Live data from Hacker News

Telegram protocol defeated. Authors are going to modify crypto-algorithm

translate.google.com

61–70 of 223 posts

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#61
post #60

Earlier quoted context omitted.

Did you write the encryption algorithm? Did you have the balls to put 200 grand on the table for anyone who could break it? Did you rise to the challenge and claim the cash? No, you just stood on the sideline and waited for somebody to fail so you could come down off your branch and peck at the corpse. Indeed, there is a lesson here. Don't expect anybody to pat you on the back when you put it all on black and win. Be…

Are you suffering from testosterone poisoning or something?

Why would you post such an inane one-liner like that? Jimmytucson made a very good point, which is that the very intelligent Telegram authors tried really hard to make a solid product, made a huge gamble that didn't quite pay off like they wanted, and that all we see now are the smug, told-you-so vultures swooping in to pat themselves on the back for being oh so much smarter than the stupid crypto guys.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#62
post #61
post #60

Earlier quoted context omitted.

Are you suffering from testosterone poisoning or something?

Why would you post such an inane one-liner like that? Jimmytucson made a very good point, which is that the very intelligent Telegram authors tried really hard to make a solid product, made a huge gamble that didn't quite pay off like they wanted, and that all we see now are the smug, told-you-so vultures swooping in to pat themselves on the back for being oh so much smarter than the stupid crypto guys.

The problem is that if the authors had actually consulted crypto guys, none of this would have happened. Their lack of security shouldn't be excused.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#63
post #61
post #60

Earlier quoted context omitted.

Are you suffering from testosterone poisoning or something?

Why would you post such an inane one-liner like that? Jimmytucson made a very good point, which is that the very intelligent Telegram authors tried really hard to make a solid product, made a huge gamble that didn't quite pay off like they wanted, and that all we see now are the smug, told-you-so vultures swooping in to pat themselves on the back for being oh so much smarter than the stupid crypto guys.

No one cares that you tried really hard before failing, doubly so with security products.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#64
post #51
post #42

Earlier quoted context omitted.

That's absolutely true, but I think the reason this seems so devastating for Telegram is not necessarily because there was a vulnerability, but because they were so dismissive of the feedback they got and so willing to immediately make such strong claims. The way I hope TextSecure can be different from Telegram is not by having an absolutely perfect security record forever (although that'd be great), but by publicly…

To be fair, no one here mentioned anything related to the found vulnerability. Instead people seemed to have focused on their choice of SHA1 and IGE.

To be fair, no one actually discovered the bridge was made of rotting wood. They seemed focused on the fact that math PhDs design it with no civil engineering background and stated plastic had no known defects.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#65
post #36

Earlier quoted context omitted.

Never forget. RIP Telegram (2013-2013). This whole thing has been interesting to follow because it seems this same thing happens every time someone make macho Crypto-claims. From seeing how confident the Telegram team was to reading all the detractors who were so ready to criticize. It's an interesting dynamic in the Crypto community.

RIP Telegram (2013-2013). omg made me lol super hard

I see you've only been here for 33 days so I'll lend you a hand.

This is HN, and we don't make posts like that.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#66
post #48

Earlier quoted context omitted.

I don't get it. If it's not secure why can't the message be revealed? What's the value of breaking someone's crypto if you are still unable to see the data unencrypted? Was the recipe for decryption given, with the actual decryption being much harder (terms so narrow, as you say)?

Moxie's blog post does a better job explaining the problems than I can [1]. Basically, the framework of the contest precludes many avenues of attack to which a given cryptosystem could be vulnerable. The researcher who discovered the vulnerability in the OP used a man-in-the-middle attack, which cannot be used in the Telegram contest.

you forgot to post the link

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#67
post #62
post #61

Earlier quoted context omitted.

Why would you post such an inane one-liner like that? Jimmytucson made a very good point, which is that the very intelligent Telegram authors tried really hard to make a solid product, made a huge gamble that didn't quite pay off like they wanted, and that all we see now are the smug, told-you-so vultures swooping in to pat themselves on the back for being oh so much smarter than the stupid crypto guys.

The problem is that if the authors had actually consulted crypto guys, none of this would have happened. Their lack of security shouldn't be excused.

The author of the hack himself declares at the very bottom of the article: "An expert in cryptography [I] am not, please correct [me] if I'm wrong."

How embarassing for telegram if what he says is true.

This excerpt was taken from the google translate version of the article.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#68
post #61
post #60

Earlier quoted context omitted.

Are you suffering from testosterone poisoning or something?

Why would you post such an inane one-liner like that? Jimmytucson made a very good point, which is that the very intelligent Telegram authors tried really hard to make a solid product, made a huge gamble that didn't quite pay off like they wanted, and that all we see now are the smug, told-you-so vultures swooping in to pat themselves on the back for being oh so much smarter than the stupid crypto guys.

> stupid crypto guys.

Because it is dangerous to everyone when non-crypto guys call themselves crypto guys.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#69
post #63
post #61

Earlier quoted context omitted.

Why would you post such an inane one-liner like that? Jimmytucson made a very good point, which is that the very intelligent Telegram authors tried really hard to make a solid product, made a huge gamble that didn't quite pay off like they wanted, and that all we see now are the smug, told-you-so vultures swooping in to pat themselves on the back for being oh so much smarter than the stupid crypto guys.

No one cares that you tried really hard before failing, doubly so with security products.

This comment seems to harshly dismiss failures, but that's not the heart of the issue.

Failure is celebrated -- if you make an effort, and try, and you fail, and you learn, and you share what you learned, people care.

But when you (Telegram, not you, XorNot) have a bad idea, and people smarter than you patiently explain why its broken, and you try to buffalo and bluster and bullshit past them, and your product's entire purpose is to provide a security, then your product is worse than a buggy tool; it's worse than not using the product at all. It's the modern-day equivalent of patent-medicine snake oil, and it hurts people.

Re: Telegram protocol defeated. Authors are going to modify crypto-algorithm

#70
post #54
post #48

Earlier quoted context omitted.

I don't get it. If it's not secure why can't the message be revealed? What's the value of breaking someone's crypto if you are still unable to see the data unencrypted? Was the recipe for decryption given, with the actual decryption being much harder (terms so narrow, as you say)?

genwin, I’ve invented a secure system. If you can tell me what this message says, you win $200k: jo You don’t know what the message says, because it’s so short. You will never win the prize. But my system was not so secure. My cipher system was this: Take a message and type it on a US Qwerty keyboard, but shift every letter over one place. So `hi` became `jo`. Not very strong. It would easily be cracked with a messag…

FWIW, "hi" was my first guess when I saw "jo". $200k, please. :-)
Post reply on HN