A Crypto Challenge For The Telegram Developers
thoughtcrime.org
A Crypto Challenge For The Telegram Developers
1–10 of 136 posts
Re: A Crypto Challenge For The Telegram Developers
#2FWIW, I agree the contest is a sham for the reasons moxie & others listed here and elsewhere.
Re: A Crypto Challenge For The Telegram Developers
#3Also, a call to arms to improve the OSS TextSecure implementation.
Re: A Crypto Challenge For The Telegram Developers
#4Re: A Crypto Challenge For The Telegram Developers
#5Another guy has butthurt from Telegram. As I read somewhere telegram guys said that after 1st march 2014 they somehow will allow to perform MITM in that crypto challenge
Re: A Crypto Challenge For The Telegram Developers
#6So far they've only published the source to their client, but their servers do all of the actual processing and cryptography.
All of Moxie's projects, on the other hand, have always been completely open source.
Re: A Crypto Challenge For The Telegram Developers
#7If they were to release the plaintext of Alice's (or, in their case, Paul's) message, wouldn't that include the secret email address? FWIW, I agree the contest is a sham for the reasons moxie & others listed here and elsewhere.
Re: A Crypto Challenge For The Telegram Developers
#8Even if Telegram's explanation did stand up to scrutiny and was ran by experienced cryptographers, the fact that its core code is closed source makes it utterly worthless from a security perspective. They can tout their own security all they like, but if no one else can independently verify it then it means nothing. So far they've only published the source to their client, but their servers do all of the actual proce…
Re: A Crypto Challenge For The Telegram Developers
#9Another guy has butthurt from Telegram. As I read somewhere telegram guys said that after 1st march 2014 they somehow will allow to perform MITM in that crypto challenge
http://telegram.org/img/key_image.jpg
I wager that if they did allow a tampering eavesdropper in their bounty contest, it would be in the same conversation that has already done a key exchange and verification, making it yet more snake oil. You can hardly call something secure when you don't allow real-world MITM attacks in testing.
Re: A Crypto Challenge For The Telegram Developers
#10Even if Telegram's explanation did stand up to scrutiny and was ran by experienced cryptographers, the fact that its core code is closed source makes it utterly worthless from a security perspective. They can tout their own security all they like, but if no one else can independently verify it then it means nothing. So far they've only published the source to their client, but their servers do all of the actual proce…