The last point Schneider made of them winning but not telling you until they feel it's worth it is still valid.
$200,000 to the first person to break Telegram
161–170 of 176 posts
Re: $200,000 to the first person to break Telegram
#162Earlier quoted context omitted.
OK, but where the hell are they going to get 2.5 months of highly motivated attacks by highly skilled people? All the people I would want looking at this aren't going to waste such a huge chunk of their time analyzing some random phone app trying to make a name for themselves for a chance at a cash reward. Bug bounties by big name companies that are actually after bugs rather than publicity haven't miraculously made…
I agree with you here. That is why such contests are going to be permanent in Telegram. New contests like this will be launched in March 2014 or earlier if anyone wins earlier. Consider the date for breaking Telegram open.
Re: $200,000 to the first person to break Telegram
#163This is $200,000 in bitcoins, not actually $200,000.
> Q: What if I don‘t trust bitcoins and don’t want them as a prize?
>If the winner prefers conventional money over bitcoin, we will be happy to transfer them 200,000 regular USD instead of BTC.
Re: $200,000 to the first person to break Telegram
#164I have a better challenge! From today until March 1, 2014, I will SSH into my server and type a secret email address on the command prompt. Send me an email to that address and tell me my crypto key, and I will allow you to pet my dog for 5 minutes. (Sorry, I do not have $200k in BTC, or any other currency, for that matter :(, but my dog is totally cute.) The point is, the above challenge is impossible without a MITM…
Your challenge isn't at all hard. An attacker could get into your server using some other method besides breaking SSH then simply look at your bash history.
Re: $200,000 to the first person to break Telegram
#165I have a better challenge! From today until March 1, 2014, I will SSH into my server and type a secret email address on the command prompt. Send me an email to that address and tell me my crypto key, and I will allow you to pet my dog for 5 minutes. (Sorry, I do not have $200k in BTC, or any other currency, for that matter :(, but my dog is totally cute.) The point is, the above challenge is impossible without a MITM…
Your challenge isn't at all hard. An attacker could get into your server using some other method besides breaking SSH then simply look at your bash history.
Re: $200,000 to the first person to break Telegram
#166This is such a sham. Here, I'll offer $2000 to break my plaintext crypto. Every morning, in the shower, I'll say a secret word. Email me the secret word and I'll send you $2000 in BTC.
Re: $200,000 to the first person to break Telegram
#167Earlier quoted context omitted.
Excluding an entity like the NSA, who cares nothing for $200,000 (literally a rounding error in their budget), but everything for the information available for the taking.
While I agree with your point, immediately jumping to the NSA and their bottomless pool of resources and talent is kind of the new Godwin's law. Logan's law: In any given discussion tangentially related to security, the thing presented as "secure" will be soon declared "definitely not secure"... because...NSA.
Re: $200,000 to the first person to break Telegram
#168Earlier quoted context omitted.
We already know the system is hopelessly vulnerable to server side MITM attacks, it makes no effort to defend against that attack model. It's mentioned in the comments that they might do manual key verification in the future, but that doesn't happen now. Compromise is silent.
Not only is it possible, they are doing it already. I installed telegram on two devices (android and ipad) and they somehow were both able to decrypt incoming messages. How did the second device get the key..?
Re: $200,000 to the first person to break Telegram
#169Earlier quoted context omitted.
Not only is it possible, they are doing it already. I installed telegram on two devices (android and ipad) and they somehow were both able to decrypt incoming messages. How did the second device get the key..?
Ah! You were mistaken in the functioning of the service (I thought this might happen). You have to specifically ask for a secure chat with a button press, normally everything is effectively plaintext.
Re: $200,000 to the first person to break Telegram
#170Pavel, since you are here, Don't you think that you are basically fighting a needless uphill battle here? I mean, people crave a good encrypted communication system and you have the intent and the infrastructure in place, but you are shooting yourselves in the foot with your cryptographic design indulgence. This animosity will continue, because Telegram crew comes across as cocky and arrogant know-it-alls, and not be…