Live data from Hacker News

$200,000 to the first person to break Telegram

telegram.org

151–160 of 176 posts

Re: $200,000 to the first person to break Telegram

#152

Earlier quoted context omitted.

Our Twofish cryptanalysis contest offers a $10K prize for the best negative comments on Twofish that aren't written by the authors. There are no arbitrary definitions of what a winning analysis is. There is no ciphertext to break or keys to recover. We are simply rewarding the most successful cryptanalysis research result, whatever it may be and however successful it is (or is not). Again, the contest is fair because…

Moxie is a great researcher and WhisperSystems seem serious. However, I don't understand why you claim that TextSecure is designed by cryptographers. From what I've seen, they use something called the "Axolotl Ratchet", developed by Trevor Perrin. A quick search of his name didn't yield any crypto papers / research by him. Also, you write " and has been studied in detail for years " There are no links/references to c…

Trevor Perrin worked at Cryptography Research (I mean, the domain name is cryptography.com!) for six years, which alone should probably be enough to call yourself a cryptographer. His other work outside of CRI is also really quite prolific.

> Again, I have the utmost respect for their research, it's just that from the side of a non-crypto-versed user/coder, Telegram and TextSecure look the same.

Yep, it's frustrating to be the quixotically genuine seller in a market for lemons.

Re: $200,000 to the first person to break Telegram

#153

This is a bullshit challenge. The attack model in which it is set is nothing like the theoretical models cryptographic systems are designed to be secure against, and even less like how crypto software is actually attacked in practice. There is no possibility for known plaintext, chosen plaintext, chosen ciphertext, side channels, etc. If they just encrypted their communications with AES-128 in ECB mode with a fixed r…

[deleted]

Re: $200,000 to the first person to break Telegram

#154

Earlier quoted context omitted.

Our Twofish cryptanalysis contest offers a $10K prize for the best negative comments on Twofish that aren't written by the authors. There are no arbitrary definitions of what a winning analysis is. There is no ciphertext to break or keys to recover. We are simply rewarding the most successful cryptanalysis research result, whatever it may be and however successful it is (or is not). Again, the contest is fair because…

Moxie is a great researcher and WhisperSystems seem serious. However, I don't understand why you claim that TextSecure is designed by cryptographers. From what I've seen, they use something called the "Axolotl Ratchet", developed by Trevor Perrin. A quick search of his name didn't yield any crypto papers / research by him. Also, you write " and has been studied in detail for years " There are no links/references to c…

Perrin appears to be one of the lead authors here: http://tack.io/draft.html

You might also try reading some of his more recent discussion comments on IETF working groups:

- http://www.ietf.org/mail-archive/web/websec/current/maillist...

- http://www.ietf.org/mail-archive/web/tls/current/maillist.ht...

- (from 2002): http://mhonarc.domainunion.de/archive/html/ietf-openpgp/2002...

Just a few things that turned up when I Googled him.

Re: $200,000 to the first person to break Telegram

#155
Pavel, since you are here,

Don't you think that you are basically fighting a needless uphill battle here? I mean, people crave a good encrypted communication system and you have the intent and the infrastructure in place, but you are shooting yourselves in the foot with your cryptographic design indulgence. This animosity will continue, because Telegram crew comes across as cocky and arrogant know-it-alls, and not because people think you cannot design a crypto protocol. The contest doesn't help a bit, it only further enforces the impression of arrogance on your end. This is not what you would've done if you in fact allowed for the existence of flaws in your design. You would've released an RFC instead.

I have all the sympathy for you. I don't doubt your motives, but you are setting yourselves up against skilled technical crowd. It has already started off on the wrong foot and this unfortunate dynamic will continue.

Perhaps consider offering an alternative crypto suite based on standard protocols? In parallel with what you have. Just reuse an existing crypto framework and redo transport layer to your needs.

Re: $200,000 to the first person to break Telegram

#156
post #135

I have a better challenge! From today until March 1, 2014, I will SSH into my server and type a secret email address on the command prompt. Send me an email to that address and tell me my crypto key, and I will allow you to pet my dog for 5 minutes. (Sorry, I do not have $200k in BTC, or any other currency, for that matter :(, but my dog is totally cute.) The point is, the above challenge is impossible without a MITM…

Your challenge isn't at all hard. An attacker could get into your server using some other method besides breaking SSH then simply look at your bash history.

Only if enter is pressed!

Re: $200,000 to the first person to break Telegram

#157
post #152

Earlier quoted context omitted.

Moxie is a great researcher and WhisperSystems seem serious. However, I don't understand why you claim that TextSecure is designed by cryptographers. From what I've seen, they use something called the "Axolotl Ratchet", developed by Trevor Perrin. A quick search of his name didn't yield any crypto papers / research by him. Also, you write " and has been studied in detail for years " There are no links/references to c…

Trevor Perrin worked at Cryptography Research (I mean, the domain name is cryptography.com!) for six years, which alone should probably be enough to call yourself a cryptographer. His other work outside of CRI is also really quite prolific. > Again, I have the utmost respect for their research, it's just that from the side of a non-crypto-versed user/coder, Telegram and TextSecure look the same. Yep, it's frustrating…

I have a question about TextSecure. Do you plan on implementing something like SMP from OTRv3 in the TextSecure protocol?

Re: $200,000 to the first person to break Telegram

#158
post #53

Earlier quoted context omitted.

No, the goal of these security products is to defend against the government, not a random guy. In that context, it's extremely important that their server undergo the same level of cryptanalysis.

We already know the system is hopelessly vulnerable to server side MITM attacks, it makes no effort to defend against that attack model. It's mentioned in the comments that they might do manual key verification in the future, but that doesn't happen now. Compromise is silent.

Not only is it possible, they are doing it already. I installed telegram on two devices (android and ipad) and they somehow were both able to decrypt incoming messages. How did the second device get the key..?

Re: $200,000 to the first person to break Telegram

#159
post #135

I have a better challenge! From today until March 1, 2014, I will SSH into my server and type a secret email address on the command prompt. Send me an email to that address and tell me my crypto key, and I will allow you to pet my dog for 5 minutes. (Sorry, I do not have $200k in BTC, or any other currency, for that matter :(, but my dog is totally cute.) The point is, the above challenge is impossible without a MITM…

Pet your dog? Now you're singing my song, potnuh...

Re: $200,000 to the first person to break Telegram

#160

Note to everyone in technology...Hacker News isn't the crowd that you need to impress. The cryptanalysis community, in particular, has a small group of experts that can credibly critique your ideas. They would probably love to pick apart a new system...seriously in the hopes that it advances the art, but critically in the case that it doesn't. Claims of some kind of "tightly knit" cabal of closed minded people exclud…

Did I miss somewhere where it stated this was HN-specific? This could just as easily have (and probably has) been posted to multiple communities, including ones that are more crypto-focused. Just because it appears here does not in any way shape or form indicate that they're trying to impress the HN community, nor that they're specifically targeting HN.

This contest is a direct result of some arguments that happened on HN when they announced their product.
Post reply on HN