Live data from Hacker News

Telegram protocol defeated. Authors are going to modify crypto-algorithm

translate.google.com

41–50 of 223 posts

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#41
Here are some of their comments:

ibeatle

Большое спасибо, автор поста полностью прав. Со своей стороны хотим пояснить, что сделано это было из лучших побуждений: исправление плохого рандома на клиентах. С настоящего момента в nonce всегда будет приходить ноль, и в следующем слое мы обязательно удалим это поле из схемы и поясним в документации. Автор топика безусловно заслужил награды, просьба обратиться хабраюзера x7mz на email support@telegram.org для уточнения деталей.

Translation:

Thanks very much, the author is absolutely correct. Just wanted to explain that the intentions were good: to correct bad "random" on the client side.

From this point on nonce will always be set to 0, and next we will definitely remove it from our diagram and explanations in the docs.

The author definitely deserves a prize, please enquire at the following email for details.

W_K

Товарищ прав — похоже, сервер в принципе может с помощью манипуляции с nonce выполнить MiTM на DH между клиентами. Не знаю, кто именно внедрил этот nonce в такой форме, хотя и знаю, какое предъявлялось обоснование — он был нужен для того, чтобы защититься от слабого рандома на клиентах, которых в принципе может писать кто угодно. Очевидно, нужно сделать этот nonce нулём и написать, что клиенты впредь не должны принимать секретные чаты с ненулевым nonce.

Удивительно, что человек, называющий себя «чайником» в криптографии, нашёл действительно серьёзный недостаток протокола, в отличие от многих якобы «профессионалов», постоянно придирающихся не по существу.

Не знаю как насчёт 200k$ — расшифровать трафик это не поможет, а сервер не знает ключа от секретного чата, поскольку на нём нет такой закладки. Но мне очень не нравится, что в будущем такая закладка могла бы быть в принципе кем-нибудь добавлена.

Тем не менее, считаю, за это ценное наблюдение Вам положен ценный приз. Пусть и не такой большой. Если Вы или кто-либо ещё найдёт какие-либо ещё потенциальные дыры в протоколе — сообщайте, будем награждать.

Translation:

He is correct, looks like the server can manipulate nonce and succeed at MiTM on DH between the clients. Not sure who's idea it was to introduce that nonce in this form, but I do understand the motivation, to protect against the "weak random" on the clients that can in theory be written by anyone. Obviously, we need to make nonce=0 and refuse secret chats with non-zero nonce.

It is quite amazing that the man who calls himself "a crypto noob" found a real vulnerability, as opposed to all those so-called professionals whose criticisms were largely unfounded.

Not sure about the $200k since this vulnerability won't really help to decipher the traffic and the server doesn't know the key from the secret chat, because it doesn't have any "bookmark". But I really don't like that in the future such a bookmark could be added.

However, I think this is a valuable observation and you do deserve a prize, even if not such a big one. If you, or anyone else, will find other potential vulnerabilities, please let us know, we will be rewarding.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#42

TextSecure's protocol, on the other hand, hasn't ever been compromised. Don't use Telegram. Use TextSecure. https://whispersystems.org/

That's absolutely true, but I think the reason this seems so devastating for Telegram is not necessarily because there was a vulnerability, but because they were so dismissive of the feedback they got and so willing to immediately make such strong claims.

The way I hope TextSecure can be different from Telegram is not by having an absolutely perfect security record forever (although that'd be great), but by publicly talking about the protocol choices we've made, employing constructions with proofs where possible, and actively soliciting feedback. Thanks for being involved!

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#43
post #36
post #34

There's a lesson here. I genuinely don't mean to sound smug, but -- remember how confident the Telegram guys were? Remember how sure they were that their protocol would be able to resist the eavesdropping efforts of the NSA and whatever other nefarious interlopers may come along? Remember how they said they'd been working on it for years, and presumably expected for it to last many more years? Remember how that was,…

Never forget. RIP Telegram (2013-2013). This whole thing has been interesting to follow because it seems this same thing happens every time someone make macho Crypto-claims. From seeing how confident the Telegram team was to reading all the detractors who were so ready to criticize. It's an interesting dynamic in the Crypto community.

    RIP Telegram (2013-2013).
omg made me lol super hard

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#44
post #8

Earlier quoted context omitted.

Yes. The contest is not about actually exposing flaws in their cryptosystem, which is why the rules are rigged up in a way that would allow even a terribly insecure protocol (like Telegram's, or Moxie's counter-challenge protocol) to pass as "secure".

Telegram's contest itself is meaningless regarding the security of its protocol (as others explained in details). Finding bugs such as this deserves 200k more than anything else

Offering the contest was shady and stupid enough. Not paying just proves they're chiselers that never intended to pay in the first place. This wins the runner-up award for second most botched PR disaster ever. The consolation prize is a lump of coal.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#45
post #38
post #28

As a side note, I didn't notice it was google translate until half way through the article. It's getting really good. Is Russian an "easy" language to translate to English?

My understanding is that it isn't but recent-ish statistical approaches have had lots of success. I know that almost overnight Arabic went from an unreadable mess to about as good as a basic non-native speaker. I wish it'd find its way into usage for East Asian languages more, but I suppose finding dual-equivalent corpuses to build the models off of is hard. https://en.wikipedia.org/wiki/Statistical_machine_translati…

Interesting, thanks!

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#46
post #26

Earlier quoted context omitted.

Why give the prize for not doing what was needed to win the prize, namely reveal the message?

As others have already said, the prize was essentially meaningless because the terms were so narrow. If the spirit of the prize was "if you break our crypto you win", this guy should win it. If the spirit of the prize was "we don't want to give away 200k, but we want to pretend we're secure", he shouldn't

Holiday banter may go something like this: "Carnival booths, lawyers and politicians maybe the most honest... But there was once this company called Telegram that went the way of its namesake. Blah blah... for screwing over a Russian guy in a PR disaster of an unpaid $200k contest award. Maybe they should have offered a canned ham instead."

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#47
post #44
post #8

Earlier quoted context omitted.

Telegram's contest itself is meaningless regarding the security of its protocol (as others explained in details). Finding bugs such as this deserves 200k more than anything else

Offering the contest was shady and stupid enough. Not paying just proves they're chiselers that never intended to pay in the first place. This wins the runner-up award for second most botched PR disaster ever. The consolation prize is a lump of coal.

[deleted]

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#48
post #26

Earlier quoted context omitted.

Why give the prize for not doing what was needed to win the prize, namely reveal the message?

As others have already said, the prize was essentially meaningless because the terms were so narrow. If the spirit of the prize was "if you break our crypto you win", this guy should win it. If the spirit of the prize was "we don't want to give away 200k, but we want to pretend we're secure", he shouldn't

I don't get it. If it's not secure why can't the message be revealed? What's the value of breaking someone's crypto if you are still unable to see the data unencrypted? Was the recipe for decryption given, with the actual decryption being much harder (terms so narrow, as you say)?

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#49

I'm excited by the insight and modesty of this guy. I will see to it that he gets a mighty prize. It's great to see how open software can leverage the power of the community to find weak spots and become stronger.

How much might a mighty prize be, if I may ask?

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#50
post #28

As a side note, I didn't notice it was google translate until half way through the article. It's getting really good. Is Russian an "easy" language to translate to English?

I had to struggle to read it. I mean: After logout, one of the key interlocutors for chat will regenerate, and to check that I have the same key as the source, I can only look in his eyes phone. ...did it translate "iPhone" to "eyes phone"? I'm not sure. If that isn't what happened, then something far more horrible must have.

The original:

После логаута одного из собеседников ключ для чата будет перегенерирован, а проверить то, что я имею тот же ключ что и собеседник я могу только посмотрев в его телефон глазами.

My (human) translation:

After one of the participants will log out, the key from the chat will be re-generated, but in order to check that I have the same key as them, I would need to see their phone with my own eyes.

This sentence has a particularly non-English word order, plus some missed punctuation. I can see how it would be a hard case for machine translation.

Post reply on HN