quoted context omitted.

This is irrelevant - the "secret chat" mode is not the default (according to someone else in this thread) and you're just shoving the key verification process off on to the user with these silly graphic patterns (which, if OTR is any indication, the user won't verify anyway). This is still vulnerable to server-side _key_ MITM. It's the hushmail/iMessage/etc silent escrow key attack.

The interesting thing with the graphic patterns is that they're lossy. If you assume that a person will just describe the pattern or show a picture of them to one another, it becomes fairly easy to forge them. http://telegram.org/img/key_image.jpg Blue in the top and bottom, white line through the middle. So little information that anybody could simply brute force the keys until they found one that matched the descri…

Someone did exactly this "fuzzy fingerprint" attack for ssh host keys in 2003:

https://www.thc.org/papers/ffp.html

Re: $200,000 to the first person to break Telegram

#104
post #98

Earlier quoted context omitted.

Is that really the case? Would you mind linking to that? Because if that's true, then this contest is dangerously misleading.

https://news.ycombinator.com/item?id=6924866

If you read the comments on that blog, telegram actually negate that:

> the server can perform a MITM attack. > you cannot detect MITM between you and your peers.

>> NOT true. You can compare key visualization in the clients.

Re: $200,000 to the first person to break Telegram

#105
post #103
post #89

Earlier quoted context omitted.

The interesting thing with the graphic patterns is that they're lossy. If you assume that a person will just describe the pattern or show a picture of them to one another, it becomes fairly easy to forge them. http://telegram.org/img/key_image.jpg Blue in the top and bottom, white line through the middle. So little information that anybody could simply brute force the keys until they found one that matched the descri…

Someone did exactly this "fuzzy fingerprint" attack for ssh host keys in 2003: https://www.thc.org/papers/ffp.html

That was a very good read that I wasn't aware of, thanks for the URL.

Re: $200,000 to the first person to break Telegram

#106
post #98

Earlier quoted context omitted.

https://news.ycombinator.com/item?id=6924866

If you read the comments on that blog, telegram actually negate that: > the server can perform a MITM attack. > you cannot detect MITM between you and your peers. >> NOT true. You can compare key visualization in the clients.

https://news.ycombinator.com/item?id=6932053

The key is not shown in hex, so a MITM is quite simple.

Re: $200,000 to the first person to break Telegram

#107
post #29

Cryptography Snake Oil Warning Sign #9: Cracking contests. https://www.schneier.com/crypto-gram-9902.html (1999)

Wouldn't legitimate cryptography products also tend to offer such challenges? It's not much different than bug bounties, which are common and (at least according to my impression) well-accepted as a legitimate practice.

Re: $200,000 to the first person to break Telegram

#108
post #80

to do this "right" shouldn't they release a hash now of the keys that will be exposed in march; as well as sign a message from a bitcoin address containing ~500btc?

Why a hash now, do you think they're going to be able to release fake keys that somehow decrypt the cyphertext to email addresses?

And converting into bitcoin months preemptively is a speculative gamble, not a verification of anything.

Re: $200,000 to the first person to break Telegram

#110

> 100% FREE & NO ADS: Telegram is free and will always be free. We do not plan to sell ads or introduce subscription fees. how you are then going to make a money ?

Paid features, like stickers and etc.

Sorry, but how does Google ads mediation have anything to do with stickers and the like? I fail to see the connection.
Post reply on HN