Live data from Hacker News

Telegram protocol defeated. Authors are going to modify crypto-algorithm

translate.google.com

51–60 of 223 posts

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#51
post #42

TextSecure's protocol, on the other hand, hasn't ever been compromised. Don't use Telegram. Use TextSecure. https://whispersystems.org/

That's absolutely true, but I think the reason this seems so devastating for Telegram is not necessarily because there was a vulnerability, but because they were so dismissive of the feedback they got and so willing to immediately make such strong claims. The way I hope TextSecure can be different from Telegram is not by having an absolutely perfect security record forever (although that'd be great), but by publicly…

To be fair, no one here mentioned anything related to the found vulnerability. Instead people seemed to have focused on their choice of SHA1 and IGE.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#54
post #48

Earlier quoted context omitted.

As others have already said, the prize was essentially meaningless because the terms were so narrow. If the spirit of the prize was "if you break our crypto you win", this guy should win it. If the spirit of the prize was "we don't want to give away 200k, but we want to pretend we're secure", he shouldn't

I don't get it. If it's not secure why can't the message be revealed? What's the value of breaking someone's crypto if you are still unable to see the data unencrypted? Was the recipe for decryption given, with the actual decryption being much harder (terms so narrow, as you say)?

genwin, I’ve invented a secure system. If you can tell me what this message says, you win $200k:

  jo
You don’t know what the message says, because it’s so short. You will never win the prize.

But my system was not so secure. My cipher system was this: Take a message and type it on a US Qwerty keyboard, but shift every letter over one place. So `hi` became `jo`. Not very strong. It would easily be cracked with a message consisting of an actual sentence or two.

Now, with Telegraph, it wasn’t just length of the message involved, but additional information; still, the conditions are so narrow that it doesn’t apply to the real world. Just like I’d never simply send you a message that said "hi", Telegraph would be used in ways beyond one simple back-and-forth exchange, so it artificially limits the information available to a cracker. Make sense?

See also: The BEAST attack or the general class of side channel attacks.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#55
post #48

Earlier quoted context omitted.

As others have already said, the prize was essentially meaningless because the terms were so narrow. If the spirit of the prize was "if you break our crypto you win", this guy should win it. If the spirit of the prize was "we don't want to give away 200k, but we want to pretend we're secure", he shouldn't

I don't get it. If it's not secure why can't the message be revealed? What's the value of breaking someone's crypto if you are still unable to see the data unencrypted? Was the recipe for decryption given, with the actual decryption being much harder (terms so narrow, as you say)?

If you search back a few days of HN posts there was an explanation posted.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#56
post #48

Earlier quoted context omitted.

As others have already said, the prize was essentially meaningless because the terms were so narrow. If the spirit of the prize was "if you break our crypto you win", this guy should win it. If the spirit of the prize was "we don't want to give away 200k, but we want to pretend we're secure", he shouldn't

I don't get it. If it's not secure why can't the message be revealed? What's the value of breaking someone's crypto if you are still unable to see the data unencrypted? Was the recipe for decryption given, with the actual decryption being much harder (terms so narrow, as you say)?

Moxie's blog post does a better job explaining the problems than I can [1].

Basically, the framework of the contest precludes many avenues of attack to which a given cryptosystem could be vulnerable. The researcher who discovered the vulnerability in the OP used a man-in-the-middle attack, which cannot be used in the Telegram contest.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#58
post #34

There's a lesson here. I genuinely don't mean to sound smug, but -- remember how confident the Telegram guys were? Remember how sure they were that their protocol would be able to resist the eavesdropping efforts of the NSA and whatever other nefarious interlopers may come along? Remember how they said they'd been working on it for years, and presumably expected for it to last many more years? Remember how that was,…

Did you write the encryption algorithm? Did you have the balls to put 200 grand on the table for anyone who could break it? Did you rise to the challenge and claim the cash?

No, you just stood on the sideline and waited for somebody to fail so you could come down off your branch and peck at the corpse.

Indeed, there is a lesson here. Don't expect anybody to pat you on the back when you put it all on black and win. Because, sure as shit, they'll be there to kick it in your face when you lose.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#59
post #41

Here are some of their comments: ibeatle Большое спасибо, автор поста полностью прав. Со своей стороны хотим пояснить, что сделано это было из лучших побуждений: исправление плохого рандома на клиентах. С настоящего момента в nonce всегда будет приходить ноль, и в следующем слое мы обязательно удалим это поле из схемы и поясним в документации. Автор топика безусловно заслужил награды, просьба обратиться хабраюзера x7…

A small correction: use "irrelevant" instead of "unfounded" to translate "не по существу".

"unfounded" is closer to "не обосновано".

It is a English-speaking forum, put English text first.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#60
post #34

There's a lesson here. I genuinely don't mean to sound smug, but -- remember how confident the Telegram guys were? Remember how sure they were that their protocol would be able to resist the eavesdropping efforts of the NSA and whatever other nefarious interlopers may come along? Remember how they said they'd been working on it for years, and presumably expected for it to last many more years? Remember how that was,…

Did you write the encryption algorithm? Did you have the balls to put 200 grand on the table for anyone who could break it? Did you rise to the challenge and claim the cash? No, you just stood on the sideline and waited for somebody to fail so you could come down off your branch and peck at the corpse. Indeed, there is a lesson here. Don't expect anybody to pat you on the back when you put it all on black and win. Be…

Are you suffering from testosterone poisoning or something?
Post reply on HN